PDF無料ダウンロードにはCIPP-US有効な練習テスト問題 [Q54-Q70]

Share

PDF無料ダウンロードにはCIPP-US有効な練習テスト問題

CIPP-USテストエンジンお試しセット、CIPP-US問題集PDF


IAPP CIPP-US(Certified Information Privacy Professional/United States)認定試験は、個人データを扱うプロフェッショナル向けの、世界的に認識された認定プログラムです。この試験は、データプライバシー、セキュリティ、コンプライアンスに責任を持つプロフェッショナルの知識とスキルをテストするように設計されています。CIPP-US認定は、世界最大かつ最も包括的なグローバル情報プライバシーコミュニティである国際プライバシープロフェッショナル協会(IAPP)によって授与されます。


CIPP-US試験は、プライバシー業界で高く評価され、世界中の雇用主や組織に認められています。また、プライバシー管理とコンプライアンスのキャリアアップを目指す個人にとっても、貴重な資格となります。この試験は、挑戦的に設計されていますが、十分に準備すれば、初回の受験で合格することができます。

 

質問 # 54
A student has left high school and is attending a public postsecondary institution. Under what condition may a school legally disclose educational records to the parents of the student without consent?

  • A. If the student has applied to transfer to another institution
  • B. If the student has not yet turned 18 years of age
  • C. If the student is in danger of academic suspension
  • D. If the student is still a dependent for tax purposes

正解:D

解説:
The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of students' educational records. FERPA generally requires schools to obtain written consent from students before disclosing their records to third parties, such as parents. However, FERPA allows some exceptions to this rule, such as when the disclosure is for health or safety emergencies, or when the student is still a dependent for tax purposes. According to FERPA, a school may disclose educational records to the parents of a student who is claimed as a dependent on the parents' most recent federal income tax return, without the student's consent. This exception applies regardless of the student's age or enrollment status at a postsecondary institution. References:
* IAPP CIPP/US Body of Knowledge, Section III, C, 2
* [IAPP CIPP/US Study Guide, Chapter 3, Section 3.5]
* [FERPA, 34 CFR § 99.31(a)(8)]


質問 # 55
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal dat a. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Under the GDPR, the complainant's request regarding her personal information is known as what?

  • A. Right of Access
  • B. Right of Removal
  • C. Right of Rectification
  • D. Right to Be Forgotten

正解:B


質問 # 56
Which entity within the Department of Health and Human Services (HHS) is the primary enforcer of the Health Insurance Portability and Accountability Act (HIPAA) "Privacy Rule"?

  • A. Office of Inspector General.
  • B. Office of Public Health and Safety.
  • C. Office for Civil Rights.
  • D. Office of Social Services.

正解:C


質問 # 57
Which authority supervises and enforces laws regarding advertising to children via the Internet?

  • A. The Federal Trade Commission
  • B. The Department of Homeland Security
  • C. The Office for Civil Rights
  • D. The Federal Communications Commission

正解:A

解説:
The Federal Trade Commission (FTC) is the primary federal agency that regulates advertising and marketing practices in the United States, including those targeting children via the Internet. The FTC enforces the Children's Online Privacy Protection Act (COPPA), which requires operators of websites and online services directed to children under 13 to obtain verifiable parental consent before collecting, using, or disclosing personal information from children. The FTC also enforces the FTC Act, which prohibits unfair or deceptive acts or practices in commerce, such as making false or misleading claims in advertising. The FTC has issued guidelines and reports on various aspects of digital advertising to children, such as sponsored content, influencers, data collection, persuasive design, and behavioral marketing. The FTC also hosts workshops and events to examine the impact of digital advertising on children and their ability to distinguish ads from entertainment. References:
* FTC website
* Digital Advertising to Children
* IAPP CIPP/US Study Guide, Chapter 5: Marketing and Privacy, pp. 169-170


質問 # 58
Who has rulemaking authority for the Fair Credit Reporting Act (FCRA) and the Fair and Accurate Credit Transactions Act (FACTA)?

