Certified Information Privacy Professional/United States · every answer carries the reasoning, and why each
other option fails.
343 questions
9 chapters of notes
EN + ZH languages
Tap an option to see the answer, the reasoning, and why the other three fail.
Question 1 of 10
"Third party doctrine" as it relates to the fourth amendment of the US constitution concerns:
AThree authorities are required for creating and administering a warrant.
BSomeone referring to themselves in the third person is hiding something.
CData or information a suspect shares with a third party is not privacy protected.
DA third party can wiretap a suspect without a warrant and then give the data to the police.
Why C is correct
The Supreme Court has confirmed that information placed in the hands of a “third party” is not protected by the Fourth Amendment. For example, no warrant is required to request a list of called persons. This third-party doctrine means that companies may provide data from employees or customers to the government.
Question 2 of 10
Although an employer may have a strong incentive or legal obligation to monitor employees' conduct or behavior, some excessive monitoring may be considered an intrusion on employees' privacy? Which of the following is the strongest example of excessive monitoring by the employer?
AAn employer who installs a video monitor in physical locations, such as a warehouse, to ensure employees are performing tasks in a safe manner and environment.Installing monitoring in a general workplace such as a warehouse to ensure safe operations falls within the employer's reasonable scope of monitoring for safety management purposes, and employees' expectation of privacy in an open work area is already low.
BAn employer who installs data loss prevention software on all employee computers to limit transmission of confidential company information.Installing data loss prevention software on employee computers to prevent leakage of confidential information is a reasonable and common technical management measure for protecting trade secrets, and does not intrude on the employee's private, secluded space.
CAn employer who installs video monitors in physical locations, such as a changing room, to reduce the risk of sexual harassment.
DAn employer who records all employee phone calls that involve financial transactions with customers completed over the phone.Recording phone calls involving financial transactions with customers is typically done for compliance record-keeping purposes (such as record-retention requirements in the financial industry), and the calls involve communications within the scope of the employee's job duties, so the employee's expectation of privacy is relatively low and the monitoring has a legitimate business justification.
Why C is correct
Whether an employer's monitoring measures are reasonable requires weighing the employer's legitimate business interests against the employee's reasonable expectation of privacy in a particular location. A changing room is one of the locations where, by common social understanding, employees have the highest expectation of privacy. Even if the employer claims the purpose of the monitoring is to reduce the risk of sexual harassment, installing video surveillance in a private space like a changing room, where employees necessarily undress, is generally considered to far exceed the reasonable limits of business-necessary monitoring, constituting a serious intrusion on employee privacy — making it, of the four options, the strongest example of excessive monitoring.
Question 3 of 10
In Nevada, companies that collect personally identifiable information on their websites must provide _____.
AencryptionCurrency exchange rates fall under financial/economic considerations and have very weak relevance to the formulation of a privacy strategy.
Ba security policyGeographic features (such as terrain or climate) are generally unrelated to privacy protection strategy.
Ca $10,000 bondPolitical history background may indirectly influence a region's legal environment, but its direct shaping effect on privacy practices is not as significant as current cultural norms, and it is not a core factor a global privacy strategy needs to prioritize.
Da privacy policy
Why D is correct
When formulating a global privacy strategy, beyond regulatory requirements and existing business practices, cultural norms are another important factor that must be taken into consideration -- social perceptions, expectations, and tolerance regarding privacy vary significantly across countries and regions (for example, Europe's strong emphasis on the right to privacy stems from historical experience, and in parts of Asia, family/collective values also influence willingness to share personal information). Ignoring these cultural differences means that even if a program is technically compliant, its acceptance and practical effectiveness in a given locality may be substantially diminished. By comparison, factors such as currency exchange rates, geographic features, and political history are clearly much less directly relevant to formulating a privacy strategy, and are not core considerations in developing a global privacy strategy.
Question 4 of 10
Smith Memorial Healthcare (SMH) is a hospital network headquartered in New York and operating in 7 other states. SMH uses an electronic medical record to enter and track information about its patients. Recently, SMH suffered a data breach where a third-party hacker was able to gain access to the SMH internal network. Because it is a HIPPA-covered entity, SMH made a notification to the Office of Civil Rights at the U.S. Department of Health and Human Services about the breach.
Which statement accurately describes SMH’s notification responsibilities?
AIf SMH is compliant with HIPAA, it will not have to make a separate notification to individuals in the state of New York.
