無料更新されたIAPP CIPP-USテストエンジン問題には228問あります [Q135-Q155]

Share

無料更新されたIAPP CIPP-USテストエンジン問題には228問あります

ベストな問題集を使おうCertified Information Privacy Professional CIPP-US専門試験問題


IAPP CIPP-US試験は、米国のプライバシー専門家にとって高く評価される認定資格です。この試験は、プライバシー法、データ保護、データプライバシー管理などのさまざまなトピックをカバーします。この試験に合格することは、プライバシー分野で成功を収めるための重要なステップであり、米国のプライバシー法や規制に基本的な理解を持っている人であれば誰でも受験することができます。また、プライバシー分野でのキャリアを追求している人にも適しています。


IAPP CIPP-US認定試験は、キャリアを前進させ、米国の最新のプライバシー法と規制を最新の状態に保ちたいプライバシーの専門家にとって重要な認定プログラムです。試験は挑戦的ですが、プライバシーの専門家に、プライバシー法と規制の複雑な世界をナビゲートするために必要な知識と専門知識を提供するため、報酬は十分に価値があります。 IAPP CIPP-US認定により、プライバシーの専門家は、プライバシーへのコミットメントと、最新のトレンドとフィールドの開発に最新の状態を維持することへの献身を示すことができます。


IAPPのCIPP-US認定試験は、アメリカのプライバシーとデータ保護分野で働く専門家にとって重要な認定試験です。この認定は、個人のプライバシー分野における能力を示し、就職市場で優位に立つことができます。試験に合格するには、米国のプライバシー法規制、プライバシープログラムのガバナンス、データ漏えい、職場におけるプライバシー問題についての深い理解が必要です。

 

質問 # 135
SCENARIO
Please use the following to answer the next question :
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals - ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
What is the most effective kind of training CloudHealth could have given its employees to help prevent this type of data breach?

  • A. Training on CloudHealth's HR policy regarding the role of employees involved data breaches
  • B. Training on the terms of the contractual agreement with HealthCo
  • C. Training on the difference between confidential and non-public information
  • D. Training on techniques for identifying phishing attempts

正解:D


質問 # 136
Which of the following would best provide a sufficient consumer disclosure under the Fair Credit Reporting Act (FCRA) prior to a consumer report being obtained for employment purposes?

  • A. A notice provision in a mailed offer letter.
  • B. A verbal notice provided with a conditional offer of employment
  • C. A standalone notice document.
  • D. A notice provision in an electronic employment application.

正解:C

解説:
Under the Fair Credit Reporting Act (FCRA), employers are required to provide a clear and conspicuous disclosure in a standalone document before obtaining a consumer report (e.g., a background check) for employment purposes. This requirement ensures that the individual is fully aware that a consumer report will be obtained and consents to the process.
Requirements for a Sufficient Consumer Disclosure:
* Clear and Conspicuous Disclosure:Employers must inform the individual, in writing, that a consumer report may be obtained for employment purposes.
* Standalone Document:The disclosure must be provided in a separate document not combined with other materials, such as an employment application. This ensures the individual's attention is focused on the notice.
* Written Authorization:Employers must obtain written authorization from the individual before procuring the consumer report.
Explanation of Options:
* A. A verbal notice provided with a conditional offer of employment:Verbal notice is insufficient under FCRA, which requires a written, standalone disclosure.
* B. A notice provision in an electronic employment application:Embedding the disclosure in an employment application would not meet the FCRA requirement for a standalone document and could be legally invalid.
* C. A notice provision in a mailed offer letter:Including the disclosure in an offer letter does not satisfy the requirement for a separate, standalone document.
* D. A standalone notice document:This is the correct answer, as the FCRA explicitly requires the disclosure to be in a separate document to ensure clarity and compliance.
References from CIPP/US Materials:
* FCRA Section 604(b) (15 U.S.C. § 1681b(b)): Requires a clear and conspicuous standalone disclosure before obtaining a consumer report for employment purposes.
* IAPP CIPP/US Certification Textbook: Explains the FCRA requirements for employment-related consumer reports, including the disclosure and authorization process.


質問 # 137
Under the Telemarketing Sales Rule, what characteristics of consent must be in place for an organization to acquire an exception to the Do-Not-Call rules for a particular consumer?

