Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Certified Information Privacy Professional/United States (CIPP/US)

Last Update 15 hours ago Total Questions : 194

The Certified Information Privacy Professional/United States (CIPP/US) content is now fully updated, with all current exam questions added 15 hours ago. Deciding to include CIPP-US practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CIPP-US exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CIPP-US sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Certified Information Privacy Professional/United States (CIPP/US) practice test comfortably within the allotted time.

Question # 51

What is the main purpose of the Global Privacy Enforcement Network?

A.

To promote universal cooperation among privacy authorities

B.

To investigate allegations of privacy violations internationally

C.

To protect the interests of privacy consumer groups worldwide

D.

To arbitrate disputes between countries over jurisdiction for privacy laws

Question # 52

Which of the following is an important implication of the Dodd-Frank Wall Street Reform and Consumer Protection Act?

A.

Financial institutions must avoid collecting a customer’s sensitive personal information

B.

Financial institutions must help ensure a customer’s understanding of products and services

C.

Financial institutions must use a prescribed level of encryption for most types of customer records

D.

Financial institutions must cease sending e-mails and other forms of advertising to customers who opt out of direct marketing

Question # 53

According to Section 5 of the FTC Act, self-regulation primarily involves a company’s right to do what?

A.

Determine which bodies will be involved in adjudication

B.

Decide if any enforcement actions are justified

C.

Adhere to its industry’s code of conduct

D.

Appeal decisions made against it

Question # 54

Which of the following privacy rights is NOT available under the Colorado Privacy Act?

A.

The right to access sensitive data.

B.

The right to correct sensitive data.

C.

The right to delete sensitive data.

D.

The right to limit the use of sensitive data.

Question # 55

What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?

A.

A consent decree

B.

Stare decisis decree

C.

A judgment rider

D.

Common law judgment

Question # 56

Federal laws establish which of the following requirements for collecting personal information of minors under the age of 13?

A.

Implied consent from a minor’s parent or guardian, or affirmative consent from the minor.

B.

Affirmative consent from a minor’s parent or guardian before collecting the minor’s personal information online.

C.

Implied consent from a minor’s parent or guardian before collecting a minor’s personal information online, such as when they permit the minor to use the internet.

D.

Affirmative consent of a parent or guardian before collecting personal information of a minor offline (e.g., in person), which also satisfies any requirements for online consent.

Question # 57

SCENARIO

Please use the following to answer the next question;

Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada. Miraculous normally treats patients in person, but has recently decided to start offering teleheaith appointments, where patients can have virtual appointments with on-site doctors via a phone app

For this new initiative. Miraculous is considering a product built by MedApps, a company that makes quality teleheaith apps for healthcare practices and licenses them to be used with the practices ' branding. MedApps provides technical support for the app. which it hosts in the cloud MedApps also offers an optional benchmarking service for providers who wish to compare their practice to others using the service

Riya is the Privacy Officer at Miraculous, responsible for the practice ' s compliance with HIPAA and other applicable laws, and she works with the Miraculous procurement team to get vendor agreements in place. She occasionally assists procurement in vetting vendors and inquiring about their own compliance practices. as well as negotiating the terms of vendor agreements Riya is currently reviewing the suitability of the MedApps app from a privacy perspective.

Riya has also been asked by the Miraculous Healthcare business operations team to review the MedApps ' optional benchmarking service. Of particular concern is the requirement that Miraculous Healthcare upload information about the appointments to a portal hosted by MedApps

What is the most practical action Riya can take to minimize the privacy risks of using an app for telehealth appointments?

A.

Prevent MedApps from using copies of the patient data.

B.

Require MedApps to obtain consent from all patients.

C.

Require MedApps to submit a SOC2 report.

D.

Engage in active oversight of MedApps

Question # 58

Which federal law or regulation preempts state law?

A.

Health Insurance Portability and Accountability Act

B.

Controlling the Assault of Non-Solicited Pornography and Marketing Act

C.

Telemarketing Sales Rule

D.

Electronic Communications Privacy Act of 1986

Go to page: