
CIPP-USブレーン問題集PDF、IAPP CIPP-US試験問題豪華お試しセット
2025年最新されたCIPP-USサンプル問題は信頼され続けるCIPP-USテストエンジン
CIPP-US認定試験は、法律、コンプライアンス、リスク管理、IT、データセキュリティなどの分野で働く専門家に最適です。この認定は、データプライバシーとセキュリティが重要な医療、金融、テクノロジーなどの業界で働く人々にとっても有益です。CIPP-US認定は、世界中の雇用主から認められ、データプライバシーとセキュリティの分野でキャリアを進めたいと考える専門家にとって必須の資格です。
質問 # 34
SCENARIO
Please use the following to answer the next QUESTION:
Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical fitness goals through classes, individual instruction, and access to an extensive indoor gym. She has owned the company for ten years and has always been concerned about protecting customer's privacy while maintaining the highest level of service. She is proud that she has built long-lasting customer relationships.
Although Cheryl and her staff have tried to make privacy protection a priority, the company has no formal privacy policy. So Cheryl hired Janice, a privacy professional, to help her develop one.
After an initial assessment, Janice created a first of a new policy. Cheryl read through the draft and was concerned about the many changes the policy would bring throughout the company. For example, the draft policy stipulates that a customer's personal information can only be held for one year after paying for a service such as a session with personal trainer. It also promises that customer information will not be shared with third parties without the written consent of the customer. The wording of these rules worry Cheryl since stored personal information often helps her company to serve her customers, even if there are long pauses between their visits. In addition, there are some third parties that provide crucial services, such as aerobics instructors who teach classes on a contract basis. Having access to customer files and understanding the fitness levels of their students helps instructors to organize their classes.
Janice understood Cheryl's concerns and was already formulating some ideas for revision. She tried to put Cheryl at ease by pointing out that customer data can still be kept, but that it should be classified according to levels of sensitivity. However, Cheryl was skeptical. It seemed that classifying data and treating each type differently would cause undue difficulties in the company's day-to-day operations. Cheryl wants one simple data storage and access system that any employee can access if needed.
Even though the privacy policy was only a draft, she was beginning to see that changes within her company were going to be necessary. She told Janice that she would be more comfortable with implementing the new policy gradually over a period of several months, one department at a time. She was also interested in a layered approach by creating documents listing applicable parts of the new policy for each department.
What is the most likely risk of Fitness Coach, Inc. adopting Janice's first draft of the privacy policy?
- A. Leaving the company susceptible to violations by setting unrealistic goals
- B. Not being in standard compliance with applicable laws
- C. Showing a lack of trust in the organization's privacy practices
- D. Failing to meet the needs of customers who are concerned about privacy
正解:A
質問 # 35
What role does the U.S. Constitution play in the area of workplace privacy?
- A. It provides legal precedent for physical information security, but not for electronic security
- B. It provides enforcement resources to large employers, but not to small businesses
- C. It provides significant protections to federal and state governments, but not to private-sector employment
- D. It provides contractual protections to members of labor unions, but not to employees at will
正解:C
解説:
The U.S. Constitution has significant workplace privacy provisions that apply to the federal and state governments, but they do not affect private-sector employment. Notably, the Fourth Amendment prohibits unreasonable searches and seizures by state actors. Courts have interpreted this amendment to place limits on the ability of government employers to search employees' private spaces, such as lockers and desks.4 Some states, including California, have extended their constitutional rights to privacy to private-sector employees.5 In general for private-sector actors, however, there is no state action, and no constitutional law governs employment privacy
質問 # 36
What practice does the USA FREEDOM Act NOT authorize?
