ExamGecko
Home Home / IAPP / CIPT

IAPP CIPT Practice Test - Questions Answers, Page 19

Question list
Search
Search

List of questions

Search

Related questions




SCENARIO Please use the following to answer the next questions: Your company is launching a new track and trace health app during the outbreak of a virus pandemic in the US. The developers claim the app is based on privacy by design because personal data collected was considered to ensure only necessary data is captured, users are presented with a privacy notice, and they are asked to give consent before data is shared. Users can update their consent after logging into an account, through a dedicated privacy and consent hub. This is accessible through the 'Settings' icon from any app page, then clicking 'My Preferences', and selecting 'Information Sharing and Consent' where the following choices are displayed: • "I consent to receive notifications and infection alerts"; • "I consent to receive information on additional features or services, and new products"; • "I consent to sharing only my risk result and location information, for exposure and contact tracing purposes"; • "I consent to share my data for medical research purposes"; and • "I consent to share my data with healthcare providers affiliated to the company". For each choice, an ON* or OFF tab is available The default setting is ON for all Users purchase a virus screening service for USS29 99 for themselves or others using the app The virus screening service works as follows: • Step 1 A photo of the user's face is taken. • Step 2 The user measures their temperature and adds the reading in the app • Step 3 The user is asked to read sentences so that a voice analysis can detect symptoms • Step 4 The user is asked to answer questions on known symptoms • Step 5 The user can input information on family members (name date of birth, citizenship, home address, phone number, email and relationship).) The results are displayed as one of the following risk status "Low. "Medium" or "High" if the user is deemed at "Medium " or "High" risk an alert may be sent to other users and the user is Invited to seek a medical consultation and diagnostic from a healthcare provider. A user's risk status also feeds a world map for contact tracing purposes, where users are able to check if they have been or are in dose proximity of an infected person If a user has come in contact with another individual classified as "medium' or 'high' risk an instant notification also alerts the user of this. The app collects location trails of every user to monitor locations visited by an infected individual Location is collected using the phone's GPS functionary, whether the app is in use or not however, the exact location of the user is "blurred' for privacy reasons Users can only see on the map circles Which of the following is likely to be the most important issue with the choices presented in the 'Information Sharing and Consent' pages?







SCENARIO

Please use the following to answer the next questions:

Your company is launching a new track and trace health app during the outbreak of a virus pandemic in the US. The developers claim the app is based on privacy by design because personal data collected was considered to ensure only necessary data is captured, users are presented with a privacy notice, and they are asked to give consent before data is shared. Users can update their consent after logging into an account, through a dedicated privacy and consent hub.

This is accessible through the 'Settings' icon from any app page, then clicking 'My Preferences', and selecting 'Information Sharing and Consent' where the following choices are displayed:

• "I consent to receive notifications and infection alerts";

• "I consent to receive information on additional features or services, and new products";

• "I consent to sharing only my risk result and location information, for exposure and contact tracing purposes";

• "I consent to share my data for medical research purposes"; and

• "I consent to share my data with healthcare providers affiliated to the company".

For each choice, an ON* or OFF tab is available The default setting is ON for all Users purchase a virus screening service for USS29 99 for themselves or others using the app The virus screening service works as follows:

• Step 1 A photo of the user's face is taken.

• Step 2 The user measures their temperature and adds the reading in the app

• Step 3 The user is asked to read sentences so that a voice analysis can detect symptoms

• Step 4 The user is asked to answer questions on known symptoms

• Step 5 The user can input information on family members (name date of birth, citizenship, home address, phone number, email and relationship).)

The results are displayed as one of the following risk status "Low. "Medium" or "High" if the user is deemed at "Medium " or "High" risk an alert may be sent to other users and the user is Invited to seek a medical consultation and diagnostic from a healthcare provider.

A user's risk status also feeds a world map for contact tracing purposes, where users are able to check if they have been or are in dose proximity of an infected person If a user has come in contact with another individual classified as "medium' or 'high' risk an instant notification also alerts the user of this. The app collects location trails of every user to monitor locations visited by an infected individual Location is collected using the phone's GPS functionary, whether the app is in use or not however, the exact location of the user is "blurred' for privacy reasons Users can only see on the map circles Which of the following is likely to be the most important issue with the choices presented in the 'Information

Sharing and Consent' pages?

