
[Apr 05, 2022] New Real CIPP-US Exam Dumps Questions
Pass Your CIPP-US Exam Easily with Accurate Certified Information Privacy Professional/United States (CIPP/US) PDF Questions
NEW QUESTION 41
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
- A. An international court ruling on personal information held in the commercial sector.
- B. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
- C. A bill of rights for individuals seeking access to their personal information.
- D. A code of responsibilities for medical establishments to uphold privacy laws.
Answer: C
NEW QUESTION 42
A large online bookseller decides to contract with a vendor to manage Personal Information (PI). What is the least important factor for the company to consider when selecting the vendor?
- A. The vendor's employee retention rates
- B. The vendor's reputation
- C. The vendor's employee training program
- D. The vendor's financial health
Answer: D
NEW QUESTION 43
What practice does the USA FREEDOM Act NOT authorize?
- A. An extension of the expiration for roving wiretaps
- B. Emergency exceptions that allows the government to target roamers
- C. The bulk collection of telephone data and internet metadata
- D. An increase in the maximum penalty for material support to terrorism
Answer: B
Explanation:
Explanation/Reference: https://www.rand.org/blog/2015/05/the-usa-freedom-act-the-definition-of-a-compromise.html
NEW QUESTION 44
Within what time period must a commercial message sender remove a recipient's address once they have asked to stop receiving future e-mail?
- A. 15 days
- B. 21 days
- C. 7 days
- D. 10 days
Answer: D
NEW QUESTION 45
SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
Based on the scenario, which of the following would have helped Janice to better meet the company's needs?
- A. Creating a more comprehensive plan for implementing a new policy
- B. Spending more time understanding the company's information goals
- C. Removing the financial burden of the company's employee training program
- D. Explaining the importance of transparency in implementing a new policy
Answer: B
NEW QUESTION 46
All of the following organizations are specified as covered entities under the Health Insurance Portability and Accountability Act (HIPAA) EXCEPT?
- A. Healthcare information clearinghouses
- B. Pharmaceutical companies
- C. Healthcare providers
- D. Health plans
Answer: B
NEW QUESTION 47
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
How can the radiology department address Declan's concern about paper waste and still comply with the Health Insurance Portability and Accountability Act (HIPAA)?
- A. Direct patients to the correct area of the hospital website
- B. State the privacy policy to the patient verbally
- C. Confirm that patients are given the privacy notice on their first visit
- D. Post the privacy notice in a prominent location instead
Answer: A
Explanation:
Section: (none)
Explanation
NEW QUESTION 48
SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asi a. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
What can Otto do to most effectively minimize the privacy risks involved in using a cloud provider for the HR data?
- A. Obtain express consent from employees for storing the HR data in the cloud and keep a record of the employee consents.
- B. Request that the Board sign off in a written document on the choice of cloud provider.
- C. Ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit.
- D. Negotiate a Business Associate Agreement with the cloud provider to protect any health-related data employees might share with Filtration Station.
Answer: C
NEW QUESTION 49
What does the Massachusetts Personal Information Security Regulation require as it relates to encryption of personal information?
- A. The encryption of personal information stored in Massachusetts-based companies when stored on portable devices.
- B. The encryption of all personal information of Massachusetts residents when all equipment is located in Massachusetts.
- C. The encryption of all personal information of Massachusetts residents when stored on portable devices.
- D. The encryption of all personal information stored in Massachusetts-based companies when all equipment is located in Massachusetts.
Answer: C
NEW QUESTION 50
In what way does the "Red Flags Rule" under the Fair and Accurate Credit Transactions Act (FACTA) relate to the owner of a grocery store who uses a money wire service?
- A. It mandates the use of updated technology for securing credit records
- B. It is not usually enforced in the case of a small financial institution
- C. It does not apply because the owner is not a creditor
- D. It requires the owner to implement an identity theft warning system
Answer: A
NEW QUESTION 51
According to FERPA, when can a school disclose records without a student's consent?
- A. If the disclosure is to practitioners who are involved in a student's health care
- B. If the disclosure is not to be conducted through email to the third party
- C. If the disclosure is to provide transcripts to a school where a student intends to enroll
- D. If the disclosure would not reveal a student's student identification number
Answer: C
Explanation:
Explanation/Reference: https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html
NEW QUESTION 52
Read this notice:
Our website uses cookies. Cookies allow us to identify the computer or device you're using to access the site, but they don't identify you personally. For instructions on setting your Web browser to refuse cookies, click here.
What type of legal choice does not notice provide?
- A. Mandatory
- B. Implied consent
- C. Opt-out
- D. Opt-in
Answer: B
NEW QUESTION 53
SCENARIO
Please use the following to answer the next QUESTION
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated dat a. In her research, Roberta had discovered that even low- level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.
Based on the problems with the company's privacy security that Roberta identifies, what is the most likely cause of the breach?
- A. Unintended disclosure of information shared with a third party.
- B. Mishandling of information caused by lack of access controls.
- C. Lost company property such as a computer or flash drive.
- D. Fraud involving credit card theft at point-of-service terminals.
Answer: B
NEW QUESTION 54
What important action should a health care provider take if the she wants to qualify for funds under the Health Information Technology for Economic and Clinical Health Act (HITECH)?
