CIPP-E問題集最新の2024年10月10日練習テスト270リアル解答があります [Q10-Q29]

Share

CIPP-E問題集最新の2024年10月10日練習テスト270リアル解答があります

2024年最新の100%試験高合格率CIPP-E問題集PDF

質問 # 10
When assessing the level of risk created by a data breach, which of the following would NOT have to be taken into consideration?

  • A. The special characteristics of the data controller.
  • B. The ease of identification of individuals.
  • C. The size of any data processor involved.
  • D. The nature, sensitivity and volume of personal data.

正解:C

解説:
When assessing the level of risk created by a data breach, the size of any data processor involved would not have to be taken into consideration. According to the GDPR, a data breach is "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed" 1. The GDPR requires data controllers and processors to notify the relevant supervisory authority of a data breach within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons 2. The GDPR also requires data controllers to communicate the data breach to the affected data subjects without undue delay, if the breach is likely to result in a high risk to their rights and freedoms 3.
The GDPR does not specify the exact criteria for determining the level of risk, but it provides some guidance in Recital 85, which states that "the likelihood and severity of the risk to the rights and freedoms of the data subject should be determined by reference to the nature, scope, context and purposes of the processing" . The recital also mentions some factors that could increase the risk, such as the ease of identification of individuals, the special categories of personal data, the large scale of the processing, or the special characteristics of the data controller . Therefore, these factors should be taken into consideration when assessing the level of risk created by a data breach.
However, the size of any data processor involved is not relevant for the risk assessment, as it does not affect the impact of the breach on the data subjects. The data processor is only responsible for processing the personal data on behalf of the data controller, and has no direct relationship with the data subjects . The data processor's obligations in case of a data breach are to notify the data controller without undue delay, and to assist the data controller in complying with its obligations under the GDPR . The data processor's size may affect its ability to fulfill these obligations, but it does not change the level of risk created by the data breach itself. Reference: 1: Article 4(12) of the GDPR 2: Article 33 of the GDPR 3: Article 34 of the GDPR : Recital 85 of the GDPR : Article 4(8) of the GDPR : Article 28 of the GDPR I hope this helps. If you have any other questions, please feel free to ask.


質問 # 11
An online company's privacy practices vary due to the fact that it offers a wide variety of services. How could it best address the concern that explaining them all would make the policies incomprehensible?

  • A. Identify uses of data in a privacy notice mailed to the data subject.
  • B. Provide only general information about its processing activities and offer a toll-free number for more information.
  • C. Use a layered privacy notice on its website and in its email communications.
  • D. Place a banner on its website stipulating that visitors agree to its privacy policy and terms of use by visiting the site.

正解:A

解説:
Reference https://www.ftc.gov/sites/default/files/documents/reports/federal-trade-commission-bureau- consumer-protection-preliminary-ftc-staff-report-protecting-consumer/101201privacyreport.pdf


質問 # 12
SCENARIO
Please use the following to answer the next question:
Building Block Inc. is a multinational company, headquartered in Chicago with offices throughout the United States, Asia, and Europe (including Germany, Italy, France and Portugal). Last year the company was the victim of a phishing attack that resulted in a significant data breach. The executive board, in coordination with the general manager, their Privacy Office and the Information Security team, resolved to adopt additional security measures. These included training awareness programs, a cybersecurity audit, and use of a new software tool called SecurityScan, which scans employees' computers to see if they have software that is no longer being supported by a vendor and therefore not getting security updates. However, this software also provides other features, including the monitoring of employees' computers.
Since these measures would potentially impact employees, Building Block's Privacy Office decided to issue a general notice to all employees indicating that the company will implement a series of initiatives to enhance information security and prevent future data breaches.
After the implementation of these measures, server performance decreased. The general manager instructed the Security team on how to use SecurityScan to monitor employees' computers activity and their location.
During these activities, the Information Security team discovered that one employee from Italy was daily connecting to a video library of movies, and another one from Germany worked remotely without authorization. The Security team reported these incidents to the Privacy Office and the general manager. In their report, the team concluded that the employee from Italy was the reason why the server performance decreased.
Due to the seriousness of these infringements, the company decided to apply disciplinary measures to both employees, since the security and privacy policy of the company prohibited employees from installing software on the company's computers, and from working remotely without authorization.
What would be the MOST APPROPRIATE way for Building Block to handle the situation with the employee from Italy?

  • A. Since the employee was not informed that the security measures would be used for other purposes such as monitoring, the company could face difficulties in applying any disciplinary measures to this employee.
  • B. Since the employee was the cause of a serious risk for the server performance and their data, the company would be entitled to apply disciplinary measures to this employee, including fair dismissal.
  • C. Since this was a serious infringement, but the employee was not appropriately informed about the consequences the new security measures, the company would be entitled to apply some disciplinary measures, but not dismissal.
  • D. Since the GDPR does not apply to this situation, the company would be entitled to apply any disciplinary measure authorized under Italian labor law.

正解:C


質問 # 13
Which kind of privacy notice, originally advocated by the Article 29 Working Party, is commonly recommended tor Al-based technologies because of the way it provides processing information at specific points of data collection?

  • A. Privacy dashboard notice
  • B. Visualization notice.
  • C. Just-in-lime notice.
  • D. Layered notice.

正解:A

解説:
According to the Article 29 Working Party, a just-in-time notice is a type of privacy notice that provides processing information at specific points of data collection, such as when the user clicks on a certain feature or enters personal data1. This kind of notice is commonly recommended for AI-based technologies because it allows the user to receive relevant and timely information about the processing of their data, without being overwhelmed by lengthy and complex privacy statements1. A just-in-time notice can also be combined with other types of notices, such as layered notices or privacy dashboards, to provide a more comprehensive and user-friendly transparency framework1. Therefore, option C is the correct answer. Option A is incorrect because a privacy dashboard notice is a type of notice that provides the user with a centralised and interactive overview of the processing of their data, and allows them to manage their privacy settings and preferences1. Option B is incorrect because a visualization notice is a type of notice that uses graphical elements, such as icons, symbols, colours, or animations, to convey the processing information in a more intuitive and engaging way1. Option D is incorrect because a layered notice is a type of notice that provides the processing information in a hierarchical and modular way, starting with the most essential information and allowing the user to access more details if they wish1. Reference:
What's new in WP29's final guidelines on transparency?


質問 # 14
SCENARIO
Please use the following to answer the next question:
Outliers Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Jonathan, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company ZenFiTech, hoping that they can design a new, cutting-edge website for Outliers Inc.'s foundering business.
During negotiations, a ZenFiTech representative describes a plan for gathering more customer information through detailed questionnaires, which could be used to tailor their preferences to specific travel destinations. Outliers Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Jonathan loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the questionnaires will require customers to provide explicit consent to having their data collected. The ZenFiTech representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the Outliers Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which ZenFiTech will analyze by means of a special program. Outliers Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Jonathan enthusiastically engages ZenFiTech for these services.
With regard to Outliers Inc.'s use of website cookies, which of the following statements is correct?

  • A. Because not all of the cookies are strictly necessary to enable the use of a service requested from Outliers Inc., consent requirements apply to their use of cookies.
  • B. Because the use of cookies involves the potential for location tracking, explicit consent must be obtained from customers.
  • C. Because ZenFiTech will receive only aggregate statistics of data collected from the cookies, no additional consent is necessary.
  • D. Because of the categories of data involved, explicit consent for the use of cookies must be obtained separately from customers.

正解:D


質問 # 15
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?

  • A. The measures being taken to address the breach.
  • B. The predicted consequences of the breach.
  • C. The type of security safeguards used to protect the data.
  • D. The contact details of the appropriate data protection officer.

正解:B

解説:
Reference https://www.dataprotection.ie/en/organisations/know-your-obligations/data-protection-impact- assessments


質問 # 16
According to Art 23 GDPR, which of the following data subject rights can NOT be restricted?

  • A. Right to lodge a complaint with a supervisory authority.
  • B. Right not to be subject to automated individual decision-making
  • C. Right to erasure ("Right to be forgotten").
  • D. Right to restriction of processing.

