
[Oct-2021] IAPP CIPP-US Dumps – Reduce Your Chance of Failure in CIPP-US Exam
To help you achieve your ultimate goal, we suggest the actual IAPP CIPP-US dumps for your Certified Information Privacy Professional/United States (CIPP/US) exam preparation to use as your guideline.
NEW QUESTION 66
SCENARIO
Please use the following to answer the next QUESTION
When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated dat a. In her research, Roberta had discovered that even low- level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.
Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.
When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.
Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.
What could the company have done differently prior to the breach to reduce their risk?
- A. Looked for any persistent threats to security that could compromise the company's network.
- B. Implemented a comprehensive policy for accessing customer information.
- C. Communicated requests for changes to users' preferences across the organization and with third parties.
- D. Honored the promise of its privacy policy to acquire information by using an opt-in method.
Answer: A
NEW QUESTION 67
Which authority supervises and enforces laws regarding advertising to children via the Internet?
- A. The Office for Civil Rights
- B. The Department of Homeland Security
- C. The Federal Trade Commission
- D. The Federal Communications Commission
Answer: C
NEW QUESTION 68
In 2012, the White House and the FTC both issued reports advocating a new approach to privacy enforcement that can best be described as what?
- A. Comprehensive.
- B. Self-regulatory.
- C. Harm-based.
- D. Notice and choice.
Answer: B
NEW QUESTION 69
SCENARIO
Please use the following to answer the next QUESTION:
Larry has become increasingly dissatisfied with his telemarketing position at SunriseLynx, and particularly with his supervisor, Evan. Just last week, he overheard Evan mocking the state's Do Not Call list, as well as the people on it. "If they were really serious about not being bothered," Evan said, "They'd be on the national DNC list. That's the only one we're required to follow. At SunriseLynx, we call until they ask us not to." Bizarrely, Evan requires telemarketers to keep records of recipients who ask them to call "another time." This, to Larry, is a clear indication that they don't want to be called at all. Evan doesn't see it that way.
Larry believes that Evan's arrogance also affects the way he treats employees. The U.S. Constitution protects American workers, and Larry believes that the rights of those at SunriseLynx are violated regularly. At first Evan seemed friendly, even connecting with employees on social medi a. However, following Evan's political posts, it became clear to Larry that employees with similar affiliations were the only ones offered promotions.
Further, Larry occasionally has packages containing personal-use items mailed to work. Several times, these have come to him already opened, even though this name was clearly marked. Larry thinks the opening of personal mail is common at SunriseLynx, and that Fourth Amendment rights are being trampled under Evan's leadership.
Larry has also been dismayed to overhear discussions about his coworker, Sadie. Telemarketing calls are regularly recorded for quality assurance, and although Sadie is always professional during business, her personal conversations sometimes contain sexual comments. This too is something Larry has heard Evan laughing about. When he mentioned this to a coworker, his concern was met with a shrug. It was the coworker's belief that employees agreed to be monitored when they signed on. Although personal devices are left alone, phone calls, emails and browsing histories are all subject to surveillance. In fact, Larry knows of one case in which an employee was fired after an undercover investigation by an outside firm turned up evidence of misconduct. Although the employee may have stolen from the company, Evan could have simply contacted the authorities when he first suspected something amiss.
Larry wants to take action, but is uncertain how to proceed.
Which act would authorize Evan's undercover investigation?
- A. The Stored Communications Act (SCA)
- B. The Fair and Accurate Credit Transactions Act (FACTA)
- C. The National Labor Relations Act (NLRA)
- D. The Whistleblower Protection Act
Answer: C
NEW QUESTION 70
SCENARIO
Please use the following to answer the next QUESTION
Noah is trying to get a new job involving the management of money. He has a poor personal credit rating, but he has made better financial decisions in the past two years.
One potential employer, Arnie's Emporium, recently called to tell Noah he did not get a position. As part of the application process, Noah signed a consent form allowing the employer to request his credit report from a consumer reporting agency (CRA). Noah thinks that the report hurt his chances, but believes that he may not ever know whether it was his credit that cost him the job. However, Noah is somewhat relieved that he was not offered this particular position. He noticed that the store where he interviewed was extremely disorganized. He imagines that his credit report could still be sitting in the office, unsecured.
Two days ago, Noah got another interview for a position at Sam's Market. The interviewer told Noah that his credit report would be a factor in the hiring decision. Noah was surprised because he had not seen anything on paper about this when he applied.