BIf SMH has more than 500 patients in the state of New York, it will need to make separate notifications to these patients.This statement runs counter to the general design logic of the HIPAA/state-law "deemed compliance" exception; the number of affected New York patients is not the key factor determining whether a separate notification is required.
CIf SMH must make a notification in any other state in which it operates, it must also make a notification to individuals in New York.Triggering notification obligations in other states and whether a separate notice must be sent to New York residents are independent questions, with no automatic linkage between them.
DIf SMH makes credit monitoring available to individuals who inquire, it will not have to make a separate notification to individuals in the state of New York.Providing credit monitoring is generally not itself a statutory condition for exemption from state notification obligations; the key to "deemed compliance" is whether HIPAA notification procedures were followed, not whether credit monitoring was offered.
Why A is correct
As a HIPAA covered entity, SMH must, following a data breach, notify HHS's Office for Civil Rights (OCR) and affected individuals in accordance with the HIPAA Breach Notification Rule. Many state breach notification laws (including New York's) provide a "deemed compliance" exception for entities that are already regulated by HIPAA and have completed notification as HIPAA requires—that is, if the entity has complied with HIPAA's notification requirements, it need not separately send a duplicate notice to state residents under state law, avoiding a double compliance burden. This is a common design feature of HIPAA-compliance carve-outs found in many state breach notification laws.
Question 5 of 10
Under the EU-US Data Privacy Framework, what must participating organizations provide to individuals in regard to complaints and disputes?
AAn independent recourse mechanism.
BA copy of the individual’s personal data.Providing a copy of an individual's personal data falls within the scope of the data subject's access right, which is a separate compliance requirement from complaint and dispute resolution mechanisms, and is not the specific obligation this question addresses.
CA description of the organization’s data processing policies.Disclosing a description of data processing policies falls within the general notice obligation under the transparency principle, not a mechanism specifically required for complaint and dispute scenarios.
DA means of communicating with the organization’s privacy team.Providing a channel to communicate with an organization's privacy team is only a preliminary internal complaint-handling method, and is not equivalent to the formal, independent recourse mechanism required by the DPF.
Why A is correct
The EU-US Data Privacy Framework (DPF, the transatlantic data transfer mechanism adopted by the European Commission's adequacy decision in 2023) requires participating U.S. organizations to provide data subjects with a multi-layered dispute resolution mechanism, one core requirement of which is providing an independent recourse mechanism, such as an independent dispute resolution body or a referral arbitration mechanism under an EU member state's data protection authority (DPA), for individuals to pursue further recourse when a complaint has not been adequately handled by the organization itself. This mechanism continues and reinforces the complaint and redress arrangements under the earlier Privacy Shield framework, and is a mandatory obligation for organizations self-certifying under the DPF.
Question 6 of 10
What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?
AA consent decree
BStare decisis decreeStare decisis is a common law principle under which courts decide cases based on prior precedent; it is not an approved agreement document and does not match the nature of the legal document described in the question.
CA judgment rider"Judgment rider" is not a widely recognized formal legal term and does not fit the question's description of a formal agreement between a government agency and an adverse party.
DCommon law judgmentA common law judgment is a ruling issued by a court based on common law precedent, representing a unilateral judicial decision — not an agreement negotiated by both parties and approved by a judge.
Why A is correct
A consent decree is a legally binding agreement, approved by a judge, between a government agency and an adverse party (typically a company under investigation or facing suit) that resolves an enforcement dispute without a full trial. In the privacy enforcement context, the FTC frequently reaches consent decrees with companies that have violated Section 5 of the FTC Act, requiring the company to commit to improved data security or privacy practices and to submit to long-term compliance audits (often up to 20 years); if a company violates the terms of a consent decree, the FTC may seek civil penalties for each violation. A consent decree combines the nature of a contract with the enforceability of a court judgment, making it the most commonly used resolution mechanism in FTC privacy and data security enforcement.
Question 7 of 10
What practice does the USA FREEDOM Act NOT authorize?
AEmergency exceptions that allow the government to target roamersThe Act does indeed contain emergency exception provisions authorizing surveillance of "lone wolf" terrorists, which falls within its scope of authorization.
BAn increase in the maximum penalty for material support to terrorismThe Act did indeed increase the maximum penalty for providing material support to terrorism, which falls within its scope of authorization.
CAn extension of the expiration for roving wiretapsThe Act did indeed extend the applicable period of the roving wiretap provisions, allowing them to continue in effect, which falls within its scope of authorization.
