IAPP CIPP-E試験問題(更新されたのは2023年)100%リアル問題解答 [Q43-Q61]

Share

IAPP CIPP-E試験問題(更新されたのは2023年)100%リアル問題解答

合格させるIAPP CIPP-E試験最速合格


CIPP-E 認定は、EU における個人データを扱う個人、プライバシー専門家、データ保護責任者、弁護士、コンサルタント、IT プロフェッショナル向けの理想的な認定です。この認定は、個人が EU で運営する組織に対してデータ保護コンプライアンスに関するアドバイスやガイダンスを提供できる能力を示しています。さらに、CIPP-E 認定は、データ保護とプライバシーの分野でキャリアを進めたい個人にとって貴重な資産です。この認定は、個人のプライバシーへの取り組みを証明し、その分野での専門知識と能力を示すものです。


IAPP CIPP-E(Certified Information Privacy Professional / Europe)試験は、データ保護とプライバシーの分野で働く専門家向けに設計された、世界的に認知された認定プログラムです。欧州のデータ保護法、規制、およびベストプラクティスの理解を証明したい個人にとって、必須の認定資格です。

 

質問 # 43
SCENARIO
Please use the following to answer the next question:
TripBliss Inc. is a travel service company which has lost substantial revenue over the last few years. Their new manager, Oliver, suspects that this is partly due to the company's outdated website. After doing some research, he meets with a sales representative from the up-and-coming IT company Techiva, hoping that they can design a new, cutting-edge website for TripBliss Inc.'s foundering business.
During negotiations, a Techiva representative describes a plan for gathering more customer information through detailed Questionaires, which could be used to tailor their preferences to specific travel destinations. TripBliss Inc. can choose any number of data categories - age, income, ethnicity - that would help them best accomplish their goals. Oliver loves this idea, but would also like to have some way of gauging how successful this approach is, especially since the Questionaires will require customers to provide explicit consent to having their data collected. The Techiva representative suggests that they also run a program to analyze the new website's traffic, in order to get a better understanding of how customers are using it. He explains his plan to place a number of cookies on customer devices. The cookies will allow the company to collect IP addresses and other information, such as the sites from which the customers came, how much time they spend on the TripBliss Inc. website, and which pages on the site they visit. All of this information will be compiled in log files, which Techiva will analyze by means of a special program. TripBliss Inc. would receive aggregate statistics to help them evaluate the website's effectiveness. Oliver enthusiastically engages Techiva for these services.
Techiva assigns the analytics portion of the project to longtime account manager Leon Santos. As is standard practice, Leon is given administrator rights to TripBliss Inc.'s website, and can authorize access to the log files gathered from it. Unfortunately for TripBliss Inc., however, Leon is taking on this new project at a time when his dissatisfaction with Techiva is at a high point. In order to take revenge for what he feels has been unfair treatment at the hands of the company, Leon asks his friend Fred, a hobby hacker, for help. Together they come up with the following plan: Fred will hack into Techiva's system and copy their log files onto a USB stick. Despite his initial intention to send the USB to the press and to the data protection authority in order to denounce Techiva, Leon experiences a crisis of conscience and ends up reconsidering his plan. He decides instead to securely wipe all the data from the USB stick and inform his manager that the company's system of access control must be reconsidered.
If TripBliss Inc. decides not to report the incident to the supervisory authority, what would be their BEST defense?

  • A. The resulting obligation to notify data subjects would involve disproportionate effort.
  • B. The destruction of the stolen data makes any risk to the affected data subjects unlikely.
  • C. The sensitivity of the categories of data involved in the incident was not substantial enough.
  • D. The incident resulted from the actions of a third-party that were beyond their control.

正解:D


質問 # 44
The origin of privacy as a fundamental human right can be found in which document?

  • A. European Convention of Human Rights 1953.
  • B. Charier of Fundamental Rights of the European Union 2000.
  • C. OECD Guidelines on the Protection of Privacy 1980.
  • D. Universal Declaration of Human Rights 1948.

正解:D


質問 # 45
Under the GDPR, which of the following is true in regard to adequacy decisions involving cross-border transfers?

  • A. The European Commission can adopt an adequacy decision for individual companies.
  • B. To be considered as adequate, third countries must implement the EU General Data Protection Regulation into their national legislation.
  • C. EU member states are vested with the power to accept or reject a European Commission adequacy decision.
  • D. The European Commission can adopt, repeal or amend an existing adequacy decision.

正解:A

解説:
Reference https://www.futurelearn.com/courses/general-data-protection-regulation/0/steps/32449


質問 # 46
In which scenario is a Controller most likely required to undertake a Data Protection Impact Assessment?

  • A. When personal data is being transferred outside of the EEA.
  • B. When the controller is required to have a Data Protection Officer.
  • C. When the controller is collecting email addresses from individuals via an online registration form for marketing purposes.
  • D. When personal data is being collected and combined with other personal data to profile the creditworthiness of individuals.

正解:D

解説:
Reference https://www.tandfonline.com/doi/full/10.1080/13600834.2020.1790092#:~:text=Article%2035%20of
%20the%20General,and%20freedoms%20of%20natural%20persons%27.


質問 # 47
What type of data lies beyond the scope of the General Data Protection Regulation?

  • A. Pseudonymized
  • B. Encrypted
  • C. Anonymized
  • D. Masked

正解:C


質問 # 48
Which marketing-related activity is least likely to be covered by the provisions of Privacy and Electronic Communications Regulations (Directive 2002/58/EC)?

  • A. Advertisements passively displayed on a website.
  • B. An email from a retail outlet promoting a sale to one of their previous customer.
  • C. The use of cookies to collect data about an individual.
  • D. A text message to individuals from a company offering concert tickets for sale.

正解:A


質問 # 49
SCENARIO
Please use the following to answer the next question:
Liem, an online retailer known for its environmentally friendly shoes, has recently expanded its presence in Europe. Anxious to achieve market dominance, Liem teamed up with another eco friendly company, EcoMick, which sells accessories like belts and bags. Together the companies drew up a series of marketing campaigns designed to highlight the environmental and economic benefits of their products. After months of planning, Liem and EcoMick entered into a data sharing agreement to use the same marketing database, MarketIQ, to send the campaigns to their respective contacts.
Liem and EcoMick also entered into a data processing agreement with MarketIQ, the terms of which included processing personal data only upon Liem and EcoMick's instructions, and making available to them all information necessary to demonstrate compliance with GDPR obligations.
Liem and EcoMick then procured the services of a company called JaphSoft, a marketing optimization firm that uses machine learning to help companies run successful campaigns. Clients provide JaphSoft with the personal data of individuals they would like to be targeted in each campaign. To ensure protection of its clients' data, JaphSoft implements the technical and organizational measures it deems appropriate. JaphSoft works to continually improve its machine learning models by analyzing the data it receives from its clients to determine the most successful components of a successful campaign. JaphSoft then uses such models in providing services to its client-base. Since the models improve only over a period of time as more information is collected, JaphSoft does not have a deletion process for the data it receives from clients. However, to ensure compliance with data privacy rules, JaphSoft pseudonymizes the personal data by removing identifying information from the contact information. JaphSoft's engineers, however, maintain all contact information in the same database as the identifying information.
Under its agreement with Liem and EcoMick, JaphSoft received access to MarketIQ, which included contact information as well as prior purchase history for such contacts, to create campaigns that would result in the most views of the two companies' websites. A prior Liem customer, Ms. Iman, received a marketing campaign from JaphSoft regarding Liem's as well as EcoMick's latest products. While Ms. Iman recalls checking a box to receive information in the future regarding Liem's products, she has never shopped EcoMick, nor provided her personal data to that company.
Under the GDPR, Liem and EcoMick's contract with MarketIQ must include all of the following provisions EXCEPT?

  • A. Processing the personal data upon documented instructions regarding data transfers outside of the EEA.
  • B. Assistance to Liem and EcoMick in their compliance with data protection impact assessments.
  • C. Returning or deleting personal data after the end of the provision of the services.
  • D. Notification regarding third party requests for access to Liem and EcoMick's personal data.

正解:B


質問 # 50
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA.
Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
Ben's collection of additional data from customers created several potential issues for the company, which would most likely require what?

