
更新された2025年02月06日 CIPP-US試験問題集でPDF問題とテストエンジン
最新(2025)IAPP CIPP-US試験問題集
CIPP-US認定試験は、米国の連邦および州のプライバシー法、規制、業界のベストプラクティスを含む幅広いトピックをカバーしています。この認定を保持している専門家は、複雑な規制環境をナビゲートし、データ保護法の遵守を確保するために装備されています。さらに、彼らは彼らの分野の専門家として認識されており、彼らのキャリアの見通しを高めることができます。
CIPP-US試験は90問の選択式問題から成り、2時間半かかります。試験に備えるためには、候補者はプライバシー法や規制、データセキュリティの実践、プライバシー管理フレームワークに堅固な基盤を持っている必要があります。これは、教室でのトレーニング、自己学習、模擬試験を通じて達成できます。
質問 # 40
A law enforcement subpoenas the ACME telecommunications company for access to text message records of a person suspected of planning a terrorist attack. The company had previously encrypted its text message records so that only the suspect could access this data.
What law did ACME violate by designing the service to prevent access to the information by a law enforcement agency?
- A. CALEA
- B. USA Freedom Act
- C. ECPA
- D. SCA
正解:A
解説:
The law that ACME violated by designing the service to prevent access to the information by a law enforcement agency is the Communications Assistance for Law Enforcement Act (CALEA)1. CALEA is a federal law that requires telecommunications carriers and manufacturers of telecommunications equipment to design their equipment, facilities, and services to ensure that they have the necessary surveillance capabilities to comply with legal requests for interception of communications2. CALEA applies to all commercial messages, including text messages, and gives law enforcement agencies the authority to subpoena the records of such communications from the service providers3. By encrypting its text message records so that only the suspect could access this data, ACME violated CALEA's duty to cooperate in the interception of communications for law enforcement purposes. References: 1: Communications Assistance for Law Enforcement Act - Wikipedia2: Home | CALEA | The Commission on Accreditation for Law Enforcement Agencies, Inc.3: Communications Assistance for Law Enforcement Act : IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 6: Law Enforcement and National Security Access, p.
177
質問 # 41
What is an exception to the Electronic Communications Privacy Act of 1986 ban on interception of wire, oral and electronic communications?
- A. Where state law permits such interception
- B. If an organization intercepts an employee's purely personal call
- C. Only if all parties have given consent
- D. Where one of the parties has given consent
正解:B
質問 # 42
How did the Fair and Accurate Credit Transactions Act (FACTA) amend the Fair Credit Reporting Act (FCRA)?
- A. It increased the obligation of organizations to dispose of consumer data in ways that prevent unauthorized access
- B. It stipulated the purpose of obtaining a consumer report can only be for a review of the employee's credit worthiness
- C. It expanded the definition of "consumer reports" to include communications relating to employee investigations
- D. It required employers to get an employee's consent in advance of requesting a consumer report for internal investigation purposes Section: (none) Explanation
正解:A
質問 # 43
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
- A. Vermont.
- B. New York.
- C. Washington.
- D. California.
正解:A
解説:
According to the web search results from my predefined tool, Vermont became the first state to pass a law specifically regulating the practices of data brokers in 2018. The law defines a data broker as "a business, or unit or units of a business, separately or together, that knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom the business does not have a direct relationship." The law requires data brokers to register with the Secretary of State, pay a registration fee, provide information about their data collection and opt-out practices, and implement security measures to protect the personal information they collect and sell. The law also imposes additional obligations on data brokers that possess the personal information of minors. The law aims to increase the transparency and accountability of the data broker industry and to protect the privacy rights of consumers12. References:
* Registered Data Brokers in the United States: 2021 | Privacy Rights ...
* Am I A Data Broker?: A Quick Primer on State Laws Regulating a ... - Taft
質問 # 44
According to FERPA, when can a school disclose records without a student's consent?
- A. If the disclosure is not to be conducted through email to the third party
- B. If the disclosure is to provide transcripts to a school where a student intends to enroll
- C. If the disclosure would not reveal a student's student identification number
- D. If the disclosure is to practitioners who are involved in a student's health care
正解:B
解説:
According to FERPA, a school may disclose personally identifiable information (PII) from an eligible student's education records without consent if the disclosure meets one of the exceptions in 34 CFR § 99.31.