  • A. The consent must be in writing, must state the times when calls can be made to the consumer and must be signed
  • B. The consent must be in writing, must contain the number to which calls can be made and must be signed
  • C. The consent must be in writing, must contain the number to which calls can be made and must have an end date
  • D. The consent must be in writing, must have an end data and must state the times when calls can be made

正解:B

解説:
https://www.ftc.gov/business-guidance/resources/complying-telemarketing-sales-rule#writtenagreement What must the written agreement contain? A written agreement need only contain: - unambiguous evidence that a call recipient is willing to receive telephone calls that deliver a - prerecorded message by or on behalf of a specific seller; the telephone number to which such messages may be delivered; and - the call recipient's signature.


質問 # 138
Which federal agency plays a role in privacy policy, but does NOT have regulatory authority?

  • A. The Department of Commerce.
  • B. The Federal Communications Commission.
  • C. The Office of the Comptroller of the Currency.
  • D. The Department of Transportation.

正解:D


質問 # 139
"Third party doctrine" as it relates to the fourth amendment of the US constitution concerns:

  • A. A third party can wiretap a suspect without a warrant and then give the data to the police.
  • B. Someone referring to themselves in the third person is hiding something.
  • C. Data or information a suspect shares with a third party is not privacy protected.
  • D. Three authorities are required for creating and administering a warrant.

正解:C

解説:
The Supreme Court has confirmed that information placed in the hands of a third party?is not protected by the Fourth Amendment. For example, no warrant is required to request a list of called persons. This third-party doctrine means that companies may provide data from employees or customers to the government.


質問 # 140
Which of these organizations would be required to provide its customers with an annual privacy notice?

  • A. The Golden Gavel Auction House.
  • B. The Four Winds Tribal College.
  • C. The King County Savings and Loan.
  • D. The Breezy City Housing Commission.

正解:C

解説:
The annual privacy notice requirement under the Gramm-Leach-Bliley Act (GLBA) applies to financial institutions that collect nonpublic personal information from customers and disclose it to nonaffiliated third parties, unless they qualify for an exception. A financial institution is any entity that engages in activities that are financial in nature or incidental to such activities, as defined by section 4(k) of the Bank Holding Company Act of 1956. The King County Savings and Loan is a financial institution under this definition, as it engages in lending money and accepting deposits. Therefore, it is required to provide its customers with an annual privacy notice, unless it meets the conditions for an exception. The Four Winds Tribal College, the Golden Gavel Auction House, and the Breezy City Housing Commission are not financial institutions under the GLBA, as they do not engage in activities that are financial in nature or incidental to such activities.
Therefore, they are not required to provide their customers with an annual privacy notice under the GLBA. References:
* Amendment to the Annual Privacy Notice Requirement Under the Gramm-Leach-Bliley Act, section I.
Background, paragraph 2.
* 17 CFR § 248.5 - Annual privacy notice to customers required., paragraph (a) (1).
* IAPP CIPP/US Study Guide, page 65.


質問 # 141
SCENARIO
Please use the following to answer the next question:
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated data. In her research, Roberta had discovered that even low- level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needs-to-know basis.
This would mean restricting employees' access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information.
Third, identify outdated customer information and then develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.
What could the company have done differently prior to the breach to reduce their risk?

  • A. Looked for any persistent threats to security that could compromise the company's network.
  • B. Communicated requests for changes to users' preferences across the organization and with third parties.
  • C. Implemented a comprehensive policy for accessing customer information.
  • D. Honored the promise of its privacy policy to acquire information by using an opt-in method.

正解:C

解説:
The scenario suggests that the company lacked adequate rules about access to customer information, which increased the risk of unauthorized access and data breach. Implementing a comprehensive policy for accessing customer information would have helped the company to limit the access to only those who need it for legitimate purposes, and to protect the confidentiality, integrity, and availability of the data. This is also one of the recommendations that Roberta made in her report.


質問 # 142
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
At this stage of the investigation, what should the data privacy leader review first?

  • A. The company's data privacy policies
  • B. Prevailing regulation on this subject
  • C. The text of the original complaint
  • D. Available data flow diagrams

正解:D

解説:
Data flow diagrams are graphical representations of how data moves within an organization or between different entities. They can help identify the sources, destinations, and processing of personal data, as well as the legal basis, retention periods, and security measures for each data flow. Reviewing the available data flow diagrams can help the data privacy leader to quickly and accurately respond to the urgent request from the EU- based retail partner, as well as to assess the potential risks and compliance gaps in the data transfer process.
Data flow diagrams are also a key component of data protection impact assessments (DPIAs), which are required by the GDPR for high-risk processing activities. References:
* IAPP CIPP/US Body of Knowledge, Section II, A, 2
* [IAPP CIPP/US Study Guide, Chapter 2, Section 2.3]
* [GDPR, Article 35]


質問 # 143
SCENARIO
Please use the following to answer the next question:
You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures.
A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals - ones that exposed the PHI of public figures including celebrities and politicians.
During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected.
A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach.
What is the most significant reason that the U.S. Department of Health and Human Services (HHS) might impose a penalty on HealthCo?