A.

The data and recipients for medical research are not specified

A.

The data and recipients for medical research are not specified

Answers
B.

Insufficient information is provided on notifications and infection alerts

B.

Insufficient information is provided on notifications and infection alerts

Answers
C.

The sharing of information with an affiliated healthcare provider is too risky

C.

The sharing of information with an affiliated healthcare provider is too risky

Answers
D.

Allowing users to share risk result information for exposure and contact tracing purposes

D.

Allowing users to share risk result information for exposure and contact tracing purposes

Answers
Suggested answer: A

Explanation:

Not specifying the data and recipients for medical research can make it difficult for users to make informed decisions about whether to consent to this type of information sharing. This lack of transparency could result in personal information being shared with third parties without the user's full understanding or consent.

SCENARIO

Please use the following to answer the next questions:

Your company is launching a new track and trace health app during the outbreak of a virus pandemic in the US. The developers claim the app is based on privacy by design because personal data collected was considered to ensure only necessary data is captured, users are presented with a privacy notice, and they are asked to give consent before data is shared. Users can update their consent after logging into an account, through a dedicated privacy and consent hub.

This is accessible through the 'Settings' icon from any app page, then clicking 'My Preferences', and selecting 'Information Sharing and Consent' where the following choices are displayed:

• "I consent to receive notifications and infection alerts";

• "I consent to receive information on additional features or services, and new products";

• "I consent to sharing only my risk result and location information, for exposure and contact tracing purposes";

• "I consent to share my data for medical research purposes"; and

• "I consent to share my data with healthcare providers affiliated to the company".

For each choice, an ON* or OFF tab is available The default setting is ON for all Users purchase a virus screening service for USS29 99 for themselves or others using the app The virus screening service works as follows:

• Step 1 A photo of the user's face is taken.

• Step 2 The user measures their temperature and adds the reading in the app

• Step 3 The user is asked to read sentences so that a voice analysis can detect symptoms

• Step 4 The user is asked to answer questions on known symptoms

• Step 5 The user can input information on family members (name date of birth, citizenship, home address, phone number, email and relationship).) The results are displayed as one of the following risk status "Low. "Medium" or "High" if the user is deemed at "Medium " or "High" risk an alert may be sent to other users and the user is Invited to seek a medical consultation and diagnostic from a healthcare provider.

A user's risk status also feeds a world map for contact tracing purposes, where users are able to check if they have been or are in dose proximity of an infected person If a user has come in contact with another individual classified as "medium' or 'high' risk an instant notification also alerts the user of this. The app collects location trails of every user to monitor locations visited by an infected individual Location is collected using the phone's GPS functionary, whether the app is in use or not however, the exact location of the user is "blurred' for privacy reasons Users can only see on the map circles Which of the following pieces of information collected is the LEAST likely to be justified tor the purposes of the app?

A.

Relationship of family member

A.

Relationship of family member

Answers
B.

Phone number

B.

Phone number

Answers
C.

Dale of birth

C.

Dale of birth

Answers
D.

Citizenship

D.

Citizenship

Answers
Suggested answer: D

Explanation:

Of the pieces of information collected by the app described in the scenario provided in the exhibit you shared, citizenship (option D) is LEAST likely to be justified for the purposes of the app.

Citizenship may not be necessary for providing health recommendations or contact tracing services.

Collecting this type of personal information could raise privacy concerns if it is not necessary for fulfilling the primary purpose of the app.

SCENARIO

Please use the following to answer the next questions:

Your company is launching a new track and trace health app during the outbreak of a virus pandemic in the US. The developers claim the app is based on privacy by design because personal data collected was considered to ensure only necessary data is captured, users are presented with a privacy notice, and they are asked to give consent before data is shared. Users can update their consent after logging into an account, through a dedicated privacy and consent hub.

This is accessible through the 'Settings' icon from any app page, then clicking 'My Preferences', and selecting 'Information Sharing and Consent' where the following choices are displayed:

• "I consent to receive notifications and infection alerts";

• "I consent to receive information on additional features or services, and new products";

• "I consent to sharing only my risk result and location information, for exposure and contact tracing purposes";

• "I consent to share my data for medical research purposes"; and

• "I consent to share my data with healthcare providers affiliated to the company".

