[2024年08月]に更新されたCertified Information Privacy Professional CIPP-C試験練習テスト問題集豪華セット! [Q25-Q45]

Share

[2024年08月]に更新されたCertified Information Privacy Professional CIPP-C試験練習テスト問題集豪華セット!

2024年最新のに更新されたCIPP-CのPDFはCIPP-C本日更新のテスト無料最新!

質問 # 25
SCENARIO
Please use the following to answer the next question:
Joe is the new privacy manager for Who-R-U, a Canadian business that provides DNA analysis. The company is headquartered in Montreal, and all of its employees are located there. The company offers its services to Canadians only: Its website is in English and French, it accepts only Canadian currency, and it blocks internet traffic from outside of Canada (although this solution doesn't prevent all non-Canadian traffic). It also declines to process orders that request the DNA report to be sent outside of Canada, and returns orders that show a non-Canadian return address.
Bob, the President of Who-R-U, thinks there is a lot of interest for the product in the EU, and the company is exploring a number of plans to expand its customer base.
The first plan, collegially called We-Track-U, will use an app to collect information about its current Canadian customer base. The expansion will allow its Canadian customers to use the app while traveling abroad. He suggests that the company use this app to gather location information. If the plan shows promise, Bob proposes to use push notifications and text messages to encourage existing customers to pre-register for an EU version of the service. Bob calls this work plan, We-Text-U. Once the company has gathered enough pre- registrations, it will develop EU-specific content and services.
Another plan is called Customer for Life. The idea is to offer additional services through the company's app, like storage and sharing of DNA information with other applications and medical providers. The company's contract says that it can keep customer DNA indefinitely, and use it to offer new services and market them to customers. It also says that customers agree not to withdraw direct marketing consent. Paul, the marketing director, suggests that the company should fully exploit these provisions, and that it can work around customers' attempts to withdraw consent because the contract invalidates them.
The final plan is to develop a brand presence in the EU. The company has already begun this process. It is in the process of purchasing the naming rights for a building in Germany, which would come with a few offices that Who-R-U executives can use while traveling internationally. The office doesn't include any technology or infrastructure; rather, it's simply a room with a desk and some chairs.
On a recent trip concerning the naming-rights deal, Bob's laptop is stolen. The laptop held unencrypted DNA reports on 5,000 Who-R-U customers, all of whom are residents of Canada. The reports include customer name, birthdate, ethnicity, racial background, names of relatives, gender, and occasionally health information.
Who-R-U is NOT required to notify the local German DPA about the laptop theft because?

  • A. The laptop belonged to a company located in Canada.
  • B. There is no evidence that the thieves have accessed the data on the laptop.
  • C. The data isn't considered personally identifiable financial information.
  • D. The company isn't a controller established in the Union.

正解:D


質問 # 26
What can be concluded from the Blood Tribe case regarding the Privacy Commissioner's access to information?

  • A. The commissioner cannot ask an organization to prove that a document is privileged.
  • B. The commissioner can officially request proof that desired information is subject to solicitor-client privilege.
  • C. The commissioner cannot receive information unless it is gathered under oath.
  • D. The commissioner can compel the production of all documents that are relevant to the investigation.

正解:B


質問 # 27
Which area of privacy is a lead supervisory authority's (LSA) MAIN concern?

  • A. Data access disputes
  • B. Special categories of data
  • C. Data subject rights
  • D. Cross-border processing

正解:D


質問 # 28
Who has rulemaking authority for the Fair Credit Reporting Act (FCRA) and the Fair and Accurate Credit Transactions Act (FACTA)?

  • A. The Consumer Financial Protection Bureau
  • B. State Attorneys General
  • C. The Department of Commerce
  • D. The Federal Trade Commission

正解:A


質問 # 29
Which GDPR principle would a Spanish employer most likely depend upon to annually send the personal data of its employees to the national tax authority?

  • A. The protection of the vital interest of the employees.
  • B. The legitimate interest of the public administration.
  • C. The legal obligation of the employer.
  • D. The consent of the employees.