  • A. State Attorneys General
  • B. The Department of Commerce
  • C. The Consumer Financial Protection Bureau
  • D. The Federal Trade Commission

正解:C

解説:
The Consumer Financial Protection Bureau (CFPB) has rulemaking authority for the Fair Credit Reporting Act (FCRA) and the Fair and Accurate Credit Transactions Act (FACTA), as well as other consumer financial laws. The Dodd-Frank Act, enacted in 2010, transferred most of the rulemaking responsibilities added to the FCRA by the FACTA and the Credit CARD Act from the Federal Trade Commission (FTC) to the CFPB. However, the FTC retains its enforcement authority for the FCRA and the FACTA, along with other federal and state agencies1. The CFPB also shares rulemaking authority for some provisions of the FACTA with the FTC, such as the identity theft red flags and address discrepancy rules2. The Department of Commerce and the State Attorneys General do not have rulemaking authority for the FCRA or the FACTA. References: 1: FTC3, Fair Credit Reporting Act; 2: CFPB4, Fair Credit Reporting Act; 3: FTC; 4: CFPB.


質問 # 59
SCENARIO
Please use the following to answer the next QUESTION:
A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the retailer's data handling practices.
The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal dat a. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration.
As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer.
Under the General Data Protection Regulation (GDPR), how would the U.S.-based startup company most likely be classified?

  • A. As a data manager
  • B. As a data controller
  • C. As a data supervisor
  • D. As a data processor

正解:C


質問 # 60
What practice do courts commonly require in order to protect certain personal information on documents, whether paper or electronic, that is involved in litigation?

  • A. Redaction
  • B. Deletion
  • C. Encryption
  • D. Hashing

正解:A

解説:
Redaction is the permanent removal of sensitive data-the digital equivalent of "blacking out" text in printed material. Redaction can be accomplished by simply deleting characters from a file or database record, or by replacing characters with asterisks or other placeholders. Redaction is often used to protect personal information, such as names, addresses, social security numbers, or financial data, on documents that are disclosed in litigation, such as pleadings, exhibits, or discovery responses. Redaction is required by courts to comply with privacy laws and rules, such as the Federal Rules of Civil Procedure (FRCP), which mandate that parties must redact certain types of personal information from documents filed with the court or produced to the other party. Redaction is also a best practice to minimize the risk of unauthorized access, identity theft, or reputational harm that may result from exposing personal information in litigation. References:
* When to redact, or not, disclosable documents in litigation - Stewarts
* The approach to redaction - High Court guidance - Lexology
* IAPP CIPP/US Certified Information Privacy Professional Study Guide, Chapter 3: Federal Privacy Laws and Regulations, Section 3.2: Federal Rules of Civil Procedure (FRCP).


質問 # 61
In March 2012, the FTC released a privacy report that outlined three core principles for companies handling consumer data. Which was NOT one of these principles?

  • A. Providing greater transparency.
  • B. Practicing Privacy by Design.
  • C. Simplifying consumer choice.
  • D. Enhancing security measures.

正解:D

解説:
The FTC's privacy report, titled "Protecting Consumer Privacy in an Era of Rapid Change", proposed a framework for companies that collect and use consumer data. The framework consisted of three core principles: privacy by design, simplified consumer choice, and greater transparency. Privacy by design means that companies should incorporate privacy protections into their everyday business practices, such as data security, reasonable collection limits, sound retention practices, and data accuracy. Simplified consumer choice means that companies should provide consumers with clear and easy-to-understand choices about the collection and use of their data, and respect their preferences. Greater transparency means that companies should increase the visibility and accessibility of their data practices, such as providing clear and concise privacy notices, educating consumers about the commercial datapractices, and providing consumers with access to their data. Enhancing security measures is not one of the core principles of the FTC's privacy framework, although it is a component of the privacy by design principle. References:
* IAPP CIPP/US Body of Knowledge, Section I.A.1.a
* IAPP CIPP/US Textbook, Chapter 1, pp. 13-15
* FTC Privacy Report, Executive Summary, pp. i-vii


質問 # 62
Who has rulemaking authority for the Fair Credit Reporting Act (FCRA) and the Fair and Accurate Credit Transactions Act (FACTA)?

  • A. State Attorneys General
  • B. The Department of Commerce
  • C. The Consumer Financial Protection Bureau
  • D. The Federal Trade Commission

正解:C


質問 # 63
Which statute is considered part of U.S. federal privacy law?

  • A. SB 1386.
  • B. The Personal Information Protection and Electronic Documents Act.
  • C. The e-Privacy Directive.
  • D. The Fair Credit Reporting Act.

正解:D


質問 # 64
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?

  • A. An international court ruling on personal information held in the commercial sector.
  • B. A code of responsibilities for medical establishments to uphold privacy laws.
  • C. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
  • D. A bill of rights for individuals seeking access to their personal information.