- A. The bulk collection of telephone data and internet metadata
- B. An extension of the expiration for roving wiretaps
- C. An increase in the maximum penalty for material support to terrorism
- D. Emergency exceptions that allows the government to target roamers
正解:A
解説:
The USA FREEDOM Act is a law that was enacted in 2015 to reform the surveillance practices of the U.S.
government. The law was a response to the revelations by Edward Snowden about the mass collection of phone records and internet data by the National Security Agency (NSA) under the authority of Section 215 of the USA PATRIOT Act. The USA FREEDOM Act ended the bulk collection of telephone data and internet metadata by the NSA, and instead required the government to obtain a specific order from the Foreign Intelligence Surveillance Court (FISC) to access such data from the telecommunication providers. The law also authorized the following practices:
* Emergency exceptions that allow the government to target roamers: The law allows the government to temporarily target a non-U.S. person who is using a phone number or identifier of a U.S. person, without a court order, if there is an emergency situation that involves a threat of death or serious bodily harm.
The government must obtain a court order within seven days to continue the surveillance.
* An increase in the maximum penalty for material support to terrorism: The law increases the maximum prison term for providing material support or resources to a foreign terrorist organization from 15 years to 20 years.
* An extension of the expiration for roving wiretaps: The law extends the sunset date for the roving wiretap provision of the USA PATRIOT Act, which allows the government to obtain a single order from the FISC to conduct surveillance on a target who switches devices or locations, without specifying the device or location. The law extends the expiration date from June 1, 2015 to December 15,
2019. References:
* USA FREEDOM Act
* USA FREEDOM Act Summary
* USA FREEDOM Act FAQs
質問 # 37
In which situation is a company operating under the assumption of implied consent?
- A. An online retailer subscribes new customers to an e-mail list by default
- B. A landlord uses the information on a completed rental application to run a credit report
- C. An employer contacts the professional references provided on an applicant's resume
- D. A retail clerk asks a customer to provide a zip code at the check-out counter
正解:C
質問 # 38
What was unique about the action that the Federal Trade Commission took against B.J.'s Wholesale Club in 2005?
- A. It made third-party audits a penalty for policy violations.
- B. It made user consent mandatory after any revisions of policy.
- C. It was based on matters of fairness rather than deception.
- D. It was the first substantial U.S.-EU Safe Harbor enforcement.
正解:C
解説:
Per the FTC Press Release in 2005, "BJ's Wholesale Club, Inc. has agreed to settle Federal Trade Commission charges that its failure to take appropriate security measures to protect the sensitive information of thousands of its customers was an unfair practice that violated federal law."
質問 # 39
John, a California resident, receives notification that a major corporation with $500 million in annual revenue has experienced a data breach. John's personal information in their possession has been stolen, including his full name and social security numb. John also learns that the corporation did not have reasonable cybersecurity measures in place to safeguard his personal information.
Which of the following answers most accurately reflects John's ability to pursue a legal claim against the corporation under the California Consumer Privacy Act (CCPA)?
- A. John can sue the corporation for the data breach to recover monetary damages suffered as a result of the data breach, and in some circumstances seek statutory damages irrespective of whether he suffered any financial harm.
- B. John cannot sue the corporation for the data breach because only the state's Attoney General has authority to file suit under the CCPA.
- C. John can sue the corporation for the data breach but only to recover monetary damages he actually suffered as a result of the data breach.
- D. John has no right to sue the corporation because the CCPA does not address any data breach rights.
正解:A
解説:
The CCPA provides consumers with a private right of action to pursue statutory damages following data security breaches that impact certain sensitive categories of personal information and are caused by a business's failure to institute reasonable and appropriate security. The CCPA defines personal information for this purpose as an individual's name in combination with any of the following: social security number, driver's license number, account number, credit or debit card number, medical information, or health insurance information. The CCPA allows consumers to seek damages between $100 and $750 per consumer per incident, or actual damages, whichever is greater. The CCPA also requires consumers to provide the business with 30 days' written notice and an opportunity to cure the violation before initiating an action. Additionally, the CCPA requires consumers to notify the Attorney General within 30 days of filing the action and obtain the Attorney General's approval or nonobjection before proceeding with the action. Therefore, John can sue the corporation for the data breach to recover monetary damages suffered as a result of the data breach, and in some circumstances seek statutory damages irrespective of whether he suffered any financial harm, as long as he meets the requirements of the CCPA. References:
* CCPA Provides Private Right of Action for Data Security Breaches
* CCPA Private Right of Action - Data Breach Security Requirement
* CCPA Fines & Penalties for Data Protection Violations | MatrixPoint
質問 # 40
Which federal act does NOT contain provisions for preempting stricter state laws?