正解:C


質問 # 30
In which case would a controller who has undertaken a DPIA most likely need to consult with a supervisory authority?

  • A. Where the DPIA identifies that the processing being proposed collects the sensitive data of EU citizens.
  • B. Where the DPIA identifies risks that will require insurance for protecting its business interests.
  • C. Where the DPIA identifies that personal data needs to be transferred to other countries outside of the EEA.
  • D. Where the DPIA identifies high risks to individuals' rights and freedoms that the controller can take steps to reduce.

正解:D


質問 # 31
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?

  • A. The data subject already has information regarding how his data will be used
  • B. Third-party data would be disclosed by providing such information to the data subject
  • C. The processing of the data subject's data is protected by appropriate technical measures
  • D. The provision of such information to the data subject would be too problematic

正解:A


質問 # 32
SCENARIO
Please use the following to answer the next question:
Anna and Frank both work at Ontario University. Anna is a lawyer responsible for data protection, while Frank is a lecturer in the engineering department. The University maintains a number of types of records:
* Student records, including names, student numbers, home addresses, pre-university information, university attendance and performance records, details of special educational needs and financial information.
* Staff records, including autobiographical materials (such as curricula, professional contact files, student evaluations and other relevant teaching files).
* Alumni records, including birthplaces, years of birth, dates of matriculation and conferrals of degrees.
These records are available to former students after registering through Ontario's Alumni portal.
Department for Education records, showing how certain demographic groups (such as first-generation students) could be expected, on average, to progress. These records do not contain names or identification numbers.
* Under their security policy, the University encrypts all of its personal data records in transit and at rest.
In order to improve his teaching, Frank wants to investigate how his engineering students perform in relational to Department for Education expectations. He has attended one of Anna's data protection training courses and knows that he should use no more personal data than necessary to accomplish his goal. He creates a program that will only export some student data: previous schools attended, grades originally obtained, grades currently obtained and first time university attended. He wants to keep the records at the individual student level. Mindful of Anna's training, Frank runs the student numbers through an algorithm to transform them into different reference numbers. He uses the same algorithm on each occasion so that he can update each record over time.
One of Anna's tasks is to complete the record of processing activities, as required by the GDPR. After receiving her email reminder, as required by the GDPR. After receiving her email reminder, Frank informs Anna about his performance database.
Ann explains to Frank that, as well as minimizing personal data, the University has to check that this new use of existing data is permissible. She also suspects that, under the GDPR, a risk analysis may have to be carried out before the data processing can take place. Anna arranges to discuss this further with Frank after she has done some additional research.
Frank wants to be able to work on his analysis in his spare time, so he transfers it to his home laptop (which is not encrypted). Unfortunately, when Frank takes the laptop into the University he loses it on the train. Frank has to see Anna that day to discuss compatible processing. He knows that he needs to report security incidents, so he decides to tell Anna about his lost laptop at the same time.
Before Anna determines whether Frank's performance database is permissible, what additional information does she need?

  • A. More information about the extent of the information loss.
  • B. More information about what students have been told and how the research will be used.
  • C. More information about Frank's data protection training.
  • D. More information about the algorithm Frank used to mask student numbers.

正解:B


質問 # 33
Which of the following describes the most likely risk for a company developing a privacy policy with standards that are much higher than its competitors?

  • A. Being more closely scrutinized for any breaches of policy
  • B. Getting accused of discriminatory practices
  • C. Attracting skepticism from auditors
  • D. Having a security system failure

