Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Certified Information Privacy Professional CIPP-US Dumps PDF

Page: 11 / 13
Total 168 questions

Certified Information Privacy Professional/United States (CIPP/US) Questions and Answers

Question 41

The “Consumer Privacy Bill of Rights” presented in a 2012 Obama administration report is generally based on?

Options:

A.

The 1974 Privacy Act

B.

Common law principles

C.

European Union Directive

D.

Traditional fair information practices

Question 42

SCENARIO

Please use the following to answer the next QUESTION

When there was a data breach involving customer personal and financial information at a large retail store, the company’s directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor

procedures for purging and destroying outdated data. In her research, Roberta had discovered that even low- level employees had access to all of the company’s customer data,including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.

Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees’ access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers’ financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.

When the breach occurred, the company’s executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta’s guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.

Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.

Based on the problems with the company’s privacy security that Roberta identifies, what is the most likely cause of the breach?

Options:

A.

Mishandling of information caused by lack of access controls.

B.

Unintended disclosure of information shared with a third party.

C.

Fraud involving credit card theft at point-of-service terminals.

D.

Lost company property such as a computer or flash drive.

Question 43

What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?

Options:

A.

A consent decree

B.

Stare decisis decree

C.

A judgment rider

D.

Common law judgment

Question 44

Which of the following is commonly required for an entity to be subject to breach notification requirements under most state laws?

Options:

A.

The entity must conduct business in the state

B.

The entity must have employees in the state

C.

The entity must be registered in the state

D.

The entity must be an information broker

Page: 11 / 13
Total 168 questions