Labour Day Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Question # 4

Value Sensitive Design (VSD) focuses on which of the following?

A.

Quality and benefit.

B.

Ethics and morality.

C.

Principles and standards.

D.

Privacy and human rights.

Full Access
Question # 5

Which is NOT a way to validate a person's identity?

A.

Swiping a smartcard into an electronic reader.

B.

Using a program that creates random passwords.

C.

Answering a question about "something you know”.

D.

Selecting a picture and tracing a unique pattern on it

Full Access
Question # 6

What is a mistake organizations make when establishing privacy settings during the development of applications?

A.

Providing a user with too many choices.

B.

Failing to use "Do Not Track” technology.

C.

Providing a user with too much third-party information.

D.

Failing to get explicit consent from a user on the use of cookies.

Full Access
Question # 7

What is the most important requirement to fulfill when transferring data out of an organization?

A.

Ensuring the organization sending the data controls how the data is tagged by the receiver.

B.

Ensuring the organization receiving the data performs a privacy impact assessment.

C.

Ensuring the commitments made to the data owner are followed.

D.

Extending the data retention schedule as needed.

Full Access
Question # 8

Combining multiple pieces of information about an individual to produce a whole that is greater than the sum of its parts is called?

A.

Identification.

B.

Insecurity.

C.

Aggregation.

D.

Exclusion.

Full Access
Question # 9

SCENARIO

Kyle is a new security compliance manager who will be responsible for coordinating and executing controls to ensure compliance with the company's information security policy and industry standards. Kyle is also new to the company, where collaboration is a core value. On his first day of new-hire orientation, Kyle's schedule included participating in meetings and observing work in the IT and compliance departments.

Kyle spent the morning in the IT department, where the CIO welcomed him and explained that her department was responsible for IT governance. The CIO and Kyle engaged in a conversation about the importance of identifying meaningful IT governance metrics. Following their conversation, the CIO introduced Kyle to Ted and Barney. Ted is implementing a plan to encrypt data at the transportation level of the organization's wireless network. Kyle would need to get up to speed on the project and suggest ways to monitor effectiveness once the implementation was complete. Barney explained that his short-term goals are to establish rules governing where data can be placed and to minimize the use of offline data storage.

Kyle spent the afternoon with Jill, a compliance specialist, and learned that she was exploring an initiative for a compliance program to follow self-regulatory privacy principles. Thanks to a recent internship, Kyle had some experience in this area and knew where Jill could find some support. Jill also shared results of the company’s privacy risk assessment, noting that the secondary use of personal information was considered a high risk.

By the end of the day, Kyle was very excited about his new job and his new company. In fact, he learned about an open position for someone with strong qualifications and experience with access privileges, project standards board approval processes, and application-level obligations, and couldn’t wait to recommend his friend Ben who would be perfect for the job.

Which of the following should Kyle recommend to Jill as the best source of support for her initiative?

A.

Investors.

B.

Regulators.

C.

Industry groups.

D.

Corporate researchers.

Full Access
Question # 10

Which of the following statements best describes the relationship between privacy and security?

A.

Security systems can be used to enforce compliance with privacy policies.

B.

Privacy and security are independent; organizations must decide which should by emphasized.

C.

Privacy restricts access to personal information; security regulates how information should be used.

D.

Privacy protects data from being viewed during collection and security governs how collected data should be shared.

Full Access
Question # 11

Which of the following activities would be considered the best method for an organization to achieve the privacy principle of data quality'?

A.

Clash customer information with information from a data broker

B.

Build a system with user access controls and approval workflows to edit customer data

C.

Set a privacy notice covering the purpose for collection of a customer's data

D.

Provide a customer with a copy of their data in a machine-readable format

Full Access
Question # 12

What is the best way to protect privacy on a geographic information system (GIS)?

A.

Limiting the data provided to the system.

B.

Using a wireless encryption protocol.

C.

Scrambling location information.

D.

Using a firewall.

Full Access
Question # 13

Which technique is most likely to facilitate the deletion of every instance of data associated with a deleted user account from every data store held by an organization?

A.

Auditing the code which deletes user accounts.

B.

Building a standardized and documented retention program for user data deletion.

C.

Monitoring each data store for presence of data associated with the deleted user account.

D.

Training engineering teams on the importance of deleting user accounts their associated data from all data stores when requested.

