[2023] Pass your CIPP-C exam with this 100% Free CIPP-C Braindump [Q86-Q111]

Share

[2023] Pass your CIPP-C exam with this 100% Free CIPP-C Braindump

View All CIPP-C Actual Exam Questions, Answers and Explanations for Free

NEW QUESTION 86
SCENARIO
Please use the following to answer the next QUESTION:
Larry has become increasingly dissatisfied with his telemarketing position at SunriseLynx, and particularly with his supervisor, Evan. Just last week, he overheard Evan mocking the state's Do Not Call list, as well as the people on it. "If they were really serious about not being bothered," Evan said, "They'd be on the national DNC list. That's the only one we're required to follow. At SunriseLynx, we call until they ask us not to." Bizarrely, Evan requires telemarketers to keep records of recipients who ask them to call "another time." This, to Larry, is a clear indication that they don't want to be called at all. Evan doesn't see it that way.
Larry believes that Evan's arrogance also affects the way he treats employees. The U.S. Constitution protects American workers, and Larry believes that the rights of those at SunriseLynx are violated regularly. At first Evan seemed friendly, even connecting with employees on social medi a. However, following Evan's political posts, it became clear to Larry that employees with similar affiliations were the only ones offered promotions.
Further, Larry occasionally has packages containing personal-use items mailed to work. Several times, these have come to him already opened, even though this name was clearly marked. Larry thinks the opening of personal mail is common at SunriseLynx, and that Fourth Amendment rights are being trampled under Evan's leadership.
Larry has also been dismayed to overhear discussions about his coworker, Sadie. Telemarketing calls are regularly recorded for quality assurance, and although Sadie is always professional during business, her personal conversations sometimes contain sexual comments. This too is something Larry has heard Evan laughing about. When he mentioned this to a coworker, his concern was met with a shrug. It was the coworker's belief that employees agreed to be monitored when they signed on. Although personal devices are left alone, phone calls, emails and browsing histories are all subject to surveillance. In fact, Larry knows of one case in which an employee was fired after an undercover investigation by an outside firm turned up evidence of misconduct. Although the employee may have stolen from the company, Evan could have simply contacted the authorities when he first suspected something amiss.
Larry wants to take action, but is uncertain how to proceed.
Based on the way he uses social media, Evan is susceptible to a lawsuit based on?

  • A. Discrimination
  • B. Intrusion upon seclusion
  • C. Defamation
  • D. Publicity given to private life

Answer: A

 

NEW QUESTION 87
SCENARIO
Please use the following to answer the next QUESTION
Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in Californi a. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants' postings on social media, ask Question:s about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements.
Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she wants to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle's GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision.
Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results. Nor does Celeste share Felicia's concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale. Celeste believes that even if the business grows a customer database of a few thousand, it's unlikely that a state agency would hassle an honest business if an accidental security incident were to occur.
In any case, Celeste feels that all they need is common sense - like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she's right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina.
Based on Felicia's Bring Your Own Device (BYOD) plan, the business consultant will most likely advise Felicia and Celeste to do what?

  • A. Adopt the same kind of monitoring policies used for work-issued devices.
  • B. Reconsider the plan in favor of a policy of dedicated work devices.
  • C. Weigh any productivity benefits of the plan against the risk of privacy issues.
  • D. Make employment decisions based on those willing to consent to the plan in writing.

Answer: D

 

NEW QUESTION 88
What term BEST describes the European model for data protection?

  • A. Self-regulatory
  • B. Sectoral
  • C. Comprehensive
  • D. Market-based

Answer: B

 

NEW QUESTION 89
Assuming that the "without undue delay" provision is followed, what is the time limit for complying with a data access request?

  • A. Within 40 days of receipt, which may be extended by up to 40 additional days
  • B. Within 40 days of receipt
  • C. Within one month of receipt, which may be extended by an additional two months
  • D. Within one month of receipt, which may be extended by up to an additional month

Answer: D

 

NEW QUESTION 90
When collecting personal data in a European Union (EU) member state, what must a company do if it collects personal data from a source other than the data subjects themselves?

