Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the IAPP Certified Information Privacy Professional CIPP-US Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CIPP-US Premium Access

View all detail and faqs for the CIPP-US exam


803 Students Passed

87% Average Score

94% Same Questions
Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
Questions # 11:

John, a California resident, receives notification that a major corporation with $500 million in annual revenue has experienced a data breach. John’s personal information in their possession has been stolen, including his full name and social security numb. John also learns that the corporation did not have reasonable cybersecurity measures in place to safeguard his personal information.

Which of the following answers most accurately reflects John’s ability to pursue a legal claim against the corporation under the California Consumer Privacy Act (CCPA)?

Options:

A.

John has no right to sue the corporation because the CCPA does not address any data breach rights.

B.

John cannot sue the corporation for the data breach because only the state’s Attoney General has authority to file suit under the CCPA.

C.

John can sue the corporation for the data breach but only to recover monetary damages he actually suffered as a result of the data breach.

D.

John can sue the corporation for the data breach to recover monetary damages suffered as a result of the data breach, and in some circumstances seek statutory damages irrespective of whether he suffered any financial harm.

Questions # 12:

In which situation is a company operating under the assumption of implied consent?

Options:

A.

An employer contacts the professional references provided on an applicant’s resume

B.

An online retailer subscribes new customers to an e-mail list by default

C.

A landlord uses the information on a completed rental application to run a credit report

D.

A retail clerk asks a customer to provide a zip code at the check-out counter

Questions # 13:

Federal laws establish which of the following requirements for collecting personal information of minors under the age of 13?

Options:

A.

Implied consent from a minor’s parent or guardian, or affirmative consent from the minor.

B.

Affirmative consent from a minor’s parent or guardian before collecting the minor’s personal information online.

C.

Implied consent from a minor’s parent or guardian before collecting a minor’s personal information online, such as when they permit the minor to use the internet.

D.

Affirmative consent of a parent or guardian before collecting personal information of a minor offline (e.g., in person), which also satisfies any requirements for online consent.

Questions # 14:

Your company, an online store selling digital keys to video games, has received a data access request from an individual. Specifically, the individual wants access to her recent purchase history, as she has misplaced the emails containing the digital keys to multiple game purchases she made last month.

From a security standpoint, what would the user have to do under CCPA in order to acceptably verify her identity?

Options:

A.

Take a photo of herself with her driver license

B.

Provide a notarized affidavit signed by two witnesses.

C.

Log in to her password-protected account with the company

D.

Phone the company and provide her contact details and credit card number

Questions # 15:

In what way does the “Red Flags Rule” under the Fair and Accurate Credit Transactions Act (FACTA) relate to the owner of a grocery store who uses a money wire service?

Options:

A.

It mandates the use of updated technology for securing credit records

B.

It requires the owner to implement an identity theft warning system

C.

It is not usually enforced in the case of a small financial institution

D.

It does not apply because the owner is not a creditor

Questions # 16:

The Video Privacy Protection Act of 1988 restricted which of the following?

Options:

A.

Which purchase records of audio visual materials may be disclosed

B.

When downloading of copyrighted audio visual materials is allowed

C.

When a user’s viewing of online video content can be monitored

D.

Who advertisements for videos and video games may target

Questions # 17:

California’s SB 1386 was the first law of its type in the United States to do what?

Options:

A.

Require commercial entities to disclose a security data breach concerning personal information about the state’s residents

B.

Require notification of non-California residents of a breach that occurred in California

C.

Require encryption of sensitive information stored on servers that are Internet connected

D.

Require state attorney general enforcement of federal regulations against unfair and deceptive trade practices

Questions # 18:

The use of cookies on a website by a service provider is generally not deemed a ‘sale’ of personal information by CCPA, as long as which of the following conditions is met?

Options:

A.

The third party stores personal information to trigger a response to a consumer’s request to exercise their right to opt in.

B.

The analytics cookies placed by the service provider are capable of being tracked but cannot be linked to a particular consumer of that business.

C.

The service provider retains personal information obtained in the course of providing the services specified in the agreement with the subcontractors.

D.

The information collected by the service provider is necessary to perform debugging and the business and service provider have entered into an appropriate agreement.

Questions # 19:

What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?

Options:

A.

A consent decree

B.

Stare decisis decree

C.

A judgment rider

D.

Common law judgment

Questions # 20:

SCENARIO -

Please use the following to answer the next question:

Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada. Miraculous normally treats patients in person, but has recently decided to start offering telehealth appointments, where patients can have virtual appointments with on-site doctors via a phone app.

For this new initiative, Miraculous is considering a product built by MedApps, a company that makes quality telehealth apps for healthcare practices and licenses them to be used with the practices’ branding. MedApps provides technical support for the app, which it hosts in the cloud. MedApps also offers an optional benchmarking service for providers who wish to compare their practice to others using the service.

Riya is the Privacy Officer at Miraculous, responsible for the practice's compliance with HIPAA and other applicable laws, and she works with the Miraculous procurement team to get vendor agreements in place. She occasionally assists procurement in vetting vendors and inquiring about their own compliance practices, as well as negotiating the terms of vendor agreements. Riya is currently reviewing the suitability of the MedApps app from a privacy perspective.

Riya has also been asked by the Miraculous Healthcare business operations team to review the MedApps’ optional benchmarking service. Of particular concern is the requirement that Miraculous Healthcare upload information about the appointments to a portal hosted by MedApps.

What HIPAA compliance issue would Miraculous have to consider before using the telehealth app?

Options:

A.

HIPAA does not permit healthcare providers to use cloud hosting services.

B.

HIPAA does not permit in-person appointment data to be hosted in the cloud.

C.

HIPAA would require Miraculous and MedApps to enter into a Business Associate Agreement.

D.

HIPAA would require Miraculous to obtain patient consent before in-person appointment data can be shared with third parties.

Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.