One of these exceptions is for disclosures to other schools to which a student seeks or intends to enroll, or is already enrolled if the disclosure is for purposes related to the student's enrollment or transfer (34 CFR §
99.31(a)(2)). This exception allows schools to disclose transcripts, recommendations, or other information that may facilitate the student's admission or enrollment at another school. However, the school must make a reasonable attempt to notify the student of the disclosure, unless the student initiated the disclosure, and must provide the student with a copy of the records that were disclosed upon request (34 CFR §
99.34(a)(1)). References: https://studentprivacy.ed.gov/ferpa
https://studentprivacy.ed.gov/ferpa
質問 # 45
Which statement is FALSE regarding the provisions of the Employee Polygraph Protection Act of 1988 (EPPA)?
- A. The EPPA includes an exception that allows polygraph tests in professions in which employee honesty is necessary for public safety.
- B. Employers are prohibited from administering psychological testing based on personality traits such as honesty, preferences or habits.
- C. Employers involved in the manufacture of controlled substances may terminate employees based on polygraph results if other evidence exists.
- D. The EPPA requires that employers post essential information about the Act in a conspicuous location.
正解:B
解説:
Section: (none)
Explanation
質問 # 46
In 2014, Google was alleged to have violated the Family Educational Rights and Privacy Act (FERPA) through its Apps for Education suite of tools. For what specific practice did students sue the company?
- A. Scanning emails sent to and received by students
- B. Relying on verbal consent for a disclosure of education records
- C. Disclosing education records without obtaining required consent
- D. Making student education records publicly available
正解:A
解説:
Explanation/Reference: https://www.edweek.org/ew/articles/2014/03/13/26google.h33.html
質問 # 47
SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S. and Asi a. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
The Board has asked Otto whether the company will need to comply with the new California Consumer Privacy Law (CCPA). What should Otto tell the Board?
- A. That CCPA will apply to the company only after the California Attorney General determines that it will enforce the statute.
- B. That the company is governed by CCPA, but does not need to take any additional steps because it follows CPBR.
- C. That CCPA only applies to companies based in California, which exempts the company from compliance.
- D. That business contact information could be considered personal information governed by CCPA.
正解:D
解説:
CCPA applies regardless of enforcement. Under the CPRA, which amended the CCPA, business contact information is PII.
質問 # 48
Which venture would be subject to the requirements of Section 5 of the Federal Trade Commission Act?
- A. A city bus system's frequent rider program
- B. A local nonprofit charity's fundraiser
- C. An online merchant's free shipping offer
- D. A national bank's no-fee checking promotion
正解:C
解説:
Section 5 of the Federal Trade Commission Act (FTC Act) prohibits "unfair or deceptive acts or practices in or affecting commerce."1 This prohibition applies to all persons engaged in commerce, including banks, but also exempts some entities, such as nonprofit organizations and common carriers, from FTC jurisdiction.2 Therefore, among the four options, only an online merchant's free shipping offer would be subject to the requirements of Section 5, as it involves a commercial activity thatcould potentially mislead or harm consumers. For example, if the online merchant fails to disclose the terms and conditions of the offer, or charges hidden fees, or delivers the products late or damaged, it could violate Section 5 by engaging in a deceptive practice.3 References: 1: Section 5 | Federal Trade Commission 2: Federal Trade Commission Act Section 5: Unfair or Deceptive Acts or Practices, page 13: IAPP CIPP/US Certified Information Privacy Professional Study Guide, page 23.
質問 # 49
Which statement is FALSE regarding the provisions of the Employee Polygraph Protection Act of 1988 (EPPA)?
- A. The EPPA includes an exception that allows polygraph tests in professions in which employee honesty is necessary for public safety.
- B. Employers are prohibited from administering psychological testing based on personality traits such as honesty, preferences or habits.
- C. Employers involved in the manufacture of controlled substances may terminate employees based on polygraph results if other evidence exists.