Regardless, the effect of Noah's credit on his employability troubles him, especially since he has tried so hard to improve it. Noah made his worst financial decisions fifteen years ago, and they led to bankruptcy. These were decisions he made as a young man, and most of his debt at the time consisted of student loans, credit card debt, and a few unpaid bills - all of which Noah is still working to pay off. He often laments that decisions he made fifteen years ago are still affecting him today.
In addition, Noah feels that an experience investing with a large bank may have contributed to his financial troubles. In 2007, in an effort to earn money to help pay off his debt, Noah talked to a customer service representative at a large investment company who urged him to purchase stocks. Without understanding the risks, Noah agreed. Unfortunately, Noah lost a great deal of money.
After losing the money, Noah was a customer of another financial institution that suffered a large security breach. Noah was one of millions of customers whose personal information was compromised. He wonders if he may have been a victim of identity theft and whether this may have negatively affected his credit.
Noah hopes that he will soon be able to put these challenges behind him, build excellent credit, and find the perfect job.
Consumers today are most likely protected from situations like the one Noah had buying stock because of which federal action or legislation?
- A. Federal Trade Commission investigations into "unfair and deceptive" acts or practices.
- B. The rules under the Fair Debt Collection Practices Act.
- C. Investigations of "abusive" acts and practices under the Dodd-Frank Wall Street Reform and Consumer Protection Act.
- D. The creation of the Consumer Financial Protection Bureau.
Answer: C
NEW QUESTION 71
What is the most important action an organization can take to comply with the FTC position on retroactive changes to a privacy policy?
- A. Obtaining affirmative consent from its customers.
- B. Reassuring customers of the security of their information.
- C. Publicizing the policy changes through social media.
- D. Describing the policy changes on its website.
Answer: A
NEW QUESTION 72
SCENARIO
Please use the following to answer the next QUESTION:
Declan has just started a job as a nursing assistant in a radiology department at Woodland Hospital. He has also started a program to become a registered nurse.
Before taking this career path, Declan was vaguely familiar with the Health Insurance Portability and Accountability Act (HIPAA). He now knows that he must help ensure the security of his patients' Protected Health Information (PHI). Therefore, he is thinking carefully about privacy issues.
On the morning of his first day, Declan noticed that the newly hired receptionist handed each patient a HIPAA privacy notice. He wondered if it was necessary to give these privacy notices to returning patients, and if the radiology department could reduce paper waste through a system of one-time distribution.
He was also curious about the hospital's use of a billing company. He Questioned whether the hospital was doing all it could to protect the privacy of its patients if the billing company had details about patients' care.
On his first day Declan became familiar with all areas of the hospital's large radiology department. As he was organizing equipment left in the halfway, he overheard a conversation between two hospital administrators. He was surprised to hear that a portable hard drive containing non-encrypted patient information was missing. The administrators expressed relief that the hospital would be able to avoid liability. Declan was surprised, and wondered whether the hospital had plans to properly report what had happened.
Despite Declan's concern about this issue, he was amazed by the hospital's effort to integrate Electronic Health Records (EHRs) into the everyday care of patients. He thought about the potential for streamlining care even more if they were accessible to all medical facilities nationwide.
Declan had many positive interactions with patients. At the end of his first day, he spoke to one patient, John, whose father had just been diagnosed with a degenerative muscular disease. John was about to get blood work done, and he feared that the blood work could reveal a genetic predisposition to the disease that could affect his ability to obtain insurance coverage. Declan told John that he did not think that was possible, but the patient was wheeled away before he could explain why. John plans to ask a colleague about this.
In one month, Declan has a paper due for one his classes on a health topic of his choice. By then, he will have had many interactions with patients he can use as examples. He will be pleased to give credit to John by name for inspiring him to think more carefully about genetic testing.
Although Declan's day ended with many Questions, he was pleased about his new position.
Based on the scenario, what is the most likely way Declan's supervisor would answer his question about the hospital's use of a billing company?
- A. By suggesting that Declan look at the hospital's publicly posted privacy policy
- B. By describing how the billing system is integrated into the hospital's electronic health records (EHR) system
- C. By pointing out that contracts are in place to help ensure the observance of minimum security standards
- D. By assuring Declan that third parties are prevented from seeing Private Health Information (PHI)
Answer: C
NEW QUESTION 73
In a case of civil litigation, what might a defendant who is being sued for distributing an employee's private information face?
- A. Criminal fines.
- B. An injunction.
- C. Probation.
- D. A jail sentence.
Answer: B
NEW QUESTION 74
According to FERPA, when can a school disclose records without a student's consent?
