
Pass Your Exam With 100% Verified CIPP-US Exam Questions
CIPP-US Dumps PDF - CIPP-US Real Exam Questions Answers
IAPP CIPP-US (Certified Information Privacy Professional/United States (CIPP/US)) Exam is one of the most sought-after certifications for professionals who are looking to establish themselves as experts in the field of data privacy. CIPP-US exam is designed to test the candidates' knowledge of the US privacy laws, regulations, and standards that govern the collection, storage, and sharing of personal data. The CIPP-US certification is recognized globally and is highly valued by organizations looking to hire professionals with expertise in privacy laws and regulations.
NEW QUESTION # 50
A large online bookseller decides to contract with a vendor to manage Personal Information (PI). What is the least important factor for the company to consider when selecting the vendor?
- A. The vendor's employee retention rates
- B. The vendor's financial health
- C. The vendor's reputation
- D. The vendor's employee training program
Answer: B
NEW QUESTION # 51
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
- A. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
- B. An international court ruling on personal information held in the commercial sector.
- C. A code of responsibilities for medical establishments to uphold privacy laws.
- D. A bill of rights for individuals seeking access to their personal information.
Answer: D
Explanation:
Explanation/Reference: http://documents1.worldbank.org/curated/en/751621525705087132/text/WPS8431.txt
NEW QUESTION # 52
When developing a company privacy program, which of the following relationships will most help a privacy professional develop useful guidance for the organization?
- A. Relationships with company leaders responsible for approving, implementing, and periodically reviewing the corporate privacy program.
- B. Relationships with individuals within the privacy professional community who are able to share expertise and leading practices for different industries.
- C. Relationships with individuals across company departments and at different levels in the organization's hierarchy.
- D. Relationships with clients, vendors, and customers whose data will be primarily collected and used throughout the organizational program.
Answer: C
Explanation:
IAPP Book, Section 4.3.1.1, paragraph 3.
NEW QUESTION # 53
Which of the following federal agencies does NOT enforce the Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA)?
- A. The Federal Trade Commission
- B. The Office of the Comptroller of the Currency
- C. The Department of Health and Human Services
- D. The Consumer Financial Protection Bureau
Answer: C
Explanation:
* The Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA) is a federal regulation that requires any person or entity that maintains or possesses consumer information derived from consumer reports to dispose of such information in a secure and proper manner1.
* The Disposal Rule aims to protect consumers from identity theft and fraud by preventing unauthorized access to or use of their personal information1.
* The Disposal Rule is enforced by several federal agencies, depending on the type and sector of the entity that is subject to the rule1. These agencies include:
* The Federal Trade Commission (FTC), which has general authority over most entities that are not specifically regulated by other agencies2.
* The Consumer Financial Protection Bureau (CFPB), which has authority over consumer financial products and services, such as banks, credit unions, lenders, debt collectors, and credit reporting agencies3.
* The Office of the Comptroller of the Currency (OCC), which has authority over national banks and federal savings associations4.
* The Federal Deposit Insurance Corporation (FDIC), which has authority over state-chartered banks that are not members of the Federal Reserve System and state-chartered savings associations5.
* The Board of Governors of the Federal Reserve System (FRB), which has authority over state-chartered banks that are members of the Federal Reserve System, bank holding companies, and certain nonbank subsidiaries of bank holding companies.
* The National Credit Union Administration (NCUA), which has authority over federally insured credit unions.
* The Securities and Exchange Commission (SEC), which has authority over brokers, dealers, investment companies, and investment advisers.
* The Commodity Futures Trading Commission (CFTC), which has authority over commodity futures and options markets and intermediaries.
* The Department of Health and Human Services (HHS) is NOT one of the federal agencies that enforces the Disposal Rule under FACTA. HHS has authority over health information privacy and security under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH), but not under FACTA.