- A. The Children's Online Privacy Protection Act (COPPA)
- B. The Fair and Accurate Credit Transactions Act (FACTA)
- C. The CAN-SPAM Act
- D. The Telemarketing Consumer Protection and Fraud Prevention Act
正解:D
質問 # 41
In 2011, the FTC announced a settlement with Google regarding its social networking service Google Buzz.
The FTC alleged that in the process of launching the service, the company did all of the following EXCEPT?
- A. Failed to employ sufficient security safeguards.
- B. Violated its own privacy policies.
- C. Failed to comply with Safe Harbor principles.
- D. Engaged in deceptive trade practices.
正解:A
解説:
The FTC alleged that Google violated its own privacy policies, engaged in deceptive trade practices, and failed to comply with Safe Harbor principles when it launched Google Buzz, a social networking service that automatically enrolled Gmail users and exposed their email contacts and other personal information without their consent or control. The FTC did not allege that Google failed to employ sufficient security safeguards, although it did require Google to implement a comprehensive privacy program and submit to regular privacy audits as part of the settlement. The other statements are incorrect because:
* A. Violated its own privacy policies: The FTC alleged that Google violated its own privacy policies by using information collected from Gmail users for a purpose that wasincompatible with the purpose for which the information was collected, without obtaining their affirmative consent. Google's privacy policy stated that "When you sign up for a particular service that requires registration, we ask you to provide personal information. If we use this information in a manner different than the purpose for which it was collected, then we will ask for your consent prior to such use."1
* B. Engaged in deceptive trade practices: The FTC alleged that Google engaged in deceptive trade practices by misrepresenting the extent to which consumers could exercise control over the collection, use, and sharing of their personal information through Google Buzz. For example, Google offered consumers the option to decline or turn off Google Buzz, but the option was ineffective and did not fully remove the consumer from the social network. Google also misled consumers about how their email contacts would be treated on Google Buzz, and failed to disclose that certain information, such as the user's frequent email contacts, would be made public by default.1
* C. Failed to comply with Safe Harbor principles: The FTC alleged that Google failed to comply with the
U.S.-EU Safe Harbor Framework, which provides a method for U.S. companies to transfer personal data from the European Union to the United States in a way that meets EU data protection requirements.
Google had self-certified to the Department of Commerce that it adhered to the Safe Harbor Privacy Principles, which include notice, choice, access, and enforcement. The FTC alleged that Google's conduct violated the notice and choice principles, as well as the requirement to adhere to the Safe Harbor FAQs.1 References: FTC Charges Deceptive Privacy Practices in Google's Rollout of Its Buzz Social Network, Google, Inc., In the Matter of, Google settles with FTC over Buzz; Privacy policies to be audited for two decades, Google Settles FTC Complaint over Google Buzz Privacy
質問 # 42
Federal laws establish which of the following requirements for collecting personal information of minors under the age of 13?
- A. Implied consent from a minor's parent or guardian before collecting a minor's personal information online, such as when they permit the minor to use the internet.
- B. Affirmative consent of a parent or guardian before collecting personal information of a minor offline (e.g., in person), which also satisfies any requirements for online consent.
- C. Affirmative consent from a minor's parent or guardian before collecting the minor's personal information online.
- D. Implied consent from a minor's parent or guardian, or affirmative consent from the minor.
正解:C
質問 # 43
Which of the following became the first state to pass a law specifically regulating the collection of biometric data?
- A. Texas.
- B. California.
- C. Washington.
- D. Illinois.