- D. The EPPA requires that employers post essential information about the Act in a conspicuous location.
正解:B
解説:
The false statement regarding the provisions of the EPPA is C. Employers are prohibited from administering psychological testing based on personality traits such as honesty, preferences or habits. The EPPA does not regulate psychological testing, only polygraph testing. Psychological testing is a broad term that covers various types of assessments that measure cognitive abilities, personality traits, interests, values, and skills.
Employers may use psychological testing for various purposes, such as hiring, promotion, training, or development, as long as they comply with other laws and regulations, such as the Americans with Disabilities Act (ADA), the Equal Employment Opportunity Commission (EEOC) guidelines, and the Uniform Guidelines on Employee Selection Procedures. However, employers should be careful to ensure that thepsychological tests they use are valid, reliable, job-related, and nondiscriminatory, and that they respect the privacy and dignity of the test takers. References:
* [IAPP CIPP/US Study Guide], Chapter 4: Workplace Privacy, pp. 115-116.
* IAPP CIPP/US Body of Knowledge, Section IV: Workplace Privacy, Subsection A: Employee Privacy Expectations, Topic 2: Employee Polygraph Protection Act.
* IAPP CIPP/US Practice Questions, Question 142.
質問 # 50
Under the Fair Credit Reporting Act (FCRA), what must a person who is denied employment based upon his credit history receive?
- A. Information from several consumer reporting agencies (CRAs).
- B. A prompt notification from the employer.
- C. A list of rights from the Consumer Financial Protection Bureau (CFPB).
- D. An opportunity to reapply with the employer.
正解:C
解説:
https://www.consumerfinance.gov/compliance/supervision-examinations/fair-credit-reporting-act-fcra-examination-procedures/ In 2010, Congress passed the Dodd-Frank Wall Street Reform and Consumer Protection Act (Dodd-Frank Act), which granted rule-making authority under FCRA (except for Section 615(e) (red flag guidelines and regulation) and Section 628 (disposal of records) to the Consumer Financial Protection Bureau (CFPB). The Dodd-Frank Act also amended two provisions of the FCRA to require the disclosure of a credit score and related information when a credit score is used in taking an adverse action or in risk-based pricing.
質問 # 51
If an organization maintains data classified as high sensitivity in the same system as data classified as low sensitivity, which of the following is the most likely outcome?
- A. The organization will be able to address legal discovery requests efficiently without producing more information than necessary.
- B. The organization will still be in compliance with most sector-specific privacy and security laws.
- C. The impact of an organizational data breach will be more severe than if the data had been segregated.
- D. Temporary employees will be able to find the data necessary to fulfill their responsibilities.
正解:C
解説:
"Holding all data in one system can increase the consequences of a single breach" Excerpt From: "IAPP_US_TB_US-Private-Sector-Privacy-3E_1.0." Apple Books.
質問 # 52
What practice does the USA FREEDOM Act NOT authorize?
- A. The bulk collection of telephone data and internet metadata
- B. An increase in the maximum penalty for material support to terrorism
- C. An extension of the expiration for roving wiretaps
- D. Emergency exceptions that allows the government to target roamers
正解:A
解説:
The USA FREEDOM Act is a law that was enacted in 2015 to reform the surveillance practices of the U.S.
government. The law was a response to the revelations by Edward Snowden about the mass collection of phone records and internet data by the National Security Agency (NSA) under the authority of Section 215 of the USA PATRIOT Act. The USA FREEDOM Act ended the bulk collection of telephone data and internet metadata by the NSA, and instead required the government to obtain a specific order from the Foreign Intelligence Surveillance Court (FISC) to access such data from the telecommunication providers. The law also authorized the following practices:
* Emergency exceptions that allow the government to target roamers: The law allows the government to temporarily target a non-U.S. person who is using a phone number or identifier of a U.S. person, without a court order, if there is an emergency situation that involves a threat of death or serious bodily harm.
The government must obtain a court order within seven days to continue the surveillance.
* An increase in the maximum penalty for material support to terrorism: The law increases the maximum prison term for providing material support or resources to a foreign terrorist organization from 15 years to 20 years.