正解:A

解説:
According to Article 23 of the GDPR, the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, may be restricted by a legislative measure of a Member State or the Union, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard certain public interests or the rights and freedoms of others1. However, Article 23 does not include Article 77, which grants the data subject the right to lodge a complaint with a supervisory authority if the data subject considers that the processing of personal data relating to him or her infringes the GDPR2. Therefore, this right cannot be restricted by any legislative measure, as it is essential for the effective judicial protection of the data subject and the enforcement of the GDPR3. Reference:
Free CIPP/E Study Guide, page 14, section 2.3
GDPR, Article 77
GDPR, Article 23
Guidelines on restrictions of data subject rights under Art. 23 of the GDPR, page 4, section 2 Statement on restrictions on data subject rights in connection to the COVID-19 pandemic, page 2, section 2


質問 # 17
When does the European Data Protection Board (EDPB) recommend reevaluating whether a transfer tool is effectively providing a level of personal data protection that is in compliance with the European Union (EU) level?

  • A. On an ongoing basis.
  • B. Every three (3) years.
  • C. After a personal data breach.
  • D. Every year.

正解:A

解説:
Reference https://edpb.europa.eu/sites/default/files/consultation/edpb_recommendations_202001_supplementarymeasurestransferstools_en.pdf


質問 # 18
When may browser settings be relied upon for the lawful application of cookies?

  • A. When users are aware of the ability to adjust their settings.
  • B. When users are provided with information about which cookies have been set.
  • C. When it is impossible to bypass the choices made by users in their browser settings.
  • D. When a user rejects cookies that are strictly necessary.

正解:A


質問 # 19
Which marketing-related activity is least likely to be covered by the provisions of Privacy and Electronic Communications Regulations (Directive 2002/58/EC)?

  • A. An email from a retail outlet promoting a sale to one of their previous customer.
  • B. The use of cookies to collect data about an individual.
  • C. Advertisements passively displayed on a website.
  • D. A text message to individuals from a company offering concert tickets for sale.

正解:C


質問 # 20
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations. TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?

  • A. The destruction of the stolen data makes any risk to the affected data subjects unlikely.
  • B. The incident resulted from the actions of a third-party that were beyond their control.
  • C. The sensitivity of the categories of data involved in the incident was not substantial enough.
  • D. The resulting obligation to notify data subjects would involve disproportionate effort.

正解:B


質問 # 21
To provide evidence of GDPR compliance, a company performs an internal audit. As a result, it finds a data base, password-protected, listing all the social network followers of the client.
Regarding the domain of the controller-processor relationships, how is this situation considered?

  • A. Compliant with the storage limitation principle, so long as the internal auditor permanently deletes the data base.
  • B. Compliant with the security principle, because the data base is password-protected.
  • C. Non-compliant, because the storage of the data exceeds the tasks contractually authorized by the controller.
  • D. Not applicable, because the data base is password protected, and therefore is not at risk of identifying any data subject.

正解:C

解説:
The GDPR requires that the processor only processes personal data on behalf of the controller and according to the controller's instructions12. The agreement between the controller and the processor must include provisions that ensure that the processor does not process personal data for any other purposes or in a manner that is inconsistent with the controller's instructions34. Therefore, if the processor stores personal data that is not necessary for the performance of the contract with the controller, such as the social network followers of the client, this is a breach of the GDPR and the processor may be fined2. The fact that the data base is password-protected does not affect the applicability of the GDPR or the security principle, as the data is still personal data that can identify data subjects. The storage limitation principle also requires that personal data be kept for no longer than is necessary for the purposes for which the personal data are processed, so deleting the data base after the audit does not make the situation compliant. Reference: 1: Article 28 of the GDPR 2: Guidelines 07/2020 on the concepts of controller and processor in the GDPR 3: Understanding Controller-to-Processor Agreements - GDPR Advisor 4: New Guidelines on Data Controllers and Processors: Time to Review Data Processing Agreements : Article 4 of the GDPR : Article 5 of the GDPR


質問 # 22
Which sentence best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?

  • A. Employees who control personal data must complete a rigorous certification procedure, as they are exempt from legal enforcement.
  • B. All employees are subject to the rules in their entirety, regardless of where the work is taking place.
  • C. All employees must follow the privacy regulations of the jurisdictions where the current scope of their work is established.
  • D. Employees must sign an ad hoc contractual agreement each time personal data is exported.