  • A. Upgrade security to match that of the source
  • B. Inform the subjects about the collection
  • C. Update the data within a reasonable timeframe
  • D. Provide a public notice regarding the data

Answer: B

 

NEW QUESTION 91
Under the Fair Credit Reporting Act (FCRA), what must a person who is denied employment based upon his credit history receive?

  • A. A prompt notification from the employer.
  • B. Information from several consumer reporting agencies (CRAs).
  • C. A list of rights from the Consumer Financial Protection Bureau (CFPB).
  • D. An opportunity to reapply with the employer.

Answer: A

 

NEW QUESTION 92
Which of the following entities would most likely be exempt from complying with the GDPR?

  • A. A Chinese company that has opened a satellite office in a European Union (EU) member state to service European customers.
  • B. A company that stores all customer data in Australia and is headquartered in a European Union (EU) member state.
  • C. A North American company servicing customers in South Africa that uses a cloud storage system made by a European company.
  • D. A South American company that regularly collects European customers' personal data.

Answer: A

 

NEW QUESTION 93
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?

  • A. If the company's status as a documentary provider allows it to claim legitimate interest.
  • B. If obtaining consent is deemed to involve disproportionate effort.
  • C. If obtaining consent is deemed voluntary by local legislation.
  • D. If the company limits the footage to data subjects solely of legal age.

Answer: C

 

NEW QUESTION 94
SCENARIO
Please use the following to answer the next QUESTION:
Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your network?" Matt asked hopefully.
"No," the boy said. "I'm filling out a survey."
Matt looked over his son's shoulder at his computer screen. "What kind of survey?" "It's asking Questions about my opinions."
"Let me see," Matt said, and began reading the list of Questions that his son had already answered. "It's asking your opinions about the government and citizenship. That's a little odd. You're only ten." Matt wondered how the web link to the survey had ended up in his son's email inbox. Thinking the message might have been sent to his son by mistake he opened it and read it. It had come from an entity called the Leadership Project, and the content and the graphics indicated that it was intended for children. As Matt read further he learned that kids who took the survey were automatically registered in a contest to win the first book in a series about famous leaders.
To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if he had been prompted to give information about himself in order to take the survey. His son told him he had been asked to give his name, address, telephone number, and date of birth, and to answer Questions about his favorite games and toys.
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from marketers advertising products for children in his son's inbox, and he decided it was time to report the incident to the proper authorities.
How does Matt come to the decision to report the marketer's activities?

  • A. The marketer seems to have distributed his son's information without Matt's permission
  • B. The marketer did not provide evidence that the prize books were appropriate for children
  • C. The marketer failed to identify himself and indicate the purpose of the messages
  • D. The marketer failed to make an adequate attempt to provide Matt with information

Answer: D

 

NEW QUESTION 95
SCENARIO
Please use the following to answer the next question:
You have just been hired by a toy manufacturer based in Hong Kong. The company sells a broad range of dolls, action figures and plush toys that can be found internationally in a wide variety of retail stores. Although the manufacturer has no offices outside Hong Kong and in fact does not employ any staff outside Hong Kong, it has entered into a number of local distribution contracts. The toys produced by the company can be found in all popular toy stores throughout Europe, the United States and Asia. A large portion of the company's revenue is due to international sales.
The company now wishes to launch a new range of connected toys, ones that can talk and interact with children. The CEO of the company is touting these toys as the next big thing, due to the increased possibilities offered: The figures can answer children's Questions: on various subjects, such as mathematical calculations or the weather. Each figure is equipped with a microphone and speaker and can connect to any smartphone or tablet via Bluetooth. Any mobile device within a 10-meter radius can connect to the toys via Bluetooth as well.
The figures can also be associated with other figures (from the same manufacturer) and interact with each other for an enhanced play experience.
When a child asks the toy a QUESTION, the request is sent to the cloud for analysis, and the answer is generated on cloud servers and sent back to the figure. The answer is given through the figure's integrated speakers, making it appear as though that the toy is actually responding to the child's QUESTION. The packaging of the toy does not provide technical details on how this works, nor does it mention that this feature requires an internet connection. The necessary data processing for this has been outsourced to a data center located in South Africa. However, your company has not yet revised its consumer-facing privacy policy to indicate this.
In parallel, the company is planning to introduce a new range of game systems through which consumers can play the characters they acquire in the course of playing the game. The system will come bundled with a portal that includes a Near-Field Communications (NFC) reader. This device will read an RFID tag in the action figure, making the figure come to life onscreen. Each character has its own stock features and abilities, but it is also possible to earn additional ones by accomplishing game goals. The only information stored in the tag relates to the figures' abilities. It is easy to switch characters during the game, and it is possible to bring the figure to locations outside of the home and have the character's abilities remain intact.
In light of the requirements of Article 32 of the GDPR (related to the Security of Processing), which practice should the company institute?