* An extension of the expiration for roving wiretaps: The law extends the sunset date for the roving wiretap provision of the USA PATRIOT Act, which allows the government to obtain a single order from the FISC to conduct surveillance on a target who switches devices or locations, without specifying the device or location. The law extends the expiration date from June 1, 2015 to December 15,
2019. References:
* USA FREEDOM Act
* USA FREEDOM Act Summary
* USA FREEDOM Act FAQs
質問 # 53
Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what?
- A. Delete their personal information.
- B. Refrain from selling their personal information to third parties.
- C. Correct their personal information.
- D. Disclose their personal information to them.
正解:C
質問 # 54
SCENARIO
Please use the following to answer the next QUESTION
Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy program. Filtration Station is a U.S. company that sells filters and tubing products to pharmaceutical companies for research use. The company is based in Seattle, Washington, with offices throughout the U.S.
and Asia. It sells to business customers across both the U.S. and the Asia-Pacific region. Filtration Station participates in the Cross-Border Privacy Rules system of the APEC Privacy Framework.
Unfortunately, Filtration Station suffered a data breach in the previous quarter. An unknown third party was able to gain access to Filtration Station's network and was able to steal data relating to employees in the company's Human Resources database, which is hosted by a third-party cloud provider based in the U.S. The HR data is encrypted. Filtration Station also uses the third-party cloud provider to host its business marketing contact database. The marketing database was not affected by the data breach. It appears that the data breach was caused when a system administrator at the cloud provider stored the encryption keys with the data itself.
The Board has asked Otto to provide information about the data breach and how updates on new developments in privacy laws and regulations apply to Filtration Station. They are particularly concerned about staying up to date on the various U.S. state laws and regulations that have been in the news, especially the California Consumer Privacy Act (CCPA) and breach notification requirements.
What can Otto do to most effectively minimize the privacy risks involved in using a cloud provider for the HR data?
- A. Negotiate a Business Associate Agreement with the cloud provider to protect any health-related data employees might share with Filtration Station.
- B. Obtain express consent from employees for storing the HR data in the cloud and keep a record of the employee consents.
- C. Request that the Board sign off in a written document on the choice of cloud provider.
- D. Ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit.
正解:D
解説:
The best way for Otto to minimize the privacy risks involved in using a cloud provider for the HR data is to ensure that the cloud provider abides by the contractual requirements by conducting an on-site audit. This would allow Otto to verify that the cloud provider has implemented adequate security measures, such as encryption, access controls, and backup systems, to protect the HR data from unauthorized access, use, or disclosure. It would also allow Otto to check that the cloud provider is complying with the applicable privacy laws and regulations, such as the CCPA, the APEC Privacy Framework, and the breach notification requirements. By conducting an on-site audit, Otto can identify any gaps or weaknesses in the cloud provider's privacy practices and address them promptly. This would also demonstrate due diligence and accountability on the part of Filtration Station, which could mitigate the legal and reputational consequences of a data breach. References:
* [IAPP CIPP/US Study Guide], Chapter 3: Data Assessments, pp. 77-78.
* IAPP CIPP/US Body of Knowledge, Section III: Government and Court Access to Private-sector Information, Subsection B: Cross-Border Data Transfer, Topic 2: APEC Privacy Framework.
* IAPP CIPP/US Practice Questions, Question 125.
質問 # 55
Which of the following accurately describes the purpose of a particular federal enforcement agency?
- A. The National Institute of Standards and Technology (NIST) has established mandatory privacy standards that can then be enforced against all for-profit organizations by the Department of Justice (DOJ).
- B. The Federal Trade Commission (FTC) is typically recognized as having the broadest authority under the FTC Act to address unfair or deceptive privacy practices.
- C. The Federal Communications Commission (FCC) regulates privacy practices on the internet and enforces violations relating to websites' posted privacy disclosures.
- D. The Cybersecurity and Infrastructure Security Agency (CISA) is authorized to bring civil enforcement actions against organizations whose website or other online service fails to adequately secure personal information.
正解:B
質問 # 56
Read this notice:
Our website uses cookies. Cookies allow us to identify the computer or device you're using to access the site, but they don't identify you personally. For instructions on setting your Web browser to refuse cookies, click here.