正解:B

解説:
According to Article 47(2)(a) of the GDPR, binding corporate rules (BCRs) must be legally binding and apply to and be enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees1. This means that all employees within the group must comply with the BCRs, irrespective of their location or the jurisdiction where they operate. The other options are incorrect, as they do not reflect the requirements of the GDPR or the guidance of the European Data Protection Board (EDPB) on BCRs23. Reference:
GDPR Article 47(2)(a)
EDPB Guidelines 3/2018 on the territorial scope of the GDPR
EDPB Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679


質問 # 23
Pursuant to Article 4(5) of the GDPR, data is considered "pseudonymized" if?

  • A. It cannot be attributed to a data subject without the use of additional information.
  • B. It can only be attributed to a person by the controller.
  • C. It can only be attributed to a person by a third party.
  • D. It cannot be attributed to a person under any circumstances.

正解:A

解説:
Reference:
According to Article 4(5) of the GDPR, pseudonymization is "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person." Therefore, option A is the correct definition of pseudonymization. Option B is incorrect because pseudonymized data can still be attributed to a person with the use of additional information. Option C is incorrect because pseudonymization does not depend on who can attribute the data to a person, but on how the data is processed. Option D is incorrect for the same reason as option C. Reference:
GDPR Article 4(5)
CIPP/E Study Guide, page 9


質問 # 24
A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is the company first required to do?

  • A. Proceed no further, as such repurposing is unlawful
  • B. Only inform the data subjects of the new purpose.
  • C. Update the privacy notice upon which consent was given
  • D. Obtain specific consent for the new processing

正解:D

解説:
According to the GDPR, consent is one of the lawful bases for processing personal data1. Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her2. Therefore, consent must be specific to each purpose of processing and cannot be bundled with other purposes3. If a company wants to use personal data for a new purpose that is not compatible with the original purpose for which consent was given, it must obtain a new consent from the data subjects for the new processing4. Simply informing the data subjects of the new purpose or updating the privacy notice is not sufficient, as it does not imply the data subject's agreement to the new processing. Proceeding with the new processing without obtaining a new consent would be unlawful and could result in fines and sanctions5. Reference:
Free CIPP/E Study Guide, page 23, section 4.1.1
GDPR, Article 4 (11)
GDPR, Recital 32
GDPR, Article 6 (4)
GDPR, Article 83 (5) (a)


質問 # 25
In which of the following cases would an organization MOST LIKELY be required to follow both ePrivacy and data protection rules?

  • A. When creating an untargeted pop-up ad on a website.
  • B. When paying a search engine company to give prominence to certain products and services within specific search results.
  • C. When emailing a customer to announce that his recent order should arrive earlier than expected.
  • D. When calling a potential customer to notify her of an upcoming product sale.

正解:A


質問 # 26
What term BEST describes the European model for data protection?

  • A. Sectoral
  • B. Comprehensive
  • C. Market-based
  • D. Self-regulatory

正解:A

解説:
Explanation/Reference: https://ec.europa.eu/info/sites/info/files/communication-european-strategy-data-19feb2020_en.pdf


質問 # 27
Under Article 80(1) of the GDPR, individuals can elect to be represented by not-for-profit organizations in a privacy group litigation or class action. These organizations are commonly known as?

  • A. Human rights organizations.
  • B. Civil society organizations.
  • C. Law firm organizations.
  • D. Constitutional rights organizations.

正解:B

解説:
Reference https://gdpr-info.eu/art-80-gdpr/


質問 # 28
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Under the GDPR, Liem and EcoMick's contract with MarketIQ must include all of the following provisions EXCEPT?

  • A. Assistance to Liem and EcoMick in their compliance with data protection impact assessments.
  • B. Processing the personal data upon documented instructions regarding data transfers outside of the EEA.
  • C. Returning or deleting personal data after the end of the provision of the services.
  • D. Notification regarding third party requests for access to Liem and EcoMick's personal data.

正解:A


質問 # 29
......

検証済みCIPP-E問題集と解答100%合格はPassTest:https://www.passtest.jp/IAPP/CIPP-E-shiken.html

合格試験完全版合格させる CIPP-E問題集270解答:https://drive.google.com/open?id=1djEIcL9OCl6gNbiGbA3_CwGRzPk-6n0u