References: 1: Disposing of Consumer Report Information? Rule Tells How 2: FTC Enforcement 3: CFPB Enforcement 4: OCC Enforcement 5: FDIC Enforcement : [FRB Enforcement] : [NCUA Enforcement] : [SEC Enforcement] : [CFTC Enforcement] : [HHS Enforcement]
NEW QUESTION # 54
Most states with data breach notification laws indicate that notice to affected individuals must be sent in the
"most expeditious time possible without unreasonable delay." By contrast, which of the following states currently imposes a definite limit for notification to affected individuals?
- A. Maine
- B. California
- C. New York
- D. Florida
Answer: D
Explanation:
Explanation/Reference: https://www.itgovernanceusa.com/data-breach-notification-laws
NEW QUESTION # 55
A covered entity suffers a ransomware attack that affects the personal health information (PHI) of more than
500 individuals. According to Federal law under HIPAA, which of the following would the covered entity NOT have to report the breach to?
- A. The affected individuals
- B. Department of Health and Human Services
- C. Medical providers
- D. The local media
Answer: C
Explanation:
According to the Health Insurance Portability and Accountability Act (HIPAA), a covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits any health information in electronic form in connection with a transaction covered by HIPAA. A covered entity must report a breach of unsecured protected health information (PHI) to the following parties:
* The Department of Health and Human Services (HHS), which is the federal agency responsible for enforcing HIPAA and issuing regulations and guidance on privacy and security issues. A covered entity must notify HHS of a breach affecting 500 or more individuals without unreasonable delay and in no case later than 60 days after discovery of the breach. A covered entity must also notify HHS of breaches affecting fewer than 500 individuals within 60 days of the end of the calendar year in which the breaches occurred.
* The affected individuals, who are the individuals whose PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach. A covered entity must notify the affected individuals without unreasonable delay and in no case later than 60 days after discovery of the breach. The notification must be in writing by first-class mail or, if the individual agrees, by electronic mail. The notification must include a brief description of the breach, the types of information involved, the steps the individual should take to protect themselves, the steps the covered entity is taking to investigate and mitigate the breach, and the contact information of the covered entity.
* The local media, if the breach affects more than 500 residents of a state or jurisdiction. A covered entity must notify prominent media outlets serving the state or jurisdiction without unreasonable delay and in no case later than 60 days after discovery of the breach. The notification must include the same information as the notification to the affected individuals.
A covered entity does not have to report the breach to medical providers, unless they are also affected individuals or business associates of the covered entity. A business associate is a person or entity that performs certain functions or activities on behalf of, or provides certain services to, a covered entity that involve the use or disclosure of PHI. A covered entity must have a written contract or agreement with its business associates that requires them to protect the privacy and security of PHI and report any breaches to the covered entity.
References:
* IAPP CIPP/US Body of Knowledge, Domain II: Limits on Private-sector Collection and Use of Data, Section C: Sector-specific Requirements for Health Information
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 2: Limits on Private- sector Collection and Use of Data, Section 2.3: Sector-specific Requirements for Health Information
* Practice Exam - International Association of Privacy Professionals
NEW QUESTION # 56
Which of these organizations would be required to provide its customers with an annual privacy notice?
- A. The Golden Gavel Auction House.
- B. The Four Winds Tribal College.
- C. The King County Savings and Loan.
- D. The Breezy City Housing Commission.
Answer: C
Explanation:
The annual privacy notice requirement under the Gramm-Leach-Bliley Act (GLBA) applies to financial institutions that collect nonpublic personal information from customers and disclose it to nonaffiliated third parties, unless they qualify for an exception. A financial institution is any entity that engages in activities that are financial in nature or incidental to such activities, as defined by section 4(k) of the Bank Holding Company Act of 1956. The King County Savings and Loan is a financial institution under this definition, as it engages in lending money and accepting deposits. Therefore, it is required to provide its customers with an annual privacy notice, unless it meets the conditions for an exception. The Four Winds Tribal College, the Golden Gavel Auction House, and the Breezy City Housing Commission are not financial institutions under the GLBA, as they do not engage in activities that are financial in nature or incidental to such activities. Therefore, they are not required to provide their customers with an annual privacy notice under the GLBA. References:
* Amendment to the Annual Privacy Notice Requirement Under the Gramm-Leach-Bliley Act, section I.