- A. Make electronic health records (EHRs) part of regular care
- B. Keep electronic updates about the Health Insurance Portability and Accountability Act
- C. Send health information and appointment reminders to patients electronically
- D. Bill the majority of patients electronically for their health care
Answer: A
NEW QUESTION 55
Which of the following statements is most accurate in regard to data breach notifications under federal and state laws:
- A. You must notify the Federal Trade Commission (FTC) in addition to affected individuals if over 500 individuals are receiving notice.
- B. The only obligations to provide data breach notification are under state law because currently there is no federal law or regulation requiring notice for the breach of personal information.
- C. When you are required to provide an individual with notice of a data breach under any state's law, you must provide the individual with an offer for free credit monitoring.
- D. When providing an individual with required notice of a data breach, you must identify what personal information was actually or likely compromised.
Answer: D
NEW QUESTION 56
Federal laws establish which of the following requirements for collecting personal information of minors under the age of 13?
- A. Affirmative consent from a minor's parent or guardian before collecting the minor's personal information online.
- B. Implied consent from a minor's parent or guardian, or affirmative consent from the minor.
- C. Affirmative consent of a parent or guardian before collecting personal information of a minor offline (e.g., in person), which also satisfies any requirements for online consent.
- D. Implied consent from a minor's parent or guardian before collecting a minor's personal information online, such as when they permit the minor to use the internet.
Answer: A
Explanation:
Explanation/Reference: https://www.ftc.gov/tips-advice/business-center/guidance/complying-coppa-frequently-asked- questions-0
NEW QUESTION 57
A student has left high school and is attending a public postsecondary institution. Under what condition may a school legally disclose educational records to the parents of the student without consent?
- A. If the student is still a dependent for tax purposes
- B. If the student has not yet turned 18 years of age
- C. If the student is in danger of academic suspension
- D. If the student has applied to transfer to another institution
Answer: A
NEW QUESTION 58
SCENARIO
Please use the following to answer the next QUESTION
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated dat a. In her research, Roberta had discovered that even low- level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.
Which principle of the Consumer Privacy Bill of Rights, if adopted, would best reform the company's privacy program?
- A. Consumers have a right to correct personal data in a manner that is appropriate to the sensitivity.
- B. Consumers have a right to exercise control over how companies use their personal data.
- C. Consumers have a right to easily accessible information about privacy and security practices.
- D. Consumers have a right to reasonable limits on the personal data that a company retains.
Answer: D
NEW QUESTION 59
Which of these organizations would be required to provide its customers with an annual privacy notice?
- A. The Four Winds Tribal College.
- B. The King County Savings and Loan.
- C. The Golden Gavel Auction House.
- D. The Breezy City Housing Commission.
Answer: C
NEW QUESTION 60
A law enforcement subpoenas the ACME telecommunications company for access to text message records of a person suspected of planning a terrorist attack. The company had previously encrypted its text message records so that only the suspect could access this data.
What law did ACME violate by designing the service to prevent access to the information by a law enforcement agency?
- A. SCA
- B. ECPA
- C. USA Freedom Act
- D. CALEA
Answer: D
Explanation:
Explanation
Explanation/Reference: https://www.nap.edu/read/11896/chapter/11#283
NEW QUESTION 61
Which entity within the Department of Health and Human Services (HHS) is the primary enforcer of the Health Insurance Portability and Accountability Act (HIPAA) "Privacy Rule"?
- A. Office of Inspector General.
- B. Office of Social Services.
- C. Office for Civil Rights.
- D. Office of Public Health and Safety.
Answer: C
NEW QUESTION 62
What is the main reason some supporters of the European approach to privacy are skeptical about self- regulation of privacy practices?
- A. A new business owner may not understand the regulations
- B. Industries may not be strict enough in the creation and enforcement of rules
- C. A large amount of money may have to be sent on improved technology and security
- D. Human rights may be disregarded for the sake of privacy
Answer: B
NEW QUESTION 63
SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the main problem with Cheryl's suggested method of communicating the new privacy policy?
- A. The policy would not be considered valid if not communicated in full.
- B. The policy might not be implemented consistency across departments.
- C. Employees might not understand how the documents relate to the policy as a whole.
- D. Employees would not be comfortable with a policy that is put into action over time.
Answer: B
NEW QUESTION 64
......
More Exam Details
The CIPP-US evaluation checks different topics that are related to data privacy. Some of the tested domains are the basics of the US Privacy Environment, the laws around the collection and the use of data in the private sector, regulations around access to private-sector data by the government, privacy at the workplace as well as privacy laws in different states. Such an exam also tests the candidate's knowledge of the laws and regulations around the movement of private information within the US, to and from the US, the EU, and other relevant jurisdictions. As for the evaluation facts, the CIPP-US exam includes 90 questions that a candidate ought to finish in 2.5 hours. The initial test attempt costs $550, but if one has another certification from IAPP, he or she gets a discount and only pays a fee of $375. In case of a retake, the amount to pay is also $375. The least score that one has to obtain is 300 points, where the range starts from 100 to 500 grades. Then, for the certificate’s maintenance, a candidate is required to pay a fee of $250 every two years. Still, the renewal fee is included in the membership cost for IAPP members. To add more, the vendor offers this test all through the year. However, the exam time and date may vary depending on the candidate‘s location. Lastly, all candidates should book their slots early enough, at least 90 days before the actual exam date.
Updated CIPP-US Exam Practice Test Questions: https://examboost.vce4dumps.com/CIPP-US-latest-dumps.html