  • A. Insert contractual clauses into the contract between the toy manufacturer and the cloud service provider, since South Africa is outside the European Union.
  • B. Include three-factor authentication before each use by a child in order to ensure the best level of security possible.
  • C. Include dual-factor authentication before each use by a child in order to ensure a minimum amount of security.
  • D. Encrypt the data in transit over the wireless Bluetooth connection.

Answer: D

 

NEW QUESTION 96
SCENARIO
Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them.
You also recall a recent visit to the Records Storage Section, often termed "The Dungeon" in the basement of the old hospital next to the modern facility, where you noticed a multitude of paper records. Some of these were in crates marked by years, medical condition or alphabetically by patient name, while others were in undifferentiated bundles on shelves and on the floor. The back shelves of the section housed data tapes and old hard drives that were often unlabeled but appeared to be years old. On your way out of the dungeon, you noticed just ahead of you a small man in a lab coat who you did not recognize. He carried a batch of folders under his arm, apparently records he had removed from storage.
Which data lifecycle phase needs the most attention at this Ontario medical center?

  • A. Disclosure
  • B. Collection
  • C. Use
  • D. Retention

Answer: D

 

NEW QUESTION 97
Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?

  • A. A voluntary notification for personal data breaches applicable to all data controllers.
  • B. A mandatory notification for personal data breaches applicable to electronic communication providers.
  • C. A mandatory notification for personal data breaches applicable to all data controllers.
  • D. A voluntary notification for personal data breaches applicable to electronic communication providers.

Answer: B

 

NEW QUESTION 98
Which federal law or regulation preempts state law?

  • A. Controlling the Assault of Non-Solicited Pornography and Marketing Act
  • B. Telemarketing Sales Rule
  • C. Health Insurance Portability and Accountability Act
  • D. Electronic Communications Privacy Act of 1986

Answer: C

 

NEW QUESTION 99
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?

  • A. A bill of rights for individuals seeking access to their personal information.
  • B. A baseline of marketers' minimum responsibilities for providing opt-out mechanisms.
  • C. An international court ruling on personal information held in the commercial sector.
  • D. A code of responsibilities for medical establishments to uphold privacy laws.

Answer: A

 

NEW QUESTION 100
Under the GDPR, which of the following is true in regard to adequacy decisions involving cross-border transfers?

  • A. The European Commission can adopt an adequacy decision for individual companies.
  • B. The European Commission can adopt, repeal or amend an existing adequacy decision.
  • C. To be considered as adequate, third countries must implement the EU General Data Protection Regulation into their national legislation.
  • D. EU member states are vested with the power to accept or reject a European Commission adequacy decision.

Answer: A

 