Background, paragraph 2.
* 17 CFR ยง 248.5 - Annual privacy notice to customers required., paragraph (a) (1).
* IAPP CIPP/US Study Guide, page 65.
NEW QUESTION # 57
Which of the following types of information would an organization generally NOT be required to disclose to law enforcement?
- A. Information about workspace injuries under OSHA requirements
- B. Personal health information under the HIPAA Privacy Rule
- C. Information about medication errors under the Food, Drug and Cosmetic Act
- D. Money laundering information under the Bank Secrecy Act of 1970
Answer: B
Explanation:
These are "permissive" disclosures. The covered entity or business associate may refuse. https://www.eff.org/issues/law-enforcement-
NEW QUESTION # 58
Which of the following is an important implication of the Dodd-Frank Wall Street Reform and Consumer Protection Act?
- A. Financial institutions must avoid collecting a customer's sensitive personal information
- B. Financial institutions must use a prescribed level of encryption for most types of customer records
- C. Financial institutions must help ensure a customer's understanding of products and services
- D. Financial institutions must cease sending e-mails and other forms of advertising to customers who opt out of direct marketing
Answer: C
Explanation:
The Dodd-Frank Act created the Consumer Financial Protection Bureau (CFPB) as an independent agency within the Federal Reserve System. The CFPB has the authority to regulate consumer financial products and services, such as mortgages, credit cards, student loans, and payday loans. One of the main objectives of the CFPB is to promote transparency, fairness, and consumer choice in the financial marketplace. The CFPB has issued rules and guidance to require financial institutions to provide clear and accurate information to consumers about the costs, risks, and benefits of their products and services. The CFPB also has the power to enforce consumer protection laws and prohibit unfair, deceptive, or abusive acts or practices by financial institutions123 References: 1: Dodd-Frank Wall Street Reform and Consumer Protection Act, Title X, Subtitle A, Section 1011. 2: Consumer Financial Protection Bureau, Wikipedia. 3: Dodd-Frank Act: What It Does, Major Components, and Criticisms, Investopedia.
NEW QUESTION # 59
In 2012, the White House and the FTC both issued reports advocating a new approach to privacy enforcement that can best be described as what?
- A. Comprehensive.
- B. Self-regulatory.
- C. Notice and choice.
- D. Harm-based.
Answer: A
Explanation:
In 2012, the White House released a report titled "Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy", which proposed a Consumer Privacy Bill of Rights based on the Fair Information Practice Principles (FIPPs). The report called for a comprehensive privacy framework that would apply to all commercial sectors and all personal data, regardless of the technology or business model involved. The report also urged Congress to enact legislation to implement the framework and empower the FTC to enforce it. Similarly, the FTC released a report titled "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers", which outlined a set of best practices for businesses to protect consumer privacy and foster innovation. The report also advocated for a comprehensive privacy framework that would cover both online and offline data, and apply to all entities that collect or use consumer data that can be reasonably linked to a specific consumer, computer, or device. The report also recommended that Congress consider enacting baseline privacy legislation and giving the FTC rulemaking authority to implement it. Therefore, both reports can be described as advocating a comprehensive approach to privacy enforcement, rather than a harm-based, self-regulatory, or notice and choice approach. References: White House Report, FTC Report, IAPP CIPP/US Study Guide (p. 31-32)
NEW QUESTION # 60
Which is an exception to the general prohibitions on telephone monitoring that exist under the
U.S.Wiretap Act?