正解:D


質問 # 65
Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusing on placing privacy professionals in roles at major companies. Job candidates create online profiles outlining their experience and credentials, and can pay $19.99/month via credit card to have their profiles promoted to potential employers. Privacy Is Hiring Inc. keeps all customer data at rest encrypted on its servers.
Under what circumstances would Privacy Is Hiring Inc., need to notify affected individuals in the event of a data breach?

  • A. If Privacy Is Hiring Inc., reasonably believes that job candidates will be harmed by the data breach.
  • B. If law enforcement has completed its investigation and has authorized Privacy Is Hiring Inc. to provide the notification to clients and applicable regulators.
  • C. If the personal information stolen included the individuals' names and credit card pin numbers.
  • D. If the job candidates' credit card information and the encryption keys were among the information taken.

正解:D

解説:
Under the California Consumer Privacy Act (CCPA), a business that collects personal information of California residents must notify them of a data breach if their personal information is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of the duty to implement and maintain reasonable security procedures and practices. However, the CCPA excludes encrypted or redacted personal information from the definition of personal information, unless the encryption key or security credential is also compromised. Therefore, Privacy Is Hiring Inc. would need to notify the affected individuals only if the encryption keys were also taken along with the credit card information, as this would render the encryption ineffective and expose the personal information to unauthorized access. The other options are not relevant to the CCPA notification requirement, although they may be relevant to other laws or best practices. References: CCPA (Section
1798.150), IAPP CIPP/US Study Guide (p. 63-64)


質問 # 66
Which entity within the Department of Health and Human Services (HHS) is the primary enforcer of the Health Insurance Portability and Accountability Act (HIPAA) "Privacy Rule"?

  • A. Office of Inspector General.
  • B. Office of Public Health and Safety.
  • C. Office for Civil Rights.
  • D. Office of Social Services.

正解:C

解説:
The Office for Civil Rights (OCR) within the HHS is the primary enforcer of the HIPAA Privacy Rule, which establishes national standards for the protection of individually identifiable health information by covered entities and business associates. The OCR investigates complaints, conducts compliance reviews, and provides technical assistance and guidance to ensure compliance with the Privacy Rule. The OCR can also impose civil monetary penalties for violations of the Privacy Rule, ranging from $100 to $50,000 per violation, up to a maximum of $1.5 million per year for the same violation. References: HIPAA Enforcement, IAPP CIPP/US Study Guide, Chapter 3, Section 3.1.1


質問 # 67
SCENARIO -
Please use the following to answer the next question:
Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada.
Miraculous normally treats patients in person, but has recently decided to start offering telehealth appointments, where patients can have virtual appointments with on-site doctors via a phone app.
For this new initiative, Miraculous is considering a product built by MedApps, a company that makes quality telehealth apps for healthcare practices and licenses them to be usedwith the practices' branding. MedApps provides technical support for the app, which it hosts in the cloud. MedApps also offers an optional benchmarking service for providers who wish to compare their practice to others using the service.
Riya is the Privacy Officer at Miraculous, responsible for the practice's compliance with HIPAA and other applicable laws, and she works with the Miraculous procurement team to get vendor agreements in place. She occasionally assists procurement in vetting vendors and inquiring about their own compliance practices, as well as negotiating the terms of vendor agreements. Riya is currently reviewing the suitability of the MedApps app from a privacy perspective.
Riya has also been asked by the Miraculous Healthcare business operations team to review the MedApps' optional benchmarking service. Of particular concern is the requirement that Miraculous Healthcare upload information about the appointments to a portal hosted by MedApps.
What HIPAA compliance issue would Miraculous have to consider before using the telehealth app?

  • A. HIPAA would require Miraculous to obtain patient consent before in-person appointment data can be shared with third parties.
  • B. HIPAA does not permit in-person appointment data to be hosted in the cloud.
  • C. HIPAA does not permit healthcare providers to use cloud hosting services.
  • D. HIPAA would require Miraculous and MedApps to enter into a Business Associate Agreement.