NEW QUESTION 101
SCENARIO
Please use the following to answer the next QUESTION
Noah is trying to get a new job involving the management of money. He has a poor personal credit rating, but he has made better financial decisions in the past two years.
One potential employer, Arnie's Emporium, recently called to tell Noah he did not get a position. As part of the application process, Noah signed a consent form allowing the employer to request his credit report from a consumer reporting agency (CRA). Noah thinks that the report hurt his chances, but believes that he may not ever know whether it was his credit that cost him the job. However, Noah is somewhat relieved that he was not offered this particular position. He noticed that the store where he interviewed was extremely disorganized. He imagines that his credit report could still be sitting in the office, unsecured.
Two days ago, Noah got another interview for a position at Sam's Market. The interviewer told Noah that his credit report would be a factor in the hiring decision. Noah was surprised because he had not seen anything on paper about this when he applied.
Regardless, the effect of Noah's credit on his employability troubles him, especially since he has tried so hard to improve it. Noah made his worst financial decisions fifteen years ago, and they led to bankruptcy. These were decisions he made as a young man, and most of his debt at the time consisted of student loans, credit card debt, and a few unpaid bills - all of which Noah is still working to pay off. He often laments that decisions he made fifteen years ago are still affecting him today.
In addition, Noah feels that an experience investing with a large bank may have contributed to his financial troubles. In 2007, in an effort to earn money to help pay off his debt, Noah talked to a customer service representative at a large investment company who urged him to purchase stocks. Without understanding the risks, Noah agreed. Unfortunately, Noah lost a great deal of money.
After losing the money, Noah was a customer of another financial institution that suffered a large security breach. Noah was one of millions of customers whose personal information was compromised. He wonders if he may have been a victim of identity theft and whether this may have negatively affected his credit.
Noah hopes that he will soon be able to put these challenges behind him, build excellent credit, and find the perfect job.
Based on the scenario, which legislation should ease Noah's worry about his credit report as a result of applying at Arnie's Emporium?

  • A. The Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA).
  • B. The Red Flags Rule under the Fair and Accurate Credit Transactions Act (FACTA).
  • C. The Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA).
  • D. The Privacy Rule under the Gramm-Leach-Bliley Act (GLBA).

Answer: A

 

NEW QUESTION 102
What is true if an employee makes an access request to his employer for any personal data held about him?

  • A. The employer must supply any information held about an employee unless an exemption applies.
  • B. The employer can decline the request if the information is only held electronically.
  • C. The employer can automatically decline the request if it contains personal data about a third person.
  • D. The employer must supply all the information held about the employee.

Answer: A

 

NEW QUESTION 103
SCENARIO
Please use the following to answer the next QUESTION:
Edufox has hosted an annual convention of users of its famous e-learning software platform, and over time, it has become a grand event. It fills one of the large downtown conference hotels and overflows into the others, with several thousand attendees enjoying three days of presentations, panel discussions and networking. The convention is the centerpiece of the company's product rollout schedule and a great training opportunity for current users. The sales force also encourages prospective clients to attend to get a better sense of the ways in which the system can be customized to meet diverse needs and understand that when they buy into this system, they are joining a community that feels like family.
This year's conference is only three weeks away, and you have just heard news of a new initiative supporting it: a smartphone app for attendees. The app will support late registration, highlight the featured presentations and provide a mobile version of the conference program. It also links to a restaurant reservation system with the best cuisine in the areas featured. "It's going to be great," the developer, Deidre Hoffman, tells you, "if, that is, we actually get it working!" She laughs nervously but explains that because of the tight time frame she'd been given to build the app, she outsourced the job to a local firm. "It's just three young people," she says, "but they do great work." She describes some of the other apps they have built. When asked how they were selected for this job, Deidre shrugs. "They do good work, so I chose them." Deidre is a terrific employee with a strong track record. That's why she's been charged to deliver this rushed project. You're sure she has the best interests of the company at heart, and you don't doubt that she's under pressure to meet a deadline that cannot be pushed back. However, you have concerns about the app's handling of personal data and its security safeguards. Over lunch in the break room, you start to talk to her about it, but she quickly tries to reassure you, "I'm sure with your help we can fix any security issues if we have to, but I doubt there'll be any. These people build apps for a living, and they know what they're doing. You worry too much, but that's why you're so good at your job!" Since it is too late to restructure the contract with the vendor or prevent the app from being deployed, what is the best step for you to take next?

  • A. Implement a more comprehensive suite of information security controls than the one used by the vendor
  • B. Insist on an audit of the vendor's privacy procedures and safeguards
  • C. Develop security protocols for the vendor and mandate that they be deployed
  • D. Ask the vendor for verifiable information about their privacy protections so weaknesses can be identified

Answer: D

 

NEW QUESTION 104
What was the original purpose of the Federal Trade Commission Act?

  • A. To ensure privacy rights of U.S. citizens
  • B. To negotiate consent decrees with companies violating personal privacy
  • C. To enforce antitrust laws
  • D. To protect consumers

Answer: D

 

NEW QUESTION 105
In a case of civil litigation, what might a defendant who is being sued for distributing an employee's private information face?