正解:A


質問 # 34
SCENARIO
Please use the following to answer the next question:
The fitness company Vigotron has recently developed a new app called M-Health, which it wants to market on its website as a free download. Vigotron's marketing manager asks his assistant Emily to create a webpage that describes the app and specifies the terms of use. Emily, who is new at Vigotron, is excited about this task.
At her previous job she took a data protection class, and though the details are a little hazy, she recognizes that Vigotron is going to need to obtain user consent for use of the app in some cases. Emily sketches out the following draft, trying to cover as much as possible before sending it to Vigotron's legal department.
Registration Form
Vigotron's new M-Health app makes it easy for you to monitor a variety of health-related activities, including diet, exercise, and sleep patterns. M-Health relies on your smartphone settings (along with other third-party apps you may already have) to collect data about all of these important lifestyle elements, and provide the information necessary for you to enrich your quality of life. (Please click here to read a full description of the services that M-Health provides.) Vigotron values your privacy. The M-Heaith app allows you to decide which information is stored in it, and which apps can access your data. When your device is locked with a passcode, all of your health and fitness data is encrypted with your passcode. You can back up data stored in the Health app to Vigotron's cloud provider, Stratculous. (Read more about Stratculous here.) Vigotron will never trade, rent or sell personal information gathered from the M-Health app. Furthermore, we will not provide a customer's name, email address or any other information gathered from the app to any third- party without a customer's consent, unless ordered by a court, directed by a subpoena, or to enforce the manufacturer's legal rights or protect its business or property.
We are happy to offer the M-Health app free of charge. If you want to download and use it, we ask that you first complete this registration form. (Please note that use of the M-Health app is restricted to adults aged 16 or older, unless parental consent has been given to minors intending to use it.)
* First name:
* Surname:
* Year of birth:
* Email:
* Physical Address (optional*):
* Health status:
*If you are interested in receiving newsletters about our products and services that we think may be of interest to you, please include your physical address. If you decide later that you do not wish to receive these newsletters, you can unsubscribe by sending an email to [email protected] or send a letter with your request to the address listed at the bottom of this page.
Terms and Conditions
1.Jurisdiction. [...]
2.Applicable law. [...]
3.Limitation of liability. [...]
Consent
By completing this registration form, you attest that you are at least 16 years of age, and that you consent to the processing of your personal data by Vigotron for the purpose of using the M-Health app. Although you are entitled to opt out of any advertising or marketing, you agree that Vigotron may contact you or provide you with any required notices, agreements, or other information concerning the services by email or other electronic means. You also agree that the Company may send automated emails with alerts regarding any problems with the M-Health app that may affect your well being.
Emily sends the draft to Sam for review. Which of the following is Sam most likely to point out as the biggest problem with Emily's consent provision?

  • A. Processing health data requires explicit consent, but the form does not ask for explicit consent.
  • B. Direct marketing requires explicit consent, whereas the registration form only provides for a right to object
  • C. The provision of the fitness app should be made conditional on the consent to the data processing for direct marketing.
  • D. It is not legal to include fields requiring information regarding health status without consent.

正解:B


質問 # 35
A law enforcement subpoenas the ACME telecommunications company for access to text message records of a person suspected of planning a terrorist attack. The company had previously encrypted its text message records so that only the suspect could access this data.
What law did ACME violate by designing the service to prevent access to the information by a law enforcement agency?

  • A. USA Freedom Act
  • B. ECPA
  • C. CALEA
  • D. SCA

正解:C


質問 # 36
Which venture would be subject to the requirements of Section 5 of the Federal Trade Commission Act?

  • A. A national bank's no-fee checking promotion
  • B. A local nonprofit charity's fundraiser
  • C. An online merchant's free shipping offer
  • D. A city bus system's frequent rider program

正解:C


質問 # 37
Which falls under the jurisdiction of the Personal Information Protection and Electronic Documents Act (PIPEDA)?

  • A. Personal information such as names, titles and contact information used by businesses to communicate with employees regarding their profession.
  • B. Personal information disclosed across provincial or national borders by organizations such as credit reporting agencies or list marketers.
  • C. Personal health information (PHI) handled by private enterprises in provinces that have adopted substantially similar legislation.
  • D. Personal information collected by private businesses for journalistic or artistic purposes.

正解:B

解説:
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), the jurisdiction generally covers personal information used or disclosed in the course of commercial activity by federal works, undertakings, or businesses, or across provincial or national borders. Thus, personal information disclosed across provincial or national borders by organizations such as credit reporting agencies or list marketers falls under PIPEDA. This is outlined in PIPEDA itself, where it specifies the regulation of personal information in federal jurisdiction and in interprovincial and international transactions. Therefore, the correct answer is C.