正解:D
解説:
Illinois became the first state to pass a law specifically regulating the collection of biometric data in 2008, when it enacted the Biometric Information Privacy Act (BIPA). BIPA defines biometric identifiers as retina or iris scans, fingerprints, voiceprints, or scans of hand or face geometry, and biometric information as any information based on biometric identifiers used to identify an individual. BIPA requires entities that collect, store, or use biometric identifiers or information to obtain informed consent from individuals, provide written policies on data retention and destruction, limit disclosure and sale of biometric data, and protect biometric data using reasonable security measures. BIPA also provides a private right of action for individuals whose biometric data is collected, stored, or used in violation of the law, and allows them to recover statutory damages of $1,000 or actual damages, whichever is greater, for each negligent violation, and $5,000 or actual damages, whichever is greater, for each intentional or reckless violation, as well as attorneys' fees and costs, and injunctive relief. References: U.S. Biometrics Laws Part I: An Overview of 2020, Is Biometric Information Protected by Privacy Laws?, Biometric Data Privacy Laws
質問 # 44
SCENARIO
Please use the following to answer the next QUESTION
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated data. In her research, Roberta had discovered that even low- level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed.
Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.
Based on the problems with the company's privacy security that Roberta identifies, what is the most likely cause of the breach?
- A. Lost company property such as a computer or flash drive.
- B. Fraud involving credit card theft at point-of-service terminals.
- C. Unintended disclosure of information shared with a third party.
- D. Mishandling of information caused by lack of access controls.
正解:D
解説:
The scenario describes how the company had no adequate rules about access to customer information and how low-level employees had access to all of the company's customer data, including financial records. This indicates that the company did not implement proper access controls to limit who can access, use, or disclose customer information based on their roles and responsibilities. Access controls are one of the key elements of information security and privacy, as they help prevent unauthorized or inappropriate access to sensitive data.
Without access controls, the company's customer information was vulnerable to mishandling by employees or outsiders who could exploit the weak security measures. Therefore, the most likely cause of the breach was mishandling of information caused by lack of access controls. References:
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 4: Information Management from a U.S. Perspective, Section 4.2: Information Security, p. 113-114
* IAPP CIPP/US Body of Knowledge, Domain I: Introduction to the U.S. Privacy Environment, Objective I.C: Describe the role of information security in privacy, Subobjective I.C.1: Identify the key elements of information security, p. 8
質問 # 45
Which entities must comply with the Telemarketing Sales Rule?
- A. For-profit organizations calling businesses when a binding contract exists between them
- B. For-profit and not-for-profit organizations when selling additional services to establish customers
- C. For-profit organizations and for-profit telefunders regarding charitable solicitations
- D. Nonprofit organizations calling on their own behalf
正解:C
解説:
Some types of businesses are not covered by the TSR even though they conduct telemarketing campaigns that may involve some interstate telephone calls to sell goods or services. These three types of entities are not subject to the FTC's jurisdiction, and are not covered by the TSR:
1. banks, federal credit unions, and federal savings and loans.
2. common carriers - such as long-distance telephone companies and airlines - when they are engaging in common carrier activity.
3. NON-PROFIT ORGANIZATIONS - those entities that are not organized to carry on business for their own, or their members', profit.
https://www.ftc.gov/business-guidance/resources/complying-telemarketing-sales-rule#comply
質問 # 46
Within what time period must a commercial message sender remove a recipient's address once they have asked to stop receiving future e-mail?
- A. 10 days
- B. 15 days
- C. 7 days
- D. 21 days
正解:A
解説:
According to the CAN-SPAM Act of 2003, a federal law that regulates commercial email messages, a commercial message sender must honor a recipient's opt-out request within 10 business days. The sender must provide a clear and conspicuous way for the recipient to opt out of receiving future emails, such as a link or an email address. The sender must not charge a fee, require the recipient to provide any personal information, or make the recipient take any steps other than sending a reply email or visiting a single web page to opt out. The sender must also not sell, exchange, or transfer the email address of the recipient who has opted out, unless it is necessary to comply with the law or prevent fraud.
References:
* IAPP CIPP/US Body of Knowledge, Domain II: Limits on Private-sector Collection and Use of Data, Section B: Communications and Marketing
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 2: Limits on Private-sector Collection and Use of Data, Section 2.2: Communications and Marketing
* Practice Exam - International Association of Privacy Professionals
質問 # 47
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
Based on the scenario, what is the most likely way Declan's supervisor would answer his question about the hospital's use of a billing company?