What type of legal choice does not notice provide?
- A. Mandatory
- B. Opt-out
- C. Opt-in
- D. Implied consent
正解:D
質問 # 57
Which of the following does Title VII of the Civil Rights Act prohibit an employer from asking a job applicant?
- A. Questions about intended pregnancy
- B. Questions about a disability
- C. Questions about age
- D. Questions about a national origin
正解:A
解説:
Title VII of the Civil Rights Act of 1964 is a federal law that prohibits employment discrimination based on race, color, religion, sex, and national origin1 It also prohibits retaliation against individuals who assert their rights under the law or participate in an EEOC investigation1 Title VII applies to employers with 15 or more employees, as well as to employment agencies, labor organizations, and joint labor-management committees1 Title VII prohibits employers from making pre-employment inquiries that express a preference, limitation, or specification based on any of the protected characteristics, unless they are bona fide occupational qualifications (BFOQs)2 BFOQs are rare and narrowly construed exceptions that allow employers to consider a protected characteristic when it is reasonably necessary to the normal operation of the business2 For example, a religious organization may require its employees to share its faith, or a women's shelter may hire only female counselors2 Option A is incorrect because questions about age are not prohibited by Title VII, but by the Age Discrimination in Employment Act of 1967 (ADEA), which protects individuals who are 40 years of age or older from employment discrimination based on age3 The ADEA generally prohibits employers from asking applicants about their age or date of birth, unless age is a BFOQ or the inquiry is part of a lawful affirmative action plan3 Option B is incorrect because questions about a disability are not prohibited by Title VII, but by the Americans with Disabilities Act of 1990 (ADA), which protects qualified individuals with disabilities from employment discrimination based on disability4 The ADA generally prohibits employers from asking applicants about whether they have a disability or the nature or severity of a disability, unless the inquiry is related to the ability to perform the essential functions of the job with or without reasonable accommodation4 Option C is incorrect because questions about a national origin are prohibited by Title VII, but not in all circumstances. Title VII prohibits employers from asking applicants about their national origin, ancestry, birthplace, native language, or accent, unless they are BFOQs or the inquiry is related to a legitimate business purpose, such as verifying eligibility to work in the United States or assessing language proficiency for a job that requires communication skills25 Option D is correct because questions about intended pregnancy are prohibited by Title VII, as amended by the Pregnancy Discrimination Act of 1978 (PDA), which protects women from employment discrimination based on pregnancy, childbirth, or related medical conditions. The PDA prohibits employers from asking applicants about whether they are pregnant or intend to become pregnant, unless they are related to the ability to perform the job. Such questions may indicate an intent to discriminate based on sex or pregnancy, or may deter women from applying for certain jobs.
References: 1: Title VII of the Civil Rights Act of 1964 | U.S. Equal Employment Opportunity Commission 2: Questions and Answers about Race and Color Discrimination in Employment | U.S. Equal Employment Opportunity Commission 3: Age Discrimination | U.S. Equal Employment Opportunity Commission 4: Disability Discrimination | U.S. Equal Employment Opportunity Commission 5: National Origin Discrimination | U.S. Equal Employment Opportunity Commission : Pregnancy Discrimination | U.S.
Equal Employment Opportunity Commission
質問 # 58
Which action is prohibited under the Electronic Communications Privacy Act of 1986?
- A. Accessing stored communications with the consent of the sender or recipient of the message
- B. Intercepting electronic communications and unauthorized access to stored communications
- C. Monitoring employee telephone calls of a personal nature
- D. Monitoring all employee telephone calls
正解:B
質問 # 59
Which of the following practices is NOT a key component of a data ethics framework?
- A. Automated decision-making.
- B. Data governance.
- C. Preferability testing.
- D. Auditing.
正解:A
解説:
A data ethics framework is a set of principles and guidelines that help organizations ensure that their data practices are ethical, responsible, and trustworthy. According to the IAPP CIPP/US Study Guide, some of the key components of a data ethics framework are1:
* Data governance: the policies, processes, and standards that govern how data is collected, used, stored, and shared within an organization.