  • A. Because CloudHealth violated its contract with HealthCo by not encrypting the ePHI
  • B. Because HealthCo did not require CloudHealth to implement appropriate physical and administrative measures to safeguard the ePHI
  • C. Because HIPAA requires the imposition of a fine if a data breach of this magnitude has occurred
  • D. Because HealthCo did not conduct due diligence to verify or monitor CloudHealth's security measures

正解:D


質問 # 144
SCENARIO
Please use the following to answer the next question:
Larry has become increasingly dissatisfied with his telemarketing position at SunriseLynx, and particularly with his supervisor, Evan. Just last week, he overheard Evan mocking the state's Do Not Call list, as well as the people on it. "If they were really serious about not being bothered," Evan said, "They'd be on the national DNC list. That's the only one we're required to follow. At SunriseLynx, we call until they ask us not to." Bizarrely, Evan requires telemarketers to keep records of recipients who ask them to call "another time." This, to Larry, is a clear indication that they don't want to be called at all. Evan doesn't see it that way.
Larry believes that Evan's arrogance also affects the way he treats employees. The U.S.
Constitution protects American workers, and Larry believes that the rights of those at SunriseLynx are violated regularly. At first Evan seemed friendly, even connecting with employees on social media. However, following Evan's political posts, it became clear to Larry that employees with similar affiliations were the only ones offered promotions.
Further, Larry occasionally has packages containing personal-use items mailed to work. Several times, these have come to him already opened, even though this name was clearly marked. Larry thinks the opening of personal mail is common at SunriseLynx, and that Fourth Amendment rights are being trampled under Evan's leadership.
Larry has also been dismayed to overhear discussions about his coworker, Sadie. Telemarketing calls are regularly recorded for quality assurance, and although Sadie is always professional during business, her personal conversations sometimes contain sexual comments. This too is something Larry has heard Evan laughing about. When he mentioned this to a coworker, his concern was met with a shrug. It was the coworker's belief that employees agreed to be monitored when they signed on. Although personal devices are left alone, phone calls, emails and browsing histories are all subject to surveillance. In fact, Larry knows of one case in which an employee was fired after an undercover investigation by an outside firm turned up evidence of misconduct. Although the employee may have stolen from the company, Evan could have simply contacted the authorities when he first suspected something amiss.
Larry wants to take action, but is uncertain how to proceed.
In regard to telemarketing practices, Evan the supervisor has a misconception regarding?

  • A. The relationship of state law to federal law
  • B. The conditions under which recipients can opt out
  • C. The right to monitor calls for quality assurance
  • D. The wishes of recipients who request callbacks

正解:D


質問 # 145
Which of these organizations would be required to provide its customers with an annual privacy notice?

  • A. The Golden Gavel Auction House.
  • B. The Four Winds Tribal College.
  • C. The King County Savings and Loan.
  • D. The Breezy City Housing Commission.

正解:C

解説:
The annual privacy notice requirement under the Gramm-Leach-Bliley Act (GLBA) applies to financial institutions that collect nonpublic personal information from customers and disclose it to nonaffiliated third parties, unless they qualify for an exception. A financial institution is any entity that engages in activities that are financial in nature or incidental to such activities, as defined by section 4(k) of the Bank Holding Company Act of 1956. The King County Savings and Loan is a financial institution under this definition, as it engages in lending money and accepting deposits. Therefore, it is required to provide its customers with an annual privacy notice, unless it meets the conditions for an exception. The Four Winds Tribal College, the Golden Gavel Auction House, and the Breezy City Housing Commission are not financial institutions under the GLBA, as they do not engage in activities that are financial in nature or incidental to such activities. Therefore, they are not required to provide their customers with an annual privacy notice under the GLBA. References:
* Amendment to the Annual Privacy Notice Requirement Under the Gramm-Leach-Bliley Act, section I.
Background, paragraph 2.
* 17 CFR § 248.5 - Annual privacy notice to customers required., paragraph (a) (1).
* IAPP CIPP/US Study Guide, page 65.