Full Access
Question # 14

Aadhaar is a unique-identity number of 12 digits issued to all Indian residents based on their biometric and demographic data. The data is collected by the Unique Identification Authority of India. The Aadhaar database contains the Aadhaar number, name, date of birth, gender and address of over 1 billion individuals.

Which of the following datasets derived from that data would be considered the most de-identified?

A.

A count of the years of birth and hash of the person’ s gender.

B.

A count of the month of birth and hash of the person's first name.

C.

A count of the day of birth and hash of the person’s first initial of their first name.

D.

Account of the century of birth and hash of the last 3 digits of the person's Aadhaar number.

Full Access
Question # 15

Which of the following does NOT illustrate the ‘respect to user privacy’ principle?

A.

Implementing privacy elements within the user interface that facilitate the use of technology by any visually-challenged users.

B.

Enabling Data Subject Access Request (DSARs) that provide rights for correction, deletion, amendment and rectification of personal information.

C.

Developing a consent management self-service portal that enables the data subjects to review the details of consent provided to an organization.

D.

Filing breach notification paperwork with data protection authorities which detail the impact to data subjects.

Full Access
Question # 16

SCENARIO

Please use the following to answer the next question:

Chuck, a compliance auditor for a consulting firm focusing on healthcare clients, was required to travel to the client’s office to perform an onsite review of the client’s operations. He rented a car from Finley Motors upon arrival at the airport as so he could commute to and from the client’s office. The car rental agreement was electronically signed by Chuck and included his name, address, driver’s license, make/model of the car, billing rate, and additional details describing the rental transaction. On the second night, Chuck was caught by a red light camera not stopping at an intersection on his way to dinner. Chuck returned the car back to the car rental agency at the end week without mentioning the infraction and Finley Motors emailed a copy of the final receipt to the address on file.

Local law enforcement later reviewed the red light camera footage. As Finley Motors is the registered owner of the car, a notice was sent to them indicating the infraction and fine incurred. This notice included the license plate number, occurrence date and time, a photograph of the driver, and a web portal link to a video clip of the violation for further review. Finley Motors, however, was not responsible for the violation as they were not driving the car at the time and transferred the incident to AMP Payment Resources for further review. AMP Payment Resources identified Chuck as the driver based on the rental agreement he signed when picking up the car and then contacted Chuck directly through a written letter regarding the infraction to collect the fine.

After reviewing the incident through the AMP Payment Resources’ web portal, Chuck paid the fine using his personal credit card. Two weeks later, Finley Motors sent Chuck an email promotion offering 10% off a future rental.

What is the strongest method for authenticating Chuck’s identity prior to allowing access to his violation information through the AMP Payment Resources web portal?

A.

By requiring Chuck use the last 4 digits of his driver’s license number in combination with a unique PIN provided within the violation notice.

B.

By requiring Chuck use his credit card number in combination with the last 4 digits of his driver’s license.

C.

By requiring Chuck use the rental agreement number in combination with his email address.

D.

By requiring Chuck to call AMP Payment Resources directly and provide his date of birth and home address.

Full Access
Question # 17

SCENARIO

Please use the following to answer next question:

EnsureClaim is developing a mobile app platform for managing data used for assessing car accident insurance claims. Individuals use the app to take pictures at the crash site, eliminating the need for a built-in vehicle camera. EnsureClaim uses a third-party hosting provider to store data collected by the app. EnsureClaim customer service employees also receive and review app data before sharing with insurance claim adjusters.

The app collects the following information:

First and last name

Date of birth (DOB)

Mailing address

Email address

Car VIN number

Car model

License plate

Insurance card number

Photo

Vehicle diagnostics

Geolocation

What IT architecture would be most appropriate for this mobile platform?

A.

Peer-to-peer architecture.

B.

Client-server architecture.

C.

Plug-in-based architecture.

D.

Service-oriented architecture.

Full Access
Question # 18

A developer is designing a new system that allows an organization's helpdesk to remotely connect into the device of the individual to provide support Which of the following will be a privacy technologist's primary concern"?

A.

Geofencing

B.

Geo-tracking

C.

Geo-tagging

D.

Geolocation

Full Access
Question # 19

SCENARIO

Kyle is a new security compliance manager who will be responsible for coordinating and executing controls to ensure compliance with the company's information security policy and industry standards. Kyle is also new to the company, where collaboration is a core value. On his first day of new-hire orientation, Kyle's schedule included participating in meetings and observing work in the IT and compliance departments.