正解:D

解説:
According to HIPAA, a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) on behalf of, or provides services to, a covered entity. A business associate agreement (BAA) is a written contract between a covered entity and a business associate that establishes the permitted and required uses and disclosures of PHI by the business associate, as well as the safeguards that the business associate must implement to protect the PHI. In this scenario, MedApps is a business associate of Miraculous, since it provides a telehealth app that involves the use or disclosure of PHI on behalf of Miraculous. Therefore, HIPAA would require Miraculous and MedApps to enter into a BAA before using the telehealth app. The other options are incorrect because HIPAA does not prohibit the use of cloud hosting services or the hosting of in-person appointment data in the cloud, as long as the appropriate safeguards and agreements are in place. HIPAA also does not require patient consent for the sharing of PHI with third parties for treatment, payment, or health care operations purposes, which would include the use of the telehealth app. References:
* HIPAA and Telehealth - Office for Civil Rights
* HIPAA Rules for telehealth technology - Telehealth.HHS.gov
* Notification of Enforcement Discretion for Telehealth - Office for Civil Rights
* Guidance: How the HIPAA Rules Permit Covered Health Care Providers and Health Plans to Provide Audio-Only Telehealth - Office for Civil Rights
* HIPAA Compliant App - Telehealth.org
* IAPP CIPP/US Certified Information Privacy Professional Study Guide - Chapter 3: HIPAA and HITECH, pages 75-76, 81-82, 86-87.


質問 # 68
SCENARIO
Please use the following to answer the next QUESTION
Noah is trying to get a new job involving the management of money. He has a poor personal credit rating, but he has made better financial decisions in the past two years.
One potential employer, Arnie's Emporium, recently called to tell Noah he did not get a position. As part of the application process, Noah signed a consent form allowing the employer to request his credit report from a consumer reporting agency (CRA). Noah thinks that the report hurt his chances, but believes that he may not ever know whether it was his credit that cost him the job. However, Noah is somewhat relieved that he was not offered this particular position. He noticed that the store where he interviewed was extremely disorganized. He imagines that his credit report could still be sitting in the office, unsecured.
Two days ago, Noah got another interview for a position at Sam's Market. The interviewer told Noah that his credit report would be a factor in the hiring decision. Noah was surprised because he had not seen anything on paper about this when he applied.
Regardless, the effect of Noah's credit on his employability troubles him, especially since he has tried so hard to improve it. Noah made his worst financial decisions fifteen years ago, and they led to bankruptcy. These were decisions he made as a young man, and most of his debt at the time consisted of student loans, credit card debt, and a few unpaid bills - all of which Noah is still working to pay off. He often laments that decisions he made fifteen years ago are still affecting him today.
In addition, Noah feels that an experience investing with a large bank may have contributed to his financial troubles. In 2007, in an effort to earn money to help pay off his debt, Noah talked to a customer service representative at a large investment company who urged him to purchase stocks. Without understanding the risks, Noah agreed. Unfortunately, Noah lost a great deal of money.
After losing the money, Noah was a customer of another financial institution that suffered a large security breach. Noah was one of millions of customers whose personal information was compromised. He wonders if he may have been a victim of identity theft and whether this may have negatively affected his credit.
Noah hopes that he will soon be able to put these challenges behind him, build excellent credit, and find the perfect job.
Based on the scenario, which legislation should ease Noah's worry about his credit report as a result of applying at Arnie's Emporium?

  • A. The Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA).
  • B. The Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA).
  • C. The Red Flags Rule under the Fair and Accurate Credit Transactions Act (FACTA).
  • D. The Privacy Rule under the Gramm-Leach-Bliley Act (GLBA).

正解:B

解説:
This Rule requires businesses and individuals that maintain or otherwise possess consumer reports and records for a business purpose to take appropriate measures to dispose of sensitive information derived from such consumer reports and records.


質問 # 69
What are banks required to do under the Gramm-Leach-Bliley Act (GLBA)?

  • A. Process requests for changes to user preferences within a designated time frame
  • B. Offer an Opt-Out before transferring PI to an unaffiliated third party for the latter's own use
  • C. Conduct annual consumer surveys regarding satisfaction with user preferences
  • D. Provide consumers with the opportunity to opt out of receiving telemarketing phone calls

正解:B


質問 # 70
......

あなたを合格させるCertified Information Privacy Professional CIPP-US試験問題集で2025年04月22日には194問あります:https://www.passtest.jp/IAPP/CIPP-US-shiken.html

最新のIAPP CIPP-USPDFと問題集で(2025)無料試験問題解答:https://drive.google.com/open?id=1g8uWDPNeBhy9dyy2wHdq_imzKNXczjKG