  • A. An injunction.
  • B. Probation.
  • C. A jail sentence.
  • D. Criminal fines.

Answer: A

 

NEW QUESTION 106
Which of the following best describes how federal anti-discrimination laws protect the privacy of private-sector employees in the United States?

  • A. They limit the amount of time a potential employee can be interviewed.
  • B. They promote a workforce of employees with diverse skills and interests.
  • C. They limit the types of information that employers can collect about employees.
  • D. They prescribe working environments that are safe and comfortable.

Answer: D

 

NEW QUESTION 107
What type of data lies beyond the scope of the General Data Protection Regulation?

  • A. Anonymized
  • B. Encrypted
  • C. Pseudonymized
  • D. Masked

Answer: A

 

NEW QUESTION 108
Which of the following is an example of federal preemption?

  • A. The California Consumer Privacy Act (CCPA) regulating businesses that have no physical brick-and-mortal presence in California, but which do business there.
  • B. The Payment Card Industry's (PCI) ability to self-regulate and enforce data security standards for payment card data.
  • C. The U.S. Federal Trade Commission's (FTC) ability to enforce against unfair and deceptive trade practices across sectors and industries.
  • D. The U.S. Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act prohibiting states from passing laws that impose greater obligations on senders of email marketing.

Answer: C

 

NEW QUESTION 109
Which entities must comply with the Telemarketing Sales Rule?

  • A. For-profit organizations and for-profit telefunders regarding charitable solicitations
  • B. For-profit organizations calling businesses when a binding contract exists between them
  • C. For-profit and not-for-profit organizations when selling additional services to establish customers
  • D. Nonprofit organizations calling on their own behalf

Answer: C

 

NEW QUESTION 110
A company is located in a country NOT considered by the European Union (EU) to have an adequate level of data protection. Which of the following is an obligation of the company if it imports personal data from another organization in the European Economic Area (EEA) under standard contractual clauses?

  • A. Supply any information requested by a data protection authority (DPA) within 30 days.
  • B. Submit the contract to its own government authority.
  • C. Ensure that local laws do not impede the company from meeting its contractual obligations.
  • D. Ensure that notice is given to and consent is obtained from data subjects.

Answer: B

 

NEW QUESTION 111
......


What will happen if I pass the IAPP CIPP-C Certification Exam?

If you pass the IAPP CIPP-C exam, then you can begin using IAPP's certified designation as a way of identifying yourself as someone who possesses the skills and knowledge associated with information protection and privacy. The CIPP-C certification will be added to your resume and can help you to land a job or earn a promotion. Introduced to all your colleagues and clients, it can help you to build trust and credibility. Published as an industry leader, this certificate is a great way to provide a competitive advantage in the job market.

Manufacturers of products and services will use this designation to market their products. You can be proud that you have earned this certification with the help of IAPP CIPP-C exam dumps. Preventing identity theft is an important consideration for everyone these days. This permits you to maintain the personal information you provide to the businesses you do business with. According to rules, attempts to steal such information can result in financial and other problems for you. Reasonable security allows you to maintain a level of privacy. If you earn IAPP CIPP-C certification, then your competitors cannot benchmark your level of privacy.


IAPP CIPP-C Exam Cover Topics

IAPP has worked out a list of the top ten topics in the IAPP CIPP-C exam. They are:

  1. Law and Policy: 40%
  2. Data Protection: 40%
  3. Data Quality: 10%
  4. Identity and Access Management: 10%
  5. Data Breaches: 5%
  6. Security Operations: 5%
  7. IT and Data Privacy Issues: 5 %
  8. Privacy Management: 10 %
  9. Technology Risk: 10 %
  10. Principles of Privacy by Design: 5%

 

CIPP-C dumps Free Test Engine Verified By It Certified Experts: https://www.practicetorrent.com/CIPP-C-practice-exam-torrent.html

CIPP-C Exam Free Practice Test with100% Accurate Answers: https://drive.google.com/open?id=1XKPw_-5OWTt1Rzp8Hxa7CQOZAYU3TaJq