質問 # 146
The FTC often negotiates consent decrees with companies found to be in violation of privacy principles. How does this benefit both parties involved?

  • A. It spares the expense of going to trial.
  • B. It avoids potentially harmful publicity.
  • C. It standardizes the amount of fines.
  • D. It simplifies the audit requirements.

正解:A

解説:
Negotiating consent decrees with companies found to be in violation of privacy principles benefits both parties involved by sparing the expense of going to trial. By opting for a consent decree, both the FTC and the company can avoid the time-consuming and costly process of litigation, including a trial. This approach allows for a more efficient resolution to the matter and enables the company to take corrective actions more quickly. Additionally, it can help the company avoid potentially harmful publicity that could arise from a public trial or a prolonged legal battle. While consent decrees might include penalties or fines, they often focus on implementing measures to improve compliance and protect consumers' privacy rights.


質問 # 147
SCENARIO
Please use the following to answer the next QUESTION:
Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop.
"Doing your network?" Matt asked hopefully.
"No," the boy said. "I'm filling out a survey."
Matt looked over his son's shoulder at his computer screen. "What kind of survey?" "It's asking Questions about my opinions."
"Let me see," Matt said, and began reading the list of Questions that his son had already answered. "It's asking your opinions about the government and citizenship. That's a little odd. You're only ten." Matt wondered how the web link to the survey had ended up in his son's email inbox. Thinking the message might have been sent to his son by mistake he opened it and read it. It had come from an entity called the Leadership Project, and the content and the graphics indicated that it was intended for children. As Matt read further he learned that kids who took the survey were automatically registered in a contest to win the first book in a series about famous leaders.
To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if he had been prompted to give information about himself in order to take the survey. His son told him he had been asked to give his name, address, telephone number, and date of birth, and to answer Questions about his favorite games and toys.
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from marketers advertising products for children in his son's inbox, and he decided it was time to report the incident to the proper authorities.
Based on the incident, the FTC's enforcement actions against the marketer would most likely include what violation?

  • A. Disregarding the privacy policy of the children's marketing industry.
  • B. Collecting information from a child under the age of thirteen.
  • C. Intruding upon the privacy of a family with young children.
  • D. Failing to notify of a breach of children's private information.

正解:B

解説:
Based on the incident, the FTC's enforcement actions against the marketer would most likely include the violation of collecting information from a childunder the age of thirteen without obtaining verifiable parental consent, as required by the Children's Online Privacy Protection Act (COPPA) Rule. The COPPA Rule applies to operators of commercial websites and online services (including mobile apps) that collect, use, or disclose personal information from children under 13, and operators of general audience websites or online services that have actual knowledge that they are collecting, using, or disclosing personal information from children under 13. The COPPA Rule also applies to websites or online services that are directed to children under 13 and that collect personal information from users of any age. The COPPA Rule defines personal information to include full name, address, phone number, email address, date of birth, and other identifiers that permit the physical or online contacting of a specific individual. The COPPA Rule requires operators to post a clear and comprehensive online privacy policy describing their information practices for personal information collected online from children; provide direct notice to parents and obtain verifiable parental consent, with limited exceptions, before collecting personal information online from children; give parents the choice of consenting to the operator's collection and internal use of a child's information, but prohibiting the operator from disclosing that information to third parties (unless disclosure is integral to the site or service, in which case, this must be made clear to parents); provide parents access to their child's personal information to review and/or have the information deleted; give parents the opportunity to prevent further use or online collection of a child's personal information; maintain the confidentiality, security, and integrity of information they collect from children, including by taking reasonable steps to release such information only to parties capable of maintaining its confidentiality and security; and retain personal information collected online from a child for only as long as is necessary to fulfill the purpose for which it was collected and delete the information using reasonable measures to protect against its unauthorized access or use. The FTC has the authority to seek civil penalties and injunctive relief for violations of the COPPA Rule. The FTC has brought numerous enforcement actions against operators for violating the COPPA Rule, resulting in millions of dollars in penalties and orders to delete illegally collected data. References:
* Children's Privacy | Federal Trade Commission
* Kids' Privacy (COPPA) | Federal Trade Commission
* FTC Is Escalating Scrutiny of Dark Patterns, Children's Privacy
* FTC to Crack Down on Companies that Illegally Surveil Children Learning Online
* FTC Takes Action Against Company for Collecting Children's Personal Information Without Parental Permission
* [IAPP CIPP/US Certified Information Privacy Professional Study Guide], Chapter 5, pages 165-168.


