IAPP CIPP-US Practice Test - Questions Answers, Page 19
List of questions
Related questions
What consumer protection did the Fair and Accurate Credit Transactions Act (FACTA) require?
The ability to correct inaccurate credit report information
The truncation of account numbers on credit card receipts
The right to request removal from email lists.
The issuing of notice when third-party data is used in an adverse decision
Which of the following would best provide a sufficient consumer disclosure under the Fair Credit Reporting Act (FCRA) prior to a consumer report being obtained for employment purposes?
A verbal notice provided with a conditional offer of employment
A notice provision in an electronic employment application.
A notice provision in a mailed offer letter.
A standalone notice document.
SCENARIO
Please use the following to answer the next question;
Jane is a U.S. citizen and a senior software engineer at California-based Jones Labs, a major software supplier to the U.S. Department of Defense and other U.S. federal agencies Jane's manager, Patrick, is a French citizen who has been living in California for over a decade. Patrick has recently begun to suspect that Jane is an insider secretly transmitting trade secrets to foreign intelligence. Unbeknownst to Patrick, the FBI has already received a hint from anonymous whistleblower, and jointly with the National Secunty Agency is investigating Jane's possible implication in a sophisticated foreign espionage campaign
Ever since the pandemic. Jane has been working from home. To complete her daily tasks she uses her corporate laptop, which after each togin conspicuously provides notice that the equipment belongs to Jones Labs and may be monitored according to the enacted privacy policy and employment handbook Jane also has a corporate mobile phone that she uses strictly for business, the terms of which are defined in her employment contract and elaborated upon in her employee handbook. Both the privacy policy and the employee handbook are revised annually by a reputable California law firm specializing in privacy law. Jane also has a personal iPhone that she uses for private purposes only.
Jones Labs has its primary data center in San Francisco, which is managed internally by Jones Labs engineers The secondary data center, managed by Amazon AWS. is physically located in the UK for disaster recovery purposes. Jones Labs' mobile devices backup is managed by a mid-sized mobile delense company located in Denver, which physically stores the data in Canada to reduce costs. Jones Labs MS Office documents are securely stored in a Microsoft Office 365 data
When storing Jane's fingerprint for remote authentication. Jones Labs should consider legality issues under which of the following9
The Privacy Rule of the HITECH Act.
The California loT Security Law (SB 327).
The applicable state law such as Illinois BIPA
The federal Genetic Information Nondiscrimination Act (GINA).
SCENARIO
Please use the following to answer the next question;
Jane is a U.S. citizen and a senior software engineer at California-based Jones Labs, a major software supplier to the U.S. Department of Defense and other U.S. federal agencies Jane's manager, Patrick, is a French citizen who has been living in California for over a decade. Patrick has recently begun to suspect that Jane is an insider secretly transmitting trade secrets to foreign intelligence. Unbeknownst to Patrick, the FBI has already received a hint from anonymous whistleblower, and jointly with the National Secunty Agency is investigating Jane's possible implication in a sophisticated foreign espionage campaign
Ever since the pandemic. Jane has been working from home. To complete her daily tasks she uses her corporate laptop, which after each togin conspicuously provides notice that the equipment belongs to Jones Labs and may be monitored according to the enacted privacy policy and employment handbook Jane also has a corporate mobile phone that she uses strictly for business, the terms of which are defined in her employment contract and elaborated upon in her employee handbook. Both the privacy policy and the employee handbook are revised annually by a reputable California law firm specializing in privacy law. Jane also has a personal iPhone that she uses for private purposes only.
Jones Labs has its primary data center in San Francisco, which is managed internally by Jones Labs engineers The secondary data center, managed by Amazon AWS. is physically located in the UK for disaster recovery purposes. Jones Labs' mobile devices backup is managed by a mid-sized mobile delense company located in Denver, which physically stores the data in Canada to reduce costs. Jones Labs MS Office documents are securely stored in a Microsoft Office 365 data
Under Section 702 of F1SA. The NSA may do which of the following without a Foreign Intelligence Surveillance Court warrant?
Compel AWS to disclose Jane's email communications with a Taiwanese national residing in Taiwan.
Compel AWS to disclose email communications between two Chinese nationals residing in the EU.
Compel Microsoft to disclose Patnck's Skype calls with a Brazilian national living in Peru.
Compel Jane to disclose the PIN code for her corporate mobile phone.
According to the Family Educational Rights and Privacy Act (FERPA). when can a school disclose records without a student's consent?
If the disclosure Is not to be conducted through email to the third party
If the disclosure would not reveal a student's student identification number
If the disclosure is made to practitioners who are involved in a student's hearth care.
If the disclosure is for the purpose of providing transcripts to a school where a student intends to enroll.
A software company wants to use web scraping to collect personal data from professional networking websites in order to train an artificial intelligence program to evaluate Job applications. The company has identified several actions for limiting their potential legal liability regarding affected data subjects and professional networking websites. Which of the following would be the least effective action for helping them do this?
Following the terms of use posted on professional networking websites that are scraped.
Adding a notice to the company website's terms of use disclosing the use of web scraping
Limiting the amount of the personally identifiable information they collect
Decertifying the scraped data before selling it to any third parties.
Due to cookie deprecation, businesses will be required to simplify their tracking practices by doing what?
Ensuring only registered users are tracked.
Running analytics only in dedicated sandboxes
Purging existing IDs that identify visitors by browser.
Deleting their existing data sets of any third-party cookies
The Clarifying Lawful Overseas Use of Data (CLOUD) Act is primarily intended to do which of the following?
Codify a treaty with the EU that permits the cross-border transfer of personal information from the EU to the United States in compliance with the General Data Protection Regulation (GDPR).
Update the legal mechanisms through which federal law enforcement may obtain data that service providers maintain in a foreign country
Establish baseline pnvacy obligations that US companies must comply with for personal information, even if stored in a foreign country
Prohibit foreign companies from using the personal Information of US. citizens without their consent
Which of the following most accurately describes the regulatory status ot pandemic contact-tracing apps in the United States?
Contact tracing is covered exclusively under the Health Insurance Portability and Accountability Act (HIPAA).
Contact tracing is regulated by the U.S. Centers for Disease Control and Prevention (CDC).
Contact tracing is subject to a patchwork of federal and state privacy laws
Contact tracing is not regulated in the United States.
Which power was NOT granted to the California Privacy Protection Agency by the California Privacy Rights Act (CPRA)?
Adopting and updating CCPA regulations
Investigating possible violations of the CCPA on the agency's own initiative.
Overriding decisions of the Attorney General regarding CCPA enforcement
Imposing administrative fines for violations of the CCPA
Question