Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free IAPP CIPP-US Practice Exam with Questions & Answers | Set: 3

Questions 21

In March 2012, the FTC released a privacy report that outlined three core principles for companies handling consumer data. Which was NOT one of these principles?

Options:
A.

Simplifying consumer choice.

B.

Enhancing security measures.

C.

Practicing Privacy by Design.

D.

Providing greater transparency.

IAPP CIPP-US Premium Access
Questions 22

Which of the following is commonly required for an entity to be subject to breach notification requirements under most state laws?

Options:
A.

The entity must conduct business in the state

B.

The entity must have employees in the state

C.

The entity must be registered in the state

D.

The entity must be an information broker

Questions 23

In what way is the Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act intended to help consumers?

Options:
A.

By providing consumers with free spam-filtering software.

B.

By requiring a company to receive an opt-in before sending any advertising e-mails.

C.

By prohibiting companies from sending objectionable content through unsolicited e-mails.

D.

By requiring companies to allow consumers to opt-out of future e-mails.

Questions 24

SCENARIO

Please use the following to answer the next QUESTION

Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asia. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.

Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station’s network and was able to steal data relating to employees in the company’s Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.

The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.

What can Otto do to most effectively minimize the privacy risks involved in using a cloud provider for the HR data?

Options:
A.

Request that the Board sign off in a written document on the choice of cloud provider.

B.

Ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit.

C.

Obtain express consent from employees for storing the HR data in the cloud and keep a record of the employee consents.

D.

Negotiate a Business Associate Agreement with the cloud provider to protect any health-related data employees might share with Filtration Station.

Questions 25

What is the main purpose of the Global Privacy Enforcement Network?

Options:
A.

To promote universal cooperation among privacy authorities

B.

To investigate allegations of privacy violations internationally

C.

To protect the interests of privacy consumer groups worldwide

D.

To arbitrate disputes between countries over jurisdiction for privacy laws

Questions 26

Who has rulemaking authority for the Fair Credit Reporting Act (FCRA) and the Fair and Accurate Credit Transactions Act (FACTA)?

Options:
A.

State Attorneys General

B.

The Federal Trade Commission

C.

The Department of Commerce

D.

The Consumer Financial Protection Bureau

Questions 27

An organization self-certified under Privacy Shield must, upon request by an individual, do what?

Options:
A.

Suspend the use of all personal information collected by the organization to fulfill its original purpose.

B.

Provide the identities of third parties with whom the organization shares personal information.

C.

Provide the identities of third and fourth parties that may potentially receive personal information.

D.

Identify all personal information disclosed during a criminal investigation.

Questions 28

What privacy concept grants a consumer the right to view and correct errors on his or her credit report?

Options:
A.

Access.

B.

Notice.

C.

Action.

D.

Choice.

Questions 29

Under state breach notification laws, which is NOT typically included in the definition of personal information?

Options:
A.

State identification number

B.

First and last name

C.

Social Security number

D.

Medical Information

Questions 30

Which of the following best describes what a “private right of action” is?

Options:
A.

The right of individuals to keep their information private.

B.

The right of individuals to submit a request to access their information.

C.

The right of individuals harmed by data processing to have their information deleted.

D.

The right of individuals harmed by a violation of a law to file a lawsuit against the violation.

Exam Code: CIPP-US
Certification Provider: IAPP
Exam Name: Certified Information Privacy Professional/United States (CIPP/US)
Last Update: Jul 17, 2025
Questions: 194

IAPP Free Exams

IAPP Free Exams
Prepare effectively for IAPP certification exams with free study resources and practice tests from Examstrack.