  • A. Hiring a data protection officer.
  • B. New corporate governance and code of conduct.
  • C. A data protection impact assessment.
  • D. A comprehensive data inventory.

正解:B


質問 # 51
Which institution has the power to adopt findings that confirm the adequacy of the data protection level in a non-EU country?

  • A. The European Commission
  • B. The European Parliament
  • C. The European Council
  • D. The Article 29 Working Party

正解:A

解説:
Reference https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/ adequacy-decisions_en


質問 # 52
In 2016's Guidance, the United Kingdom's Information Commissioner's Office (ICO) reaffirmed the importance of using a "layered notice" to provide data subjects with what?

  • A. A privacy notice containing brief information whilst offering access to further detail.
  • B. A privacy notice explaining the consequences for opting out of the use of cookies on a website.
  • C. An efficient means of providing written consent in member states where they are required to do so.
  • D. An explanation of the security measures used when personal data is transferred to a third party.

正解:D


質問 # 53
What term BEST describes the European model for data protection?

  • A. Comprehensive
  • B. Sectoral
  • C. Market-based
  • D. Self-regulatory

正解:A

解説:
Reference https://ec.europa.eu/info/sites/info/files/communication-european-strategy-data-19feb2020_en.pdf


質問 # 54
In which situation would a data controller most likely be able to justify the processing of the data of a child without parental consent?

  • A. When a legitimate business interest makes obtaining consent impractical.
  • B. When providing preventive or counselling services to the child.
  • C. When providing the child with materials purely for educational use.
  • D. When the data is to be processed for market research.

正解:B


質問 # 55
What should a controller do after a data subject opts out of a direct marketing activity?

  • A. Refrain from processing personal data relating to the data subject for the relevant type of communication.
  • B. Take reasonable steps to inform third-party recipients that the data subject's personal data should be deleted and no longer processed.
  • C. Without exception, securely delete all personal data relating to the data subject.
  • D. Without undue delay, provide information to the data subject on the action that will be taken.

正解:A


質問 # 56
An organization conducts body temperature checks as a part of COVID-19 monitoring. Body temperature is measured manually and is not followed by registration, documentation or other processing of an individual's personal data.
Which of the following best explain why this practice would NOT be subject to the GDPR?

  • A. The practice is for the purpose of alleviating extreme risks to public health.
  • B. Body temperature is not considered personal data.
  • C. The practice does not involve completion by automated means.
  • D. Body temperature is considered pseudonymous data.

正解:C


質問 # 57
What is the most frequently used mechanism for legitimizing cross-border data transfer?

  • A. Standard Contractual Clauses.
  • B. Derogations.
  • C. Approved Code of Conduct.
  • D. Binding Corporate Rules.

正解:A

解説:
Reference https://www.dataguidance.com/opinion/international-eu-us-cross-border-data-transfers


質問 # 58
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?

  • A. The group of undertakings must obtain approval from a supervisory authority.
  • B. The data protection officer must be located in the country where the data controller has its main establishment.
  • C. The group of undertakings must be comprised of organizations of similar sizes and functions.
  • D. The data protection officer must be easily accessible from each establishment where the undertakings are located.

正解:D

解説:
Explanation/Reference: https://www.privacy-regulation.eu/en/article-37-designation-of-the-data-protection-officer- GDPR.htm


質問 # 59
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?

  • A. The data subject already has information regarding how his data will be used
  • B. The processing of the data subject's data is protected by appropriate technical measures
  • C. Third-party data would be disclosed by providing such information to the data subject
  • D. The provision of such information to the data subject would be too problematic

正解:A


質問 # 60
The European Parliament jointly exercises legislative and budgetary functions with which of the following?

  • A. The Article 29 Working Party.
  • B. The European Commission.
  • C. The European Data Protection Board.
  • D. The Council of the European Union.

正解:D


質問 # 61
......

リアルIAPP CIPP-E試験問題 [更新されたのは2023年]:https://www.passtest.jp/IAPP/CIPP-E-shiken.html

準備CIPP-E問題解答でCIPP-E試験問題集:https://drive.google.com/open?id=1uXJbbmW-0-QtRqErJLTZjPjFaidK-dWv