Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free DSCI DCPLA Practice Exam with Questions & Answers | Set: 2

Questions 11

In the landmark case _______________ the Honourable Supreme Court of India reaffirmed the status of Right to Privacy as a Fundamental Right under Part III of the constitution.

Options:
A.

M. P. Sharma and others vs. Satish Chandra, District Magistrate, Delhi, and others

B.

Maneka Gandhi vs. Union of India

C.

Justice K. S. Puttaswamy (Retd.) and Anr. vs. Union of India And Ors

D.

Olga Tellis vs. Bombay Municipal Corporation

DSCI DCPLA Premium Access
Questions 12

Which of the following could be considered as triggers for updating privacy policy? (Choose all that apply.)

Options:
A.

Regulatory changes

B.

Privacy breach

C.

Change in service provider for an established business process

D.

Recruitment of more employees

Questions 13

Entities should collect personal information from user that is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. This Privacy Principle is called:

Options:
A.

Collection Limitation

B.

Use Limitation

C.

Accountability

D.

Storage Limitation

Questions 14

Which of the following measures can an organization implement to establish regulatory compliance intelligence? (Choose all that apply.)

Options:
A.

Establish a process that keeps a track of applicable legal and regulatory changes

B.

Identify the liabilities imposed by the regulations with respect to specific data elements

C.

Ensure that a mechanism exists for quick and effective provisioning, de-provisioning and authorization of access to information or systems which are exposed to data

D.

Ensure that knowledge with respect to legal and regulatory compliances is managed effectively

Questions 15

With respect to privacy governance, which of the following statements are correct? (Tick all that apply)

Options:
A.

Privacy governance defines the specifications for privacy operations performed on data processed through computer resource only

B.

Privacy governance provides privacy strategy and direction, and takes decisions on key privacy issues

C.

Privacy governance addresses day-to-day privacy incidents with processes established by privacy policies and procedures

D.

Privacy governance ensures that privacy issues are not left unaddressed in the organization

Questions 16

Which of the following are the key factors that need to be considered for determining the applicability of the privacy principles? (Choose all that apply.)

Options:
A.

The role of the organization in determining the purpose of the data collection

B.

How and where the data is coming in the organization

C.

Requirements stipulated by the local authorities from where the organization operating

D.

Organization’s commitment to the external stakeholder with respect to privacy

Questions 17

Categorise the following statement:

"In case of eventualities or incidents, the organization struggles to locate source, evaluate reasons and fix the accountability."

Options:
A.

Visibility

B.

Capability

C.

Enforcement

D.

Demonstration

Questions 18

What is a Data Subject? (Choose all that apply.)

Options:
A.

An individual who provides his/her data/information for availing any service

B.

An individual who processes the data/information of individuals for providing necessary services

C.

An individual whose data/information is processed

D.

A company providing PI of its employees for processing

E.

An individual who collects data from illegitimate sources

Questions 19

The assessor organization can issue the DSCI certification to the assessee organization if it is satisfied with the assessment outcome.

Options:
A.

True

B.

False

Questions 20

FILL BLANK

MIM

The company has a well-defined and tested Information security monitoring and incident management process in place. The process has been in place since last 10 years and has matured significantly over a period of time. There is a Security Operations Centre (SOC) to detect security incidents based on well-defined business rules.

The security incident management is based on ISO 27001 and defines incident types, alert levels, roles and responsibilities, escalation matrix, among others. The consultants advised company to realign the existing monitoring and incident management to cater to privacy requirements. The company consultants sought help of external privacy expert in this regard.

(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a definitive conclusion)

Introduction and Background

XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves more than 500 clients across industry verticals — BFSI, Retail, Government, Healthcare, Telecom among others in Americas, Europe, Asia-Pacific, Middle East and Africa. The company provides IT services including application development and maintenance, IT Infrastructure management, consulting, among others. It also offers IT products mainly for its BFSI customers.

The company is witnessing phenomenal growth in the BPM services over last few years including FinanceandAccounting including credit card processing, Payroll processing, Customer support, Legal Process Outsourcing, among others and has rolled out platform based services. Most of the company’s revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the company is looking to expand its operations in Europe. India, too has attracted company’s attention given the phenomenal increase in domestic IT spend esp. by the government through various large scale IT projects. The company is also very aggressive in the cloud and mobility space, with a strong focus on delivery of cloud services. When it comes to expanding operations in Europe, company is facing difficulties in realizing the full potential of the market because of privacy related concerns of the clients arising from the stringent regulatory requirements based on EU General Data Protection Regulation (EU GDPR).

To get better access to this market, the company decided to invest in privacy, so that it is able to provide increased assurance to potential clients in the EU and this will also benefit its US operations because privacy concerns are also on rise in the US. It will also help company leverage outsourcing opportunities in the Healthcare sector in the US which would involve protection of sensitive medical records of the US citizens. The company believes that privacy will also be a key differentiator in the cloud business going forward. In short, privacy was taken up as a strategic initiative in the company in early 2011.

Since XYZ had an internal consulting arm, it assigned the responsibility of designing and implementing an enterprise wide privacy program to the consulting arm. The consulting arm had very good expertise in information security consulting but had limited expertise in the privacy domain. The project was to be driven by CIO's office, in close consultation with the Corporate Information Security and Legal functions.

If you were the privacy expert advising the company, what steps would you suggest to realign the existing security monitoring and incident management to address privacy requirements especially those specific to client relationships? (250 to 500 words)

Options:
Exam Code: DCPLA
Certification Provider: DSCI
Exam Name: DSCI Certified Privacy Lead Assessor
Last Update: Jul 11, 2025
Questions: 86
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42

DSCI Free Exams

DSCI Free Exams
Examstrack offers free DSCI exam materials and practice tests to aid your DSCI certification journey.