- A. Inter-company communications exception
- B. Ordinary course of business exception
- C. Internet calls exception
- D. Call center exception
Answer: B
Explanation:
The U.S. Wiretap Act prohibits the interception and disclosure of wire, oral, or electronic communications, unless one of the statutory exceptions applies. One of these exceptions is the ordinary course of business exception, which allows an employer or service provider to intercept communications that are made in the ordinary course of its business, such as for quality control, training, or security purposes. This exception does not apply to communications that are not related to the business, such as personal calls or emails, or to communications that are intercepted for other reasons, such as harassment, discrimination, or retaliation. The scope and applicability of this exception may vary depending on the context, the consent of the parties, and the state law.
NEW QUESTION # 61
Which federal act does NOT contain provisions for preempting stricter state laws?
- A. The CAN-SPAM Act
- B. The Children's Online Privacy Protection Act (COPPA)
- C. The Fair and Accurate Credit Transactions Act (FACTA)
- D. The Telemarketing Consumer Protection and Fraud Prevention Act
Answer: D
Explanation:
The federal act that does NOT contain provisions for preempting stricter state laws is the Telemarketing Consumer Protection and Fraud Prevention Act1. This act authorizes the Federal Trade Commission (FTC) to establish and enforce rules for telemarketing practices, such as the Do Not Call Registry, the prohibition of robocalls, and the disclosure of material information2. However, the act also explicitly states that it does not "annul, alter, or affect, or exempt any person subject to the provisions of this section from complying with, the laws of any State with respect to telemarketing practices, except to the extent that those laws are inconsistent with any provision of this section, and then only to the extent of the inconsistency"1. This means that states can enact and enforce their own laws regarding telemarketing, as long as they are not less protective than the federal law. In contrast, the other three acts listed in the question do contain preemption clauses that limit or override the authority of states to regulate certain aspects of electronic communications, online privacy, and credit transactions345. References: 1: Telemarketing Consumer Protection and Fraud Prevention Act2: Telemarketing Sales Rule | Federal Trade Commission3: CAN-SPAM Act: A Compliance Guide for Business4: Children's Online Privacy Protection Rule ("COPPA") | Federal Trade Commission5: Fair and Accurate Credit Transactions Act of 2003 - Wikipedia : IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 5: Federal Trade Commission and Consumer Privacy, p. 144-145, 149-150, 154-155
NEW QUESTION # 62
SCENARIO
Please use the following to answer the next QUESTION
Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your homework?" Matt asked hopefully.
"No," the boy said. "I'm filling out a survey."
Matt looked over his son's shoulder at his computer screen. "What kind of survey?" "It's asking QUESTIONs about my opinions."
"Let me see," Matt said, and began reading the list of
QUESTION s that his son had already answered. "It's asking your opinions about the government and citizenship. That's a little odd. You're only ten." Matt wondered how the web link to the survey had ended up in his son's email inbox. Thinking the message might have been sent to his son by mistake he opened it and read it. It had come from an entity called the Leadership Project, and the content and the graphics indicated that it was intended for children. As Matt read further he learned that kids who took the survey were automatically registered in a contest to win the first book in a series about famous leaders.
To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if he had been prompted to give information about himself in order to take the survey. His son told him he had been asked to give his name, address, telephone number, and date of birth, and to answer QUESTIONs about his favorite games and toys.
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from marketers advertising products for children in his son's inbox, and he decided it was time to report the incident to the proper authorities.
Depending on where Matt lives, the marketer could be prosecuted for violating which of the following?
- A. Investigative Consumer Reporting Agencies Act.
- B. Consumer Bill of Rights.
- C. Red Flag Rules.
- D. Unfair and Deceptive Acts and Practices laws.
Answer: D
NEW QUESTION # 63
What role does the U.S. Constitution play in the area of workplace privacy?