- A. If the disclosure is to provide transcripts to a school where a student intends to enroll
- B. If the disclosure is to practitioners who are involved in a student's health care
- C. If the disclosure would not reveal a student's student identification number
- D. If the disclosure is not to be conducted through email to the third party
Answer: A
Explanation:
Explanation/Reference: https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html
NEW QUESTION 75
Which entity within the Department of Health and Human Services (HHS) is the primary enforcer of the Health Insurance Portability and Accountability Act (HIPAA) "Privacy Rule"?
- A. Office of Inspector General.
- B. Office for Civil Rights.
- C. Office of Social Services.
- D. Office of Public Health and Safety.
Answer: B
NEW QUESTION 76
When developing a company privacy program, which of the following relationships will most help a privacy professional develop useful guidance for the organization?
- A. Relationships with company leaders responsible for approving, implementing, and periodically reviewing the corporate privacy program.
- B. Relationships with clients, vendors, and customers whose data will be primarily collected and used throughout the organizational program.
- C. Relationships with individuals across company departments and at different levels in the organization's hierarchy.
- D. Relationships with individuals within the privacy professional community who are able to share expertise and leading practices for different industries.
Answer: A
NEW QUESTION 77
Which entities must comply with the Telemarketing Sales Rule?
- A. For-profit and not-for-profit organizations when selling additional services to establish customers
- B. For-profit organizations calling businesses when a binding contract exists between them
- C. Nonprofit organizations calling on their own behalf
- D. For-profit organizations and for-profit telefunders regarding charitable solicitations
Answer: A
Explanation:
Explanation/Reference: https://www.ftc.gov/tips-advice/business-center/guidance/complying-telemarketing-sales-rule
NEW QUESTION 78
The Video Privacy Protection Act of 1988 restricted which of the following?
- A. When downloading of copyrighted audio visual materials is allowed
- B. When a user's viewing of online video content can be monitored
- C. Which purchase records of audio visual materials may be disclosed
- D. Who advertisements for videos and video games may target
Answer: C
Explanation:
Explanation/Reference: https://searchcompliance.techtarget.com/definition/Video-Privacy-Protection-Act-of-1988
NEW QUESTION 79
A covered entity suffers a ransomware attack that affects the personal health information (PHI) of more than
500 individuals. According to Federal law under HIPAA, which of the following would the covered entity NOT have to report the breach to?
- A. The local media
- B. Medical providers
- C. Department of Health and Human Services
- D. The affected individuals
Answer: B
Explanation:
Explanation/Reference: https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdf (page 6)
NEW QUESTION 80
Which of the following is most likely to provide privacy protection to private-sector employees in the United States?
- A. State law, contract law, and tort law
- B. The Federal Trade Commission Act (FTC Act)
- C. The U.S. Department of Health and Human Services (HHS)
- D. Amendments one, four, and five of the U.S. Constitution
Answer: A
Explanation:
Explanation/Reference: https://corporate.findlaw.com/law-library/right-to-privacy-in-the-workplace-in-the-information- age.html
NEW QUESTION 81
What is the main purpose of the Global Privacy Enforcement Network?
- A. To promote universal cooperation among privacy authorities
- B. To arbitrate disputes between countries over jurisdiction for privacy laws
- C. To protect the interests of privacy consumer groups worldwide
- D. To investigate allegations of privacy violations internationally
Answer: A
Explanation:
Explanation/Reference: https://en.wikipedia.org/wiki/Global_Privacy_Enforcement_Network
NEW QUESTION 82
Which of the following is NOT one of three broad categories of products offered by data brokers, as identified by the U.S. Federal Trade Commission (FTC)?
- A. Risk mitigation (such as information that may reduce the risk of fraud).
- B. Marketing (such as appending data to customer information that a marketing company already has).
- C. Research (such as information for understanding consumer trends).
- D. Location of individuals (such as identifying an individual from partial information).
Answer: D
NEW QUESTION 83
An organization self-certified under Privacy Shield must, upon request by an individual, do what?
- A. Identify all personal information disclosed during a criminal investigation.
- B. Provide the identities of third and fourth parties that may potentially receive personal information.
- C. Suspend the use of all personal information collected by the organization to fulfill its original purpose.
- D. Provide the identities of third parties with whom the organization shares personal information.
Answer: D
Explanation:
Explanation/Reference: https://www.lakesidesoftware.com/sites/default/files/Privacy_Shield_Privacy_Statement.pdf
NEW QUESTION 84
......
100% Free CIPP-US Demo-Trial [Pdf], get it now: https://drive.google.com/open?id=1Zwdn59rliv46TMwZZhjvT8Oov9cMnb0l
Accurate & Verified Answers As Seen in the Real Exam here: https://www.dumpexam.com/CIPP-US-valid-torrent.html