- A. By pointing out that contracts are in place to help ensure the observance of minimum security standards
- B. By suggesting that Declan look at the hospital's publicly posted privacy policy
- C. By describing how the billing system is integrated into the hospital's electronic health records (EHR) system
- D. By assuring Declan that third parties are prevented from seeing Private Health Information (PHI)
正解:A
質問 # 48
When developing a company privacy program, which of the following relationships will most help a privacy professional develop useful guidance for the organization?
- A. Relationships with clients, vendors, and customers whose data will be primarily collected and used throughout the organizational program.
- B. Relationships with individuals within the privacy professional community who are able to share expertise and leading practices for different industries.
- C. Relationships with company leaders responsible for approving, implementing, and periodically reviewing the corporate privacy program.
- D. Relationships with individuals across company departments and at different levels in the organization's hierarchy.
正解:D
解説:
IAPP Book, Section 4.3.1.1, paragraph 3.
質問 # 49
Which of the following statements is most accurate in regard to data breach notifications under federal and state laws:
- A. When you are required to provide an individual with notice of a data breach under any state's law, you must provide the individual with an offer for free credit monitoring.
- B. The only obligations to provide data breach notification are under state law because currently there is no federal law or regulation requiring notice for the breach of personal information.
- C. You must notify the Federal Trade Commission (FTC) in addition to affected individuals if over 500 individuals are receiving notice.
- D. When providing an individual with required notice of a data breach, you must identify what personal information was actually or likely compromised.
正解:B
質問 # 50
Which statement is FALSE regarding the provisions of the Employee Polygraph Protection Act of 1988 (EPPA)?
- A. Employers are prohibited from administering psychological testing based on personality traits such as honesty, preferences or habits.
- B. The EPPA requires that employers post essential information about the Act in a conspicuous location.
- C. The EPPA includes an exception that allows polygraph tests in professions in which employee honesty is necessary for public safety.
- D. Employers involved in the manufacture of controlled substances may terminate employees based on polygraph results if other evidence exists.
正解:A
解説:
Polygraphs (but no other lie detector tests) are permissible in certain circumstances. Under the EPPA, polygraph means an instrument that records continuously, visually, permanently, and simultaneously changes in cardiovascular, respiratory and electrodermal patterns as minimum instrumentation standards and is used to render a diagnostic opinion as to the *honesty or dishonesty* of as individual. https://www.dol.gov/agencies/whd/fact-sheets/36-eppa
質問 # 51
Under state breach notification laws, which is NOT typically included in the definition of personal information?
- A. Social Security number
- B. First and last name
- C. State identification number
- D. Medical Information
正解:D
質問 # 52
SCENARIO -
Please use the following to answer the next question:
Jane is a U.S. citizen and a senior software engineer at California-based Jones Labs, a major software supplier to the U.S. Department of Defense and other U.S. federal agencies. Jane's manager, Patrick, is a French citizen who has been living in California for over a decade. Patrick has recently begun to suspect that Jane is an insider secretly transmitting trade secrets to foreign intelligence. Unbeknownst to Patrick, the FBI has already received a hint from anonymous whistleblower, and jointly with the National Security Agency is investigating Jane's possible implication in a sophisticated foreign espionage campaign.
Ever since the pandemic, Jane has been working from home. To complete her daily tasks she uses her corporate laptop, which after each login conspicuously provides notice that the equipment belongs to Jones Labs and may be monitored according to the enacted privacy policy and employment handbook. Jane also has a corporate mobile phone that she uses strictly for business, the terms of which are defined in her employment contract and elaborated upon in her employee handbook. Both the privacy policy and the employee handbook are revised annually by a reputable California law firm specializing in privacy law. Jane also has a personal iPhone that she uses for private purposes only.
Jones Labs has its primary data center in San Francisco, which is managed internally by Jones Labs engineers.