* Preferability testing: the process of assessing the potential impacts and risks of data-driven solutions on stakeholders, such as customers, employees, and society.
* Auditing: the process of monitoring, reviewing, and verifying the compliance and performance of data practices against the established ethical standards and legal requirements. Automated decision-making, on the other hand, is not a key component of a data ethics framework, but rather a data practice that may raise ethical issues and challenges. Automated decision-making refers to the use of algorithms, artificial intelligence, or machine learning to make decisions or recommendations without human intervention2. While automated decision-making can offer benefits such as efficiency, accuracy, and consistency, it can also pose risks such as bias, discrimination, lack of transparency, and accountability3.
Therefore, automated decision-making should be subject to ethical evaluation and oversight, but it is not itself a part of a data ethics framework. References:
* [IAPP CIPP/US Study Guide], Chapter 10, Section 10.4, page 287
* [IAPP Glossary], Automated Decision-Making
* IAPP Resources, Ethical Data Use and Automated Decision-Making: A Practical Guide
質問 # 60
Acme Student Loan Company has developed an artificial intelligence algorithm that determines whether an individual is likely to pay their bill or default. A person who is determined by the algorithm to be more likely to default will receive frequent payment reminder calls, while those who are less likely to default will not receive payment reminders.
Which of the following most accurately reflects the privacy concerns with Acme Student Loan Company using artificial intelligence in this manner?
- A. If the algorithm makes automated decisions based on risk factors and public information, Acme need not determine if the algorithm has a disparate impact on protected classes.
- B. If the algorithm's methodology is disclosed to consumers, then it is acceptable for Acme to have a disparate impact on protected classes.
- C. If the algorithm uses risk factors that impact the automatic decision engine. Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output.
- D. If the algorithm uses information about protected classes to make automated decisions, Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output.
正解:D
解説:
The correct answer is D. If the algorithm uses information about protected classes to make automated decisions, Acme must ensure that the algorithm does not have a disparate impact on protected classes in the output. The Fair Credit Reporting Act (FCRA) protects consumers from unfair, inaccurate, and discriminatory treatment by creditors and other businesses that use credit reports. The FCRA prohibits creditors from using information about protected classes, such as race, color, religion, national origin, sex, marital status, age, or because they receive income from a public assistance program, to make decisions about credit. In the case of Acme Student Loan Company, the algorithm is using information about protected classes to make automated decisions about whether to send payment reminder calls. This could have a disparate impact on protected classes, such as people of color or people with low incomes. For example, people of color may be more likely to be identified as being at risk of default, even if they are just as likely to repay their loans as people of other races. Acme Student Loan Company must ensure that the algorithm does not have a disparate impact on protected classes. This could be done by using a variety of methods, such as:
* Testing the algorithm for accuracy, fairness, and bias before and after deployment
* Providing consumers with notice and consent options for the use of their data
* Allowing consumers to access, correct, or delete their data
* Implementing accountability and oversight mechanisms for the algorithm
* Ensuring compliance with applicable laws and regulations
References: https://economictimes.indiatimes.com/news/how-to/ai-and-privacy-the-privacy-concerns- surrounding-ai-its-potential-impact-on-personal-data/articleshow/99738234.cms
https://pupuweb.com/iapp-cipp-us-qa-privacy-concerns-acme-student-loan-company-artificial-intelligence/
質問 # 61
......
IAPP CIPP-US試験は、90問の選択式問題で構成され、個人は2.5時間で試験を完了する必要があります。試験は、米国のプライバシー法規制、プライバシープログラムのガバナンス、データ漏えい、職場におけるプライバシー問題の4つの主要カテゴリをカバーしています。試験に合格するためには、500点満点中300点以上のスコアが必要です。
更新された検証済みの合格させるCIPP-US試験にはリアル問題と解答:https://www.passtest.jp/IAPP/CIPP-US-shiken.html
最適な練習法にはIAPP CIPP-US試験の素晴らしいCIPP-US試験問題PDF:https://drive.google.com/open?id=16HBuvijQPSRfnTR9fDXhpWxRlC-errjc