質問 # 38
A small commercial business in Canada was preparing a mailing to its customers when the letters and the envelopes were mismatched, causing 500 of 1000 letters to be sent to the wrong recipients. The letters contained the name and mailing address of the clients as well as account numbers and account balances.
The business has discovered this error as clients called to report receiving the wrong letter and expressing concern that their information has been breached. Which of the following is the most appropriate next step to take?

  • A. The Office of the Privacy Commissioner (OPC) must be immediately notified.
  • B. A risk assessment must be completed to determine the real risk of significant harm (RROSH) to the clients.
  • C. The 500 clients who were impacted must be immediately notified.
  • D. All 1000 clients must be sent new letters.

正解:B


質問 # 39
An online company's privacy practices vary due to the fact that it offers a wide variety of services. How could it best address the concern that explaining them all would make the policies incomprehensible?

  • A. Identify uses of data in a privacy notice mailed to the data subject.
  • B. Use a layered privacy notice on its website and in its email communications.
  • C. Place a banner on its website stipulating that visitors agree to its privacy policy and terms of use by visiting the site.
  • D. Provide only general information about its processing activities and offer a toll-free number for more information.

正解:A


質問 # 40
What important action should a health care provider take if the she wants to qualify for funds under the Health Information Technology for Economic and Clinical Health Act (HITECH)?

  • A. Make electronic health records (EHRs) part of regular care
  • B. Keep electronic updates about the Health Insurance Portability and Accountability Act
  • C. Bill the majority of patients electronically for their health care
  • D. Send health information and appointment reminders to patients electronically

正解:A


質問 # 41
When hiring a data processor, which action would a data controller NOT be able to depend upon to avoid liability in the event of a security breach?

  • A. Maintaining evidence that the processor was the best possible market choice available.
  • B. Requiring that the processor directly notify the appropriate supervisory authority.
  • C. Conducting a risk assessment to analyze possible outsourcing threats.
  • D. Documenting due diligence steps taken in the pre-contractual stage.

正解:D


質問 # 42
According to Article 14 of the GDPR, how long does a controller have to provide a data subject with necessary privacy information, if that subject's personal data has been obtained from other sources?

  • A. As soon as possible after the first communication with the data subject.
  • B. Within a reasonable period after obtaining the personal data, but no later than one month.
  • C. Within a reasonable period after obtaining the personal data, but no later than eight weeks.
  • D. As soon as possible after obtaining the personal data.

正解:D


質問 # 43
In Ontario, personal information can be withheld from disclosure in a Freedom of Information (FOI) request.
The following information is included in a record that is the subject of a FOI request being handled by a hospital: employee name, employee title, employee designation, employee educational history, employee personal cell phone number, and feedback about the employee from a colleague.
Which of the following statements is accurate regarding what can be released?

  • A. No employee information can be released as it is information that was collected throughout the course of employment.
  • B. The employee designation is not to be released as it is considered employment history.
  • C. Employee name, title, and designation can be released as it is not classified as personal information.
  • D. Employee name and title can only be released if the employee consents

正解:C


質問 # 44
With respect to international transfers of personal data, the European Data Protection Board (EDPB) confirmed that derogations may be relied upon under what condition?

  • A. Only as a last resort and when interpreted restrictively.
  • B. When it has been determined that adequate protection can be performed.
  • C. Only if the Data Protection Impact Assessment (DPIA) shows low risk.
  • D. If the data controller has received preapproval from a Data Protection Authority (DPA), after submitting the appropriate documents.

正解:B


質問 # 45
......

全幅的な更新された問題集PDFのテストCIPP-C試験問題とアンサー:https://www.goshiken.com/IAPP/CIPP-C-mondaishu.html

100%無料CIPP-C試験問題集を試験簡単にパスせよ:https://drive.google.com/open?id=1yRkEILjgzUo911JUM5OlEbFsTsFrX8hZ