質問 # 148
SCENARIO
Please use the following to answer the next question:
Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in California. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants' postings on social media, ask question NO:s about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements.
Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle's GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision.
Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results. Nor does Celeste share Felicia's concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale.
Celeste believes that even if the business grows a customer database of a few thousand, it's unlikely that a state agency would hassle an honest business if an accidental security incident were to occur.
In any case, Celeste feels that all they need is common sense ?like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she's right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina.
Based on Felicia's Bring Your Own Device (BYOD) plan, the business consultant will most likely advise Felicia and Celeste to do what?

  • A. Weigh any productivity benefits of the plan against the risk of privacy issues.
  • B. Make employment decisions based on those willing to consent to the plan in writing.
  • C. Adopt the same kind of monitoring policies used for work-issued devices.
  • D. Reconsider the plan in favor of a policy of dedicated work devices.

正解:A

解説:
BYOD is a practice that allows employees to use their own personal devices, such as smartphones, tablets, or laptops, for work-related purposes. BYOD can offer some benefits for both employers and employees, such as increased flexibility, convenience, and productivity.
However, BYOD also poses significant privacy and security risks, such as data breaches, unauthorized access, loss or theft of devices, malware infections, and compliance challenges.
Therefore, the business consultant will most likely advise Felicia and Celeste to weigh any productivity benefits of the plan against the risk of privacy issues, and to implement a comprehensive BYOD policy that addresses the following aspects:
The scope and purpose of the BYOD program, including the types of devices, data, and applications that are allowed or prohibited.
The roles and responsibilities of the employer and the employees, including the ownership, control, and access rights of the devices and the data.
The security measures and controls that are required to protect the devices and the data, such as encryption, passwords, remote wipe, antivirus software, firewalls, and VPNs. The privacy expectations and obligations of the employer and the employees, such as the notice, consent, and disclosure requirements, the limits on data collection and monitoring, the retention and deletion policies, and the rights of access and correction. The legal and regulatory compliance requirements that apply to the BYOD program, such as the FTC Act, the GLBA, the HIPAA, the COPPA, the CCPA, and the GDPR. The incident response and reporting procedures that are followed in the event of a data breach, loss, or theft of a device, or any other privacy or security issue. The training and education programs that are provided to the employees to raise awareness and understanding of the BYOD policy and the best practices. The enforcement and audit mechanisms that are used to ensure compliance and accountability of the BYOD policy, such as sanctions, penalties, reviews, and audits.


質問 # 149
SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S.
and Asia. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
The Board has asked Otto whether the company will need to comply with the new California Consumer Privacy Law (CCPA). What should Otto tell the Board?

  • A. That CCPA will apply to the company only after the California Attorney General determines that it will enforce the statute.
  • B. That business contact information could be considered personal information governed by CCPA.
  • C. That CCPA only applies to companies based in California, which exempts the company from compliance.
  • D. That the company is governed by CCPA, but does not need to take any additional steps because it follows CPBR.

正解:B

解説:
The CCPA applies to any business that collects personal information of California residents, regardless of where the business is located1. The CCPA defines personal information broadly as any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household2. This could include business contact information, such as name, email address, phone number, or job title, if it is linked to a specific individual3. Therefore, Otto should tell the Board that business contact information could be considered personal information governed by CCPA, and that the company may need to comply with the CCPA requirements, such as providing notice, honoring consumer rights requests, and implementing reasonable security measures4. References:
* CIPP/US Practice Questions (Sample Questions), Question 124, Answer C, Explanation C.
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 6, Section 6.2, p.
181-182.
* California Consumer Privacy Act (CCPA), Section 1798.140, Subsection (o).
* CCPA Compliance Checklist for Businesses, Section 2, Subsection (a).


質問 # 150
Which of the following federal agencies does NOT have regulatory authority related to privacy?

  • A. U.S. Department of Commerce.
  • B. U.S. Department of Transportation.
  • C. Federal Reserve
  • D. Consumer Financial Protection Bureau.

正解:B


質問 # 151
All of the following are tasks in the "Discover" phase of building an information management program EXCEPT?

