Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Passed Exam Today CIPM

Page: 3 / 18
Total 243 questions

Certified Information Privacy Manager (CIPM) Questions and Answers

Question 9

“Collection”, “access” and “destruction” are aspects of what privacy management process?

Options:

A.

The data governance strategy

B.

The breach response plan

C.

The metric life cycle

D.

The business case

Question 10

All of the following are accurate regarding the use of technical security controls EXCEPT?

Options:

A.

Technical security controls are part of a data governance strategy.

B.

Technical security controls deployed for one jurisdiction often satisfy another jurisdiction.

C.

Most privacy legislation lists the types of technical security controls that must be implemented.

D.

A person with security knowledge should be involved with the deployment of technical security controls.

Question 11

SCENARIO

Please use the following lo answer the next question:

The board risk committee of your organization is particularly concerned not only by the number and frequency of data breaches reported to it over the past 12 months, but also the inconsistency in responses and poor incident response turnaround times.

Upon reviewing the current incident response plan (IRP), it was discovered that while the business continuity plan (BCP) had been updated on time, the IRP, linked to BCP. was last updated over three years ago.

The board risk committee has noted this as high risk especially since company policy is to review and update policies and plans annually. Consequently, the newly appointed data protection officer (DPO) was requested to provide a paper on how she would remediate the situation.

As a seasoned data privacy professional, you have been requested to assist the new DPO.

Which additional proactive step listed below would best mitigate these risks in the future?

Options:

A.

Make the IRP a live document that is evaluated for completeness during each incident.

B.

Make copies of the IRP in various place so it can be accessed remotely or when offline.

C.

Add comments about incidents to the IRP to record what action was taken.

D.

Make sure that everyone listed in the IRP has a copy of the IRP

Question 12

What United States federal law requires financial institutions to declare their personal data collection practices?

Options:

A.

The Kennedy-Hatch Disclosure Act of 1997.

B.

The Gramm-Leach-Bliley Act of 1999.

C.

SUPCLA, or the federal Superprivacy Act of 2001.

D.

The Financial Portability and Accountability Act of 2006.

Page: 3 / 18
Total 243 questions