- A. It provides significant protections to federal and state governments, but not to private-sector employment
- B. It provides contractual protections to members of labor unions, but not to employees at will
- C. It provides legal precedent for physical information security, but not for electronic security
- D. It provides enforcement resources to large employers, but not to small businesses
Answer: A
Explanation:
The U.S. Constitution has significant workplace privacy provisions that apply to the federal and state governments, but they do not affect private-sector employment. Notably, the Fourth Amendment prohibits unreasonable searches and seizures by state actors. Courts have interpreted this amendment to place limits on the ability of government employers to search employees' private spaces, such as lockers and desks.4 Some states, including California, have extended their constitutional rights to privacy to private-sector employees.5 In general for private-sector actors, however, there is no state action, and no constitutional law governs employment privacy
NEW QUESTION # 64
What was the original purpose of the Foreign Intelligence Surveillance Act?
- A. To further define what information can reasonably be under surveillance in public places under the USA PATRIOT Act, such as Internet access in public libraries.
- B. To further clarify a reasonable expectation of privacy stemming from the Katz v. United States decision.
- C. To further clarify when a warrant is not required for a wiretap performed internally by the telephone company outside the suspect's home, stemming from the Olmstead v. United States decision.
- D. To further define a framework for authorizing wiretaps by the executive branch for national security purposes under Article II of the Constitution.
Answer: A
NEW QUESTION # 65
Which action is prohibited under the Electronic Communications Privacy Act of 1986?
- A. Monitoring all employee telephone calls
- B. Accessing stored communications with the consent of the sender or recipient of the message
- C. Intercepting electronic communications and unauthorized access to stored communications
- D. Monitoring employee telephone calls of a personal nature
Answer: C
Explanation:
The Electronic Communications Privacy Act of 1986 (ECPA) is a federal law that protects the privacy of wire, oral, and electronic communications while they are being made, in transit, or stored on computers. The ECPA has three titles: Title I prohibits the intentional interception, use, or disclosure of wire, oral, or electronic communications, except for certain exceptions, such as consent, provider protection, or law enforcement purposes. Title II, also known as the Stored Communications Act (SCA), prohibits the unauthorized access to or disclosure of stored wire or electronic communications, such as email, voicemail, or online messages, except for certain exceptions, such as consent, provider protection, or law enforcement purposes. Title III regulates the installation and use of pen register and trap and trace devices, which record the numbers dialed to or from a telephone line, but not the content of the communications. Therefore, the action that is prohibited under the ECPA is intercepting electronic communications and unauthorized access to stored communications, which are covered by Title I and Title II of the Act, respectively.
NEW QUESTION # 66
Acme Student Loan Company has developed an artificial intelligence algorithm that determines whether an individual is likely to pay their bill or default. A person who is determined by the algorithm to be more likely to default will receive frequent payment reminder calls, while those who are less likely to default will not receive payment reminders.
Which of the following most accurately reflects the privacy concerns with Acme Student Loan Company using artificial intelligence in this manner?
- A. If the algorithm's methodology is disclosed to consumers, then it is acceptable for Acme to have a disparate impact on protected classes.
- B. If the algorithm uses information about protected classes to make automated decisions, Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output.
- C. If the algorithm uses risk factors that impact the automatic decision engine. Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output.
- D. If the algorithm makes automated decisions based on risk factors and public information, Acme need not determine if the algorithm has a disparate impact on protected classes.
Answer: D
NEW QUESTION # 67
......
IAPP CIPP-US certification is ideal for privacy professionals, lawyers, compliance officers, and anyone who wants to stay up-to-date with the latest privacy laws and regulations in the US. Certified Information Privacy Professional/United States (CIPP/US) certification demonstrates an individual's commitment to the privacy field and enhances their credibility as a privacy expert. Moreover, the certification provides access to a global network of privacy professionals and resources, including a vast library of articles, webinars, and conferences, which can help individuals stay informed and connected in the privacy community.
CIPP-US Dumps 100 Pass Guarantee With Latest Demo: https://learningtree.actualvce.com/IAPP/CIPP-US-valid-vce-dumps.html