DThe bulk collection of telephone data and internet metadata
Why D is correct
The USA FREEDOM Act (2015) was a major reform enacted after certain PATRIOT Act provisions expired. One of its core changes was to end the National Security Agency's (NSA) bulk collection of telephone metadata previously conducted under Section 215 of the PATRIOT Act, requiring intelligence agencies instead to apply to telecommunications carriers for specific communication records after obtaining a specific, targeted court order, rather than indiscriminately collecting and retaining the call and internet metadata of the entire citizenry in bulk. The Act simultaneously extended the applicable period of the roving wiretap provisions and increased the maximum penalty for providing material support to terrorism, reflecting Congress's recalibration of the relationship between surveillance powers and citizens' privacy rights following the Snowden disclosures of bulk surveillance programs.
Question 8 of 10
Which federal act does NOT contain provisions for preempting stricter state laws?
AThe CAN-SPAM ActThe CAN-SPAM Act expressly preempts state laws that substantively regulate commercial email, and states may not impose stricter requirements on the same subject matter, so it is a law containing a preemption provision.
BThe Children's Online Privacy Protection Act (COPPA)COPPA likewise contains a preemption provision, providing that state law may not be inconsistent with or impose additional requirements beyond COPPA's online privacy protections for children, so it is a law containing a preemption provision.
CThe Fair and Accurate Credit Transactions Act (FACTA)FACTA contains explicit federal preemption provisions for certain parts of its consumer report and identity-theft-related provisions, limiting states from enacting stricter rules on those specific matters, so it is a law containing a preemption provision.
DThe Telemarketing Consumer Protection and Fraud Prevention Act
Why D is correct
The Telemarketing Consumer Protection and Fraud Prevention Act (i.e., the legislative package associated with the Telephone Consumer Protection Act and its implementing enforcement rules) does not contain an explicit preemption provision excluding states' power to enact stricter telemarketing laws; states may adopt stricter rules on top of the federal baseline. By contrast, the CAN-SPAM Act, COPPA, and FACTA each explicitly include preemption provisions in their statutory text, limiting state legislatures from enacting stricter or inconsistent rules on the same subject matter, reflecting Congress's intent to establish uniform federal standards in these areas.
Question 9 of 10
Which of the following is NOT a common challenge large organizations face when implementing data portability?
AThe presence of third-party data in the data to be ported.Data to be ported is often mixed with third-party personal information, and figuring out how to satisfy the portability right without disclosing others' privacy is a common practical difficulty.
BTechnically compatible systems for transmission feasibility.
CSecurity considerations in relation to the transfer of the data.Security protection during data transfer (such as preventing interception or tampering) is a widely faced real-world challenge in implementing data portability.
DThe technical skillsets available in the transmitting organization.Many large organizations' transmitting-side technical teams lack the specialized skills needed to handle large-scale, structured data exports, which is also a common obstacle.
Why B is correct
Common challenges large organizations face when implementing data portability include: the presence of third-party data mixed within the data to be ported (requiring identification and removal of others' information during export to avoid infringing third-party privacy), security risks during the transfer process, and whether the transmitting organization has sufficient technical skill sets to complete a secure and efficient migration. By contrast, "technically compatible transmission systems" are generally not a major challenge — large organizations typically already have relatively mature IT infrastructure and standardized data format capabilities, so system compatibility issues are relatively secondary; the real difficulties lie in data identification, privacy risk control, and the personnel/process support across systems, rather than technical compatibility itself.
Question 10 of 10
Which one of the following categories of advertising is not regulated by the Delaware Online Privacy Protection Act?
ADietary supplementsDietary supplement advertising is one of the advertising categories listed by Delaware's law as restricted with respect to minors.
BGamblingGambling advertising, due to minor-protection considerations, is listed as an advertising category restricted from delivery under this law.
CTanningTanning service advertising is likewise an advertising category the law expressly restricts from being delivered to minors.
DComputing
Why D is correct
The Delaware Online Privacy and Data Protection Act imposes special restrictions on targeted advertising related to minors, expressly prohibiting the delivery of specific categories of advertising to users known to be minors. These restricted categories typically include dietary supplements, gambling, tanning services, tattoos, and certain other goods/services deemed harmful or unsuitable for minors. "Computing"-related advertising is not among the restricted sensitive advertising categories listed under the law, and therefore is not subject to this special regulation.
These 10 are a sample
✓343 questions, each with the full reasoning
✓Every wrong option explained, not just the right one
✓9 chapters of syllabus notes, written from a cold start
✓Full-length mock exam with per-domain scoring
✓Printable PDF included — one purchase, no renewal