The secondary data center, managed by Amazon AWS, is physically located in the UK for disaster recovery purposes. Jones Labs' mobile devices backup is managed by a mid-sized mobile defense company located in Denver, which physically stores the data in Canada to reduce costs. Jones Labs MS Office documents are securely stored in a Microsoft Office 365 data center based in Ireland. Manufacturing data of Jones Labs is stored in Taiwan and managed by a local supplier that has no presence in the U.S.
Before inspecting any GPS geolocation data from Jane's corporate mobile phone, Patrick should first do what?
- A. Ensure that such activity is permitted under Jane's employment contract or the company's employee privacy policy.
- B. Revise emerging workplace privacy best practices with a reputable advocacy organization.
- C. Obtain a subpoena from law enforcement, or a court order, directing Jones Labs to collect the GPS geolocation data.
- D. Obtain prior consent from Jane pursuant to the Telephone Consumer Protection Act
正解:A
解説:
Patrick should first ensure that inspecting GPS geolocation data from Jane's corporate mobile phone is permitted under Jane's employment contract or the company's employee privacy policy. This is because Jane has a reasonable expectation of privacy in her location information, even if she uses a corporate-owned device for business purposes. The Fourth Amendment protects individuals from unreasonable searches and seizures by the government, and the Electronic Communications Privacy Act (ECPA) prohibits unauthorized interception or access to electronic communications by private parties. Therefore, Patrick cannot inspect Jane's GPS data without a valid legal basis, such as consent, contract, or court order. Obtaining prior consent from Jane pursuant to the Telephone Consumer Protection Act (A) is not relevant, as this law regulates unsolicited calls and text messages, not location tracking. Revising emerging workplace privacy best practices with a reputable advocacy organization (B) is not sufficient, as Patrick still needs to comply with the existing legal obligations and contractual terms. Obtaining a subpoena from law enforcement, or a court order, directing Jones Labs to collect the GPS geolocation data is not necessary, as Patrick is not acting on behalf of the government or in response to a legal request. However, if Patrick does obtain such a legal order, he should also comply with it and notify Jane of the disclosure, unless prohibited by law. References:
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.1.2, p. 115-116
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.2.1, p. 118-119
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.2.2, p. 120-121
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.2.3, p. 122-123
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.1, p. 124-125
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.2, p. 126-127
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.3, p. 128-129
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.4, p. 130-131
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.5, p. 132-133
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.6, p. 134-135
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.7, p. 136-137
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.8, p. 138-139
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.9, p. 140-141
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.10, p. 142-143
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.11, p. 144-145
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.12, p. 146-147
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.13, p. 148-149
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.14, p. 150-151
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.15, p. 152-153
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.16, p. 154-155
* IAPP CIPP/US Study Guide, Chapter 4, Section 4.3.17, p. 156-157
質問 # 53
How did the Fair and Accurate Credit Transactions Act (FACTA) amend the Fair Credit Reporting Act (FCRA)?
- A. It stipulated the purpose of obtaining a consumer report can only be for a review of the employee's credit worthiness
- B. It required employers to get an employee's consent in advance of requesting a consumer report for internal investigation purposes
- C. It increased the obligation of organizations to dispose of consumer data in ways that prevent unauthorized access
- D. It expanded the definition of "consumer reports" to include communications relating to employee investigations
正解:C
解説:
Section: (none)
Explanation
質問 # 54
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal dat a. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
At this stage of the investigation, what should the data privacy leader review first?
- A. Prevailing regulation on this subject
- B. The company's data privacy policies
- C. Available data flow diagrams
- D. The text of the original complaint
正解:A
質問 # 55
Which authority supervises and enforces laws regarding advertising to children via the Internet?
- A. The Federal Communications Commission
- B. The Department of Homeland Security
- C. The Federal Trade Commission
- D. The Office for Civil Rights
正解:C
質問 # 56
Global Manufacturing Co's Human Resources department recently purchased a new software tool. This tool helps evaluate future candidates for executive roles by scanning emails to see what those candidates say and what is said about them. This provides the HR department with an automated "360 review" that lets them know how the candidate thinks and operates, what their peers and direct reports say about them, and how well they interact with each other.
What is the most important step for the Human Resources Department to take when implementing this new software?
