PassFish

CIPP-US practice questions — 10 free

Certified Information Privacy Professional/United States · every answer carries the reasoning, and why each other option fails.
343 questions
9 chapters of notes
EN + ZH languages

Tap an option to see the answer, the reasoning, and why the other three fail.

Question 1 of 10

"Third party doctrine" as it relates to the fourth amendment of the US constitution concerns:

Why C is correct

The Supreme Court has confirmed that information placed in the hands of a “third party” is not protected by the Fourth Amendment. For example, no warrant is required to request a list of called persons. This third-party doctrine means that companies may provide data from employees or customers to the government.

Question 2 of 10

Although an employer may have a strong incentive or legal obligation to monitor employees' conduct or behavior, some excessive monitoring may be considered an intrusion on employees' privacy? Which of the following is the strongest example of excessive monitoring by the employer?

Why C is correct

Whether an employer's monitoring measures are reasonable requires weighing the employer's legitimate business interests against the employee's reasonable expectation of privacy in a particular location. A changing room is one of the locations where, by common social understanding, employees have the highest expectation of privacy. Even if the employer claims the purpose of the monitoring is to reduce the risk of sexual harassment, installing video surveillance in a private space like a changing room, where employees necessarily undress, is generally considered to far exceed the reasonable limits of business-necessary monitoring, constituting a serious intrusion on employee privacy — making it, of the four options, the strongest example of excessive monitoring.

Question 3 of 10

In Nevada, companies that collect personally identifiable information on their websites must provide _____.

Why D is correct

When formulating a global privacy strategy, beyond regulatory requirements and existing business practices, cultural norms are another important factor that must be taken into consideration -- social perceptions, expectations, and tolerance regarding privacy vary significantly across countries and regions (for example, Europe's strong emphasis on the right to privacy stems from historical experience, and in parts of Asia, family/collective values also influence willingness to share personal information). Ignoring these cultural differences means that even if a program is technically compliant, its acceptance and practical effectiveness in a given locality may be substantially diminished. By comparison, factors such as currency exchange rates, geographic features, and political history are clearly much less directly relevant to formulating a privacy strategy, and are not core considerations in developing a global privacy strategy.

Question 4 of 10

Smith Memorial Healthcare (SMH) is a hospital network headquartered in New York and operating in 7 other states. SMH uses an electronic medical record to enter and track information about its patients. Recently, SMH suffered a data breach where a third-party hacker was able to gain access to the SMH internal network. Because it is a HIPPA-covered entity, SMH made a notification to the Office of Civil Rights at the U.S. Department of Health and Human Services about the breach. Which statement accurately describes SMH’s notification responsibilities?

Why A is correct

As a HIPAA covered entity, SMH must, following a data breach, notify HHS's Office for Civil Rights (OCR) and affected individuals in accordance with the HIPAA Breach Notification Rule. Many state breach notification laws (including New York's) provide a "deemed compliance" exception for entities that are already regulated by HIPAA and have completed notification as HIPAA requires—that is, if the entity has complied with HIPAA's notification requirements, it need not separately send a duplicate notice to state residents under state law, avoiding a double compliance burden. This is a common design feature of HIPAA-compliance carve-outs found in many state breach notification laws.

Question 5 of 10

Under the EU-US Data Privacy Framework, what must participating organizations provide to individuals in regard to complaints and disputes?

Why A is correct

The EU-US Data Privacy Framework (DPF, the transatlantic data transfer mechanism adopted by the European Commission's adequacy decision in 2023) requires participating U.S. organizations to provide data subjects with a multi-layered dispute resolution mechanism, one core requirement of which is providing an independent recourse mechanism, such as an independent dispute resolution body or a referral arbitration mechanism under an EU member state's data protection authority (DPA), for individuals to pursue further recourse when a complaint has not been adequately handled by the organization itself. This mechanism continues and reinforces the complaint and redress arrangements under the earlier Privacy Shield framework, and is a mandatory obligation for organizations self-certifying under the DPF.

Question 6 of 10

What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?

Why A is correct

A consent decree is a legally binding agreement, approved by a judge, between a government agency and an adverse party (typically a company under investigation or facing suit) that resolves an enforcement dispute without a full trial. In the privacy enforcement context, the FTC frequently reaches consent decrees with companies that have violated Section 5 of the FTC Act, requiring the company to commit to improved data security or privacy practices and to submit to long-term compliance audits (often up to 20 years); if a company violates the terms of a consent decree, the FTC may seek civil penalties for each violation. A consent decree combines the nature of a contract with the enforceability of a court judgment, making it the most commonly used resolution mechanism in FTC privacy and data security enforcement.

Question 7 of 10

What practice does the USA FREEDOM Act NOT authorize?

Why D is correct

The USA FREEDOM Act (2015) was a major reform enacted after certain PATRIOT Act provisions expired. One of its core changes was to end the National Security Agency's (NSA) bulk collection of telephone metadata previously conducted under Section 215 of the PATRIOT Act, requiring intelligence agencies instead to apply to telecommunications carriers for specific communication records after obtaining a specific, targeted court order, rather than indiscriminately collecting and retaining the call and internet metadata of the entire citizenry in bulk. The Act simultaneously extended the applicable period of the roving wiretap provisions and increased the maximum penalty for providing material support to terrorism, reflecting Congress's recalibration of the relationship between surveillance powers and citizens' privacy rights following the Snowden disclosures of bulk surveillance programs.

Question 8 of 10

Which federal act does NOT contain provisions for preempting stricter state laws?

Why D is correct

The Telemarketing Consumer Protection and Fraud Prevention Act (i.e., the legislative package associated with the Telephone Consumer Protection Act and its implementing enforcement rules) does not contain an explicit preemption provision excluding states' power to enact stricter telemarketing laws; states may adopt stricter rules on top of the federal baseline. By contrast, the CAN-SPAM Act, COPPA, and FACTA each explicitly include preemption provisions in their statutory text, limiting state legislatures from enacting stricter or inconsistent rules on the same subject matter, reflecting Congress's intent to establish uniform federal standards in these areas.

Question 9 of 10

Which of the following is NOT a common challenge large organizations face when implementing data portability?

Why B is correct

Common challenges large organizations face when implementing data portability include: the presence of third-party data mixed within the data to be ported (requiring identification and removal of others' information during export to avoid infringing third-party privacy), security risks during the transfer process, and whether the transmitting organization has sufficient technical skill sets to complete a secure and efficient migration. By contrast, "technically compatible transmission systems" are generally not a major challenge — large organizations typically already have relatively mature IT infrastructure and standardized data format capabilities, so system compatibility issues are relatively secondary; the real difficulties lie in data identification, privacy risk control, and the personnel/process support across systems, rather than technical compatibility itself.

Question 10 of 10

Which one of the following categories of advertising is not regulated by the Delaware Online Privacy Protection Act?

Why D is correct

The Delaware Online Privacy and Data Protection Act imposes special restrictions on targeted advertising related to minors, expressly prohibiting the delivery of specific categories of advertising to users known to be minors. These restricted categories typically include dietary supplements, gambling, tanning services, tattoos, and certain other goods/services deemed harmful or unsuitable for minors. "Computing"-related advertising is not among the restricted sensitive advertising categories listed under the law, and therefore is not subject to this special regulation.

These 10 are a sample

See the full bank