Kyle spent the morning in the IT department, where the CIO welcomed him and explained that her department was responsible for IT governance. The CIO and Kyle engaged in a conversation about the importance of identifying meaningful IT governance metrics. Following their conversation, the CIO introduced Kyle to Ted and Barney. Ted is implementing a plan to encrypt data at the transportation level of the organization's wireless network. Kyle would need to get up to speed on the project and suggest ways to monitor effectiveness once the implementation was complete. Barney explained that his short-term goals are to establish rules governing where data can be placed and to minimize the use of offline data storage.

Kyle spent the afternoon with Jill, a compliance specialist, and learned that she was exploring an initiative for a compliance program to follow self-regulatory privacy principles. Thanks to a recent internship, Kyle had some experience in this area and knew where Jill could find some support. Jill also shared results of the company’s privacy risk assessment, noting that the secondary use of personal information was considered a high risk.

By the end of the day, Kyle was very excited about his new job and his new company. In fact, he learned about an open position for someone with strong qualifications and experience with access privileges, project standards board approval processes, and application-level obligations, and couldn’t wait to recommend his friend Ben who would be perfect for the job.

Ted's implementation is most likely a response to what incident?

A.

Encryption keys were previously unavailable to the organization's cloud storage host.

B.

Signatureless advanced malware was detected at multiple points on the organization's networks.

C.

Cyber criminals accessed proprietary data by running automated authentication attacks on the organization's network.

D.

Confidential information discussed during a strategic teleconference was intercepted by the organization's top competitor.

Full Access
Question # 20

What is the distinguishing feature of asymmetric encryption?

A.

It has a stronger key for encryption than for decryption.

B.

It employs layered encryption using dissimilar methods.

C.

It uses distinct keys for encryption and decryption.

D.

It is designed to cross operating systems.

Full Access
Question # 21

What Privacy by Design (PbD) element should include a de-identification or deletion plan?

A.

Categorization.

B.

Remediation.

C.

Retention.

D.

Security

Full Access
Question # 22

What has been found to undermine the public key infrastructure system?

A.

Man-in-the-middle attacks.

B.

Inability to track abandoned keys.

C.

Disreputable certificate authorities.

D.

Browsers missing a copy of the certificate authority's public key.

Full Access
Question # 23

Value sensitive design focuses on which of the following?

A.

Quality and benefit.

B.

Ethics and morality.

C.

Confidentiality and integrity.

D.

Consent and human rights.

Full Access
Question # 24

SCENARIO

Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them.

You also recall a recent visit to the Records Storage Section, often termed “The Dungeon” in the basement of the old hospital next to the modern facility, where you noticed a multitude of paper records. Some of these were in crates marked by years, medical condition or alphabetically by patient name, while others were in undifferentiated bundles on shelves and on the floor. The back shelves of the section housed data tapes and old hard drives that were often unlabeled but appeared to be years old. On your way out of the dungeon, you noticed just ahead of you a small man in a lab coat who you did not recognize. He carried a batch of folders under his arm, apparently records he had removed from storage.

Which cryptographic standard would be most appropriate for protecting patient credit card information in the records system?

A.

Asymmetric Encryption

B.

Symmetric Encryption

C.

Obfuscation

D.

Hashing

Full Access
Question # 25

What is the main reason a company relies on implied consent instead of explicit consent from a user to process her data?

A.

The implied consent model provides the user with more detailed data collection information.

B.

To secure explicit consent, a user's website browsing would be significantly disrupted.

C.

An explicit consent model is more expensive to implement.

D.

Regulators prefer the implied consent model.

Full Access
Question # 26

SCENARIO

Tom looked forward to starting his new position with a U.S —based automobile leasing company (New Company), now operating in 32 states. New Company was recently formed through the merger of two prominent players, one from the eastern region (East Company) and one from the western region (West Company). Tom, a Certified Information Privacy Technologist (CIPT), is New Company's first Information Privacy and Security Officer. He met today with Dick from East Company, and Harry, from West Company. Dick and Harry are veteran senior information privacy and security professionals at their respective companies, and continue to lead the east and west divisions of New Company. The purpose of the meeting was to conduct a SWOT (strengths/weaknesses/opportunities/threats) analysis for New Company. Their SWOT analysis conclusions are summarized below.

Dick was enthusiastic about an opportunity for the New Company to reduce costs and increase computing power and flexibility through cloud services. East Company had been contemplating moving to the cloud, but West Company already had a vendor that was providing it with software-as-a-service (SaaS). Dick was looking forward to extending this service to the eastern region. Harry noted that this was a threat as well, because West Company had to rely on the third party to protect its data.