- A. Confirming that employees have read and signed the employee handbook where they have been advised that they have no right to privacy as long as they are using the organization's systems, regardless of the protected group or laws enforced by EEOC.
- B. Providing notice to employees that their emails will be scanned by the software and creating automated profiles.
- C. Making sure that the software does not unintentionally discriminate against protected groups.
- D. Ensuring that the software contains a privacy notice explaining that employees have no right to privacy as long as they are running this software on organization systems to scan email systems.
正解:B
解説:
The most important step for the HR department to take when implementing this new software is to provide notice to employees that their emails will be scanned by the software and creating automated profiles. This is because the software involves the collection and use of personal information from employees, which may implicate their privacy rights and expectations. By providing notice, the HR department can inform employees about the purpose, scope, and consequences of the software, as well as their choices and rights regarding their data. Notice is also a key element of transparency and accountability, which are essential principles of privacy management. Providing notice can also help the HR department comply with various privacy laws and regulations that may apply to the software, such as the Electronic Communications Privacy Act (ECPA), the Stored Communications Act (SCA), the Fair Credit Reporting Act (FCRA), and state privacy laws. Notice can also help the HR department avoid potential legal risks and liabilities that may arise from the software, such as claims of invasion of privacy, breach of contract, or violation of employee rights. References:
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 4, Section 4.2.1, pp. 97-98.
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 5, Section 5.2.1, pp. 125-126.
* U.S. Private-Sector Privacy, Third Edition by Peter P. Swire, DeBrae Kennedy-Mayo, Chapter 6, Section 6.2.1, pp. 153-154.
* IAPP CIPP/US Certified Information Privacy Professional Study Guide by Mike Chapple and Joe Shelley, Chapter 4, Section 4.1, pp. 113-114.
質問 # 57
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
- A. A bill of rights for individuals seeking access to their personal information.
- B. A code of responsibilities for medical establishments to uphold privacy laws.
- C. An international court ruling on personal information held in the commercial sector.
- D. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
正解:A
質問 # 58
Which of the following best describes private-sector workplace monitoring in the United States?
- A. Judgments in private lawsuits have severely limited the monitoring of employees
- B. Most employees are protected from workplace monitoring by the U.S. Constitution
- C. U.S. federal law restricts monitoring only to industries for which it is necessary
- D. Employers have broad authority to monitor their employees
正解:D
解説:
In the United States, there is no comprehensive federal law that regulates employee monitoring in the private sector. Instead, there are various federal and state laws that address specific aspects of monitoring, such as electronic communications, video surveillance, GPS tracking, and biometric data. Generally, these laws provide more protection for employees' privacy when they are using their own devices or personal accounts, or when they are outside of work hours or premises. However, when employees are using company-owned devices or accounts, or when they are performing work-related tasks, employers have broad authority to monitor their activities, as long as they have a legitimate business interest and do not violate any specific laws. Employers are also advised to inform employees of their monitoring practices and obtain their consent, either explicitly or implicitly, to avoid potential legal disputes or employee backlash123 References: https://www.jibble.io/article/us-employee-monitoring
https://www.worktime.com/most-asked-questions-on-us-employee-monitoring-laws
質問 # 59
......
CIPP-US試験は、米国におけるプライバシー法や規制、プライバシープログラムのガバナンス、情報セキュリティ、データ漏洩管理、プライバシーリスク管理など、プライバシーに関連する幅広いトピックをカバーしています。試験は複数選択肢の問題で構成され、90問に回答する必要があり、2.5時間で行われます。試験に合格するには、候補者は500点中少なくとも300点を獲得する必要があります。この認定資格は2年間有効であり、個人は認定を維持するために20の継続的なプライバシー教育(CPE)クレジットを獲得する必要があります。
無料お試しIAPP CIPP-US問題集PDFは必ずベストの問題集オプションを使おう:https://www.goshiken.com/IAPP/CIPP-US-mondaishu.html
CIPP-US試験資料IAPP学習ガイド:https://drive.google.com/open?id=1ZMgxlSzFwynPEH0jWxJMfGrw1RhLTHA7