  • A. Developing a process for review and update of privacy policies
  • B. Understanding the laws that regulate a company's collection of information
  • C. Facilitating participation across departments and levels
  • D. Deciding how aggressive to be in the use of personal information

正解:B


質問 # 152
Under Section 702 of FISA, which surveillance program allows data requests of Internet Service Providers?

  • A. RAINBOW
  • B. MAGENTA
  • C. PRISM
  • D. Upstream

正解:C

解説:
Two surveillance programs are currently authorized under Section 702: PRISM and Upstream.
With PRISM, data requests can be made to ISPs. Upstream is about searching internet-based communications as they pass through physical U.S. internet infrastructure.


質問 # 153
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?

  • A. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
  • B. A bill of rights for individuals seeking access to their personal information.
  • C. A code of responsibilities for medical establishments to uphold privacy laws.
  • D. An international court ruling on personal information held in the commercial sector.

正解:D

解説:
The APEC principles are part of the APEC Privacy Framework, which is an inter-governmental agreement among the 21 member economies of the Asia-Pacific Economic Cooperation (APEC) to promote information privacy protection and the free flow of information in the region. The APEC Privacy Framework consists of four parts: a preamble, a scope, a set of nine information privacy principles, and an implementation section.
The APEC information privacy principles are:
* Preventing harm: Personal information controllers should take reasonable steps to protect personal information from loss, misuse, unauthorized access, disclosure, alteration, and destruction, and to address the risks and challenges posed by specific technologies and business practices.
* Notice: Personal information controllers should provide clear and easily accessible statements about their personal information handling practices, including the types of personal information they collect, the purposes for which they collect it, the types of third parties to which they disclose it, the choices and means they offer individuals for limiting the use and disclosure of their personal information, and how they can contact the personal information controller with inquiries or complaints.
* Collection limitation: Personal information controllers should limit the collection of personal information to what is relevant for the purposes of collection and should collect personal information by lawful and fair means and, where appropriate, with notice to, or consent of, the individual concerned.
* Use limitation: Personal information controllers should use personal information only for the purposes for which it was collected or for purposes that a reasonable person would consider appropriate in the circumstances, and should retain personal information only as long as necessary to fulfill the stated purposes or as required by law or regulation.
* Choice: Personal information controllers should offer individuals choices and means to limit the use and disclosure of their personal information, where appropriate, and should respect the choices made by individuals.
* Integrity of personal information: Personal information controllers should take reasonable steps to ensure that personal information is accurate, complete, and up-to-date for the purposes for which it is used.
* Security safeguards: Personal information controllers should protect personal information with reasonable security safeguards against risks such as loss, unauthorized access, destruction, misuse, modification, and disclosure.
* Access and correction: Personal information controllers should give individuals the ability to access and, where appropriate, correct their personal information that is under their control, subject to reasonable limitations, such as where the burden or expense of providing access would be disproportionate to the risks to the individual's privacy, or where the legitimate rights of persons other than the individual would be violated.
* Accountability: Personal information controllers should be accountable for complying with the privacy principles and should have in place mechanisms to ensure their implementation and compliance.
The APEC Privacy Framework is not a binding legal instrument, but rather a voluntary and flexible arrangement that allows each member economy to implement the principles according to its own domestic laws and regulations, applicable international frameworks, and cultural and social values. The APEC Privacy Framework also provides for cross-border cooperation and information sharing among member economies, as well as the development of mechanisms to facilitate the cross-border transfer of personal information,such as the APEC Cross-Border Privacy Rules (CBPR) System and the APEC Privacy Recognition for Processors (PRP) System. These mechanisms are based on a common set of rules and standards derived from the APEC Privacy Framework, and are intended to enhance the protection of personal information that flows across borders and to increase the interoperability among different privacy regimes in the region and beyond. References:
* APEC Privacy Framework (2015)
* APEC Cross-Border Privacy Rules (CBPR) System
* APEC Privacy Recognition for Processors (PRP) System
* APEC Privacy Framework: A New Model for Transborder Data Flows


質問 # 154
What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?

  • A. A judgment rider
  • B. A consent decree
  • C. Common law judgment
  • D. Stare decisis decree

正解:B


質問 # 155
......

100%の合格率を試そう!更新されたのはCIPP-US試験問題 [2025年更新]:https://www.passtest.jp/IAPP/CIPP-US-shiken.html

合格させるCIPP-US試験にはリアル問題解答:https://drive.google.com/open?id=1g8uWDPNeBhy9dyy2wHdq_imzKNXczjKG