Tom mentioned that neither of the legacy companies had sufficient data storage space to meet the projected growth of New Company, which he saw as a weakness. Tom stated that one of the team's first projects would be to construct a consolidated New Company data warehouse. Tom would personally lead this project and would be held accountable if information was modified during transmission to or during storage in the new data warehouse.

Tom, Dick and Harry agreed that employee network access could be considered both a strength and a weakness. East Company and West Company had strong performance records in this regard; both had robust network access controls that were working as designed. However, during a projected year-long transition period, New Company employees would need to be able to connect to a New Company network while retaining access to the East Company and West Company networks.

Which statement is correct about addressing New Company stakeholders’ expectations for privacy?

A.

New Company should expect consumers to read the company’s privacy policy.

B.

New Company should manage stakeholder expectations for privacy even when the stakeholders‘ data is not held by New Company.

C.

New Company would best meet consumer expectations for privacy by adhering to legal requirements.

D.

New Company's commitment to stakeholders ends when the stakeholders’ data leaves New Company.

Full Access
Question # 27

Which of the following is NOT a step in the methodology of a privacy risk framework?

A.

Assessment.

B.

Monitoring.

C.

Response.

D.

Ranking.

Full Access
Question # 28

What is an example of a just-in-time notice?

A.

A warning that a website may be unsafe.

B.

A full organizational privacy notice publicly available on a website

C.

A credit card company calling a user to verify a purchase before itis authorized

D.

Privacy information given to a user when he attempts to comment on an online article.

Full Access
Question # 29

An organization is considering launching enhancements to improve security and authentication mechanisms in their products. To better identify the user and reduce friction from the authentication process, they plan to track physical attributes of an individual. A privacy technologist assessing privacy implications would be most interested in which of the following?

A.

The purpose of the data tracking.

B.

That the individual is aware tracking is occurring.

C.

The authentication mechanism proposed.

D.

The encryption of individual physical attributes.

Full Access
Question # 30

A key principle of an effective privacy policy is that it should be?

A.

Written in enough detail to cover the majority of likely scenarios.

B.

Made general enough to maximize flexibility in its application.

C.

Presented with external parties as the intended audience.

D.

Designed primarily by the organization's lawyers.

Full Access
Question # 31

Which of the following is considered a records management best practice?

A.

Archiving expired data records and files.

B.

Storing decryption keys with their associated backup systems.

C.

Implementing consistent handling practices across all record types.

D.

Using classification to determine access rules and retention policy.

Full Access
Question # 32

SCENARIO

Clean-Q is a company that offers house-hold and office cleaning services. The company receives requests from consumers via their website and telephone, to book cleaning services. Based on the type and size of service, Clean-Q then contracts individuals that are registered on its resource database - currently managed in-house by Clean-Q IT Support. Because of Clean-Q's business model, resources are contracted as needed instead of permanently employed.

The table below indicates some of the personal information Clean-Q requires as part of its business operations:

Clean-Q has an internal employee base of about 30 people. A recent privacy compliance exercise has been conducted to align employee data management and human resource functions with applicable data protection regulation. Therefore, the Clean-Q permanent employee base is not included as part of this scenario.

With an increase in construction work and housing developments, Clean-Q has had an influx of requests for cleaning services. The demand has overwhelmed Clean-Q's traditional supply and demand system that has caused some overlapping bookings.

Ina business strategy session held by senior management recently, Clear-Q invited vendors to present potential solutions to their current operational issues. These vendors included Application developers and Cloud-Q’s solution providers, presenting their proposed solutions and platforms.

The Managing Director opted to initiate the process to integrate Clean-Q's operations with a cloud solution (LeadOps) that will provide the following solution one single online platform: A web interface that Clean-Q accesses for the purposes of resource and customer management. This would entail uploading resource and customer information.

  • A customer facing web interface that enables customers to register, manage and submit cleaning service requests online.
  • A resource facing web interface that enables resources to apply and manage their assigned jobs.
  • An online payment facility for customers to pay for services.

Which question would you most likely ask to gain more insight about LeadOps and provide practical privacy recommendations?

A.

What is LeadOps’ annual turnover?

B.

How big is LeadOps’ employee base?

C.

Where are LeadOps' operations and hosting services located?

D.

Does LeadOps practice agile development and maintenance of their system?

Full Access