CIPP-US Exam Questions
225 real CIPP-US exam questions with expert-verified answers and explanations. Page 5 of 5.
- Question #201Health, Financial & Marketing Privacy
What is the primary purpose of the HIPAA Security Rule?
HIPAA Security Ruleelectronic PHIminimum security requirementsePHI - Question #202Health, Financial & Marketing Privacy
All the following are security requirements set forth by the HIPPA Security Rule, except:
HIPAA Security Rulesecurity requirementsOffice of Civil Rightscompliance audit - Question #203Workplace Privacy
Which action is prohibited under the Electronic Communications Privacy Act of 1986?
ECPAElectronic Communications Privacy Actwiretappingstored communications - Question #204Workplace Privacy
Which of the following does Title VII of the Civil Rights Act prohibit an employer from asking a job applicant?
Title VIICivil Rights Actjob applicant questionspregnancy discrimination - Question #205Sector-Specific Laws
How did the Fair and Accurate Credit Transactions Act (FACTA) amend the Fair Credit Reporting Act (FCRA)?
FACTAFCRAconsumer data disposalcredit reporting - Question #206State Privacy Laws
Which federal act does NOT contain provisions for preempting stricter state laws?
federal preemptionstate lawCAN-SPAMCOPPA - Question #207Data Breaches
Which of the following is commonly required for an entity to be subject to breach notification requirements under most state laws?
data breach notificationstate lawsbusiness nexusnotification requirements - Question #208Data Breaches
What is the most likely reason that states have adopted their own data breach notification laws?
state breach lawsfederal enforcement gapdata breach notificationlegislative motivation - Question #209State Privacy Laws
Which federal law or regulation preempts state law?
HIPAA preemptionfederal preemptionstate lawCAN-SPAM - Question #210State Privacy Laws
More than half of U.S. states require telemarketers to?
telemarketingstate registrationconsumer protectionDo Not Call - Question #211State Privacy Laws
What does the Massachusetts Personal Information Security Regulation require as it relates to encryption of personal information?
Massachusetts 201 CMR 17encryptionportable devicespersonal information security - Question #212Data Breaches
California's SB 1386 was the first law of its type in the United States to do what?
California SB 1386data breach notificationsecurity breach disclosurestate law history - Question #213Workplace Privacy
Which of the following is not a legal requirement when a potential employer is using information in a consumer report to determine employment eligibility?
FCRAconsumer reportemployment screeningadverse action notice - Question #214Government and Court Access to Private-Sector Information
Under Section 702 of FISA, which surveillance program allows data requests of Internet Service Providers?
FISA Section 702PRISMgovernment surveillanceISP data requests - Question #215Sector-Specific Laws
In which of the following laws is disclosure forbidden unless a person has expressly opted-in?
COPPAopt-in consentchildren's privacydata disclosure - Question #216Workplace Privacy
Based on current US employment privacy laws, which of the following should NOT be expected to happen while employed with a company?
Employee Polygraph Protection Actworkplace monitoringemployment privacypolygraph - Question #217Government and Court Access to Private-Sector Information
"Third party doctrine" as it relates to the fourth amendment of the US constitution concerns:
third party doctrineFourth Amendmentconstitutional privacywarrant requirement - Question #218Government and Court Access to Private-Sector Information
Which legislation provides protection to the media from government searches unless they have committed a crime or threaten to commit a crime?
Privacy Protection Actmedia protectiongovernment searchpress freedom - Question #219Limits on Private-Sector Collection and Use of Data
In which situation is a company operating under the assumption of implied consent?
implied consentprofessional referencesconsent typesdata collection - Question #220Introduction to the U.S. Privacy Environment
All of the following are tasks in the "Discover" phase of building an information management program EXCEPT?
privacy program managementdiscover phaseinformation lifecycleprivacy policy development - Question #221Introduction to the U.S. Privacy Environment
Which of the following describes the most likely risk for a company developing a privacy policy with standards that are much higher than its competitors?
privacy policy standardsFTC enforcementpolicy riskregulatory scrutiny - Question #222Limits on Private-Sector Collection and Use of Data
If an organization certified under Privacy Shield wants to transfer personal data to a third party acting as an agent, the organization must ensure the third party does all of the...
Privacy Shieldthird party agentonward transferaccountability principle - Question #223Government Enforcement
What was the original purpose of the Federal Trade Commission Act?
FTC ActantitrustFTC historyunfair competition - Question #224Sector-Specific Laws
SCENARIO Please use the following to answer the next question: Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your...
COPPAchildren under 13online data collectionparental consent - Question #225Sector-Specific Laws
SCENARIO Please use the following to answer the next question: Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your...
COPPAparental consentdata sharingchildren's marketing