For each choice, an ON* or OFF tab is available The default setting is ON for all Users purchase a virus screening service for USS29 99 for themselves or others using the app The virus screening service works as follows:

• Step 1 A photo of the user's face is taken.

• Step 2 The user measures their temperature and adds the reading in the app

• Step 3 The user is asked to read sentences so that a voice analysis can detect symptoms

• Step 4 The user is asked to answer questions on known symptoms

• Step 5 The user can input information on family members (name date of birth, citizenship, home address, phone number, email and relationship).) The results are displayed as one of the following risk status "Low. "Medium" or "High" if the user is deemed at "Medium " or "High" risk an alert may be sent to other users and the user is Invited to seek a medical consultation and diagnostic from a healthcare provider.

A user's risk status also feeds a world map for contact tracing purposes, where users are able to check if they have been or are in dose proximity of an infected person If a user has come in contact with another individual classified as "medium' or 'high' risk an instant notification also alerts the user of this. The app collects location trails of every user to monitor locations visited by an infected individual Location is collected using the phone's GPS functionary, whether the app is in use or not however, the exact location of the user is "blurred' for privacy reasons Users can only see on the map circles The location data collected and displayed on the map should be changed for which of the following reasons?

A.

The blurriness does not allow users to know how close they are to an infected person

A.

The blurriness does not allow users to know how close they are to an infected person

Answers
B.

The radius used for location data exceeds official social distancing rules

B.

The radius used for location data exceeds official social distancing rules

Answers
C.

The location data has not been pseudonymized

C.

The location data has not been pseudonymized

Answers
D.

The location data is loo precise

D.

The location data is loo precise

Answers
Suggested answer: D

Explanation:

Location data that is too precise can reveal sensitive information about an individual's movements and activities. This could raise privacy concerns if this detailed location data is shared with third parties or used for purposes other than contact tracing. Pseudonymizing location data (option C) could also help protect user privacy but may not address concerns about overly precise location data.

SCENARIO

Please use the following to answer the next questions:

Your company is launching a new track and trace health app during the outbreak of a virus pandemic in the US. The developers claim the app is based on privacy by design because personal data collected was considered to ensure only necessary data is captured, users are presented with a privacy notice, and they are asked to give consent before data is shared. Users can update their consent after logging into an account, through a dedicated privacy and consent hub.

This is accessible through the 'Settings' icon from any app page, then clicking 'My Preferences', and selecting 'Information Sharing and Consent' where the following choices are displayed:

• "I consent to receive notifications and infection alerts";

• "I consent to receive information on additional features or services, and new products";

• "I consent to sharing only my risk result and location information, for exposure and contact tracing purposes";

• "I consent to share my data for medical research purposes"; and

• "I consent to share my data with healthcare providers affiliated to the company".

For each choice, an ON* or OFF tab is available The default setting is ON for all Users purchase a virus screening service for USS29 99 for themselves or others using the app The virus screening service works as follows:

• Step 1 A photo of the user's face is taken.

• Step 2 The user measures their temperature and adds the reading in the app

• Step 3 The user is asked to read sentences so that a voice analysis can detect symptoms

• Step 4 The user is asked to answer questions on known symptoms

• Step 5 The user can input information on family members (name date of birth, citizenship, home address, phone number, email and relationship).) The results are displayed as one of the following risk status "Low. "Medium" or "High" if the user is deemed at "Medium " or "High" risk an alert may be sent to other users and the user is Invited to seek a medical consultation and diagnostic from a healthcare provider.

A user's risk status also feeds a world map for contact tracing purposes, where users are able to check if they have been or are in dose proximity of an infected person If a user has come in contact with another individual classified as "medium' or 'high' risk an instant notification also alerts the user of this. The app collects location trails of every user to monitor locations visited by an infected individual Location is collected using the phone's GPS functionary, whether the app is in use or not however, the exact location of the user is "blurred' for privacy reasons Users can only see on the map circles Which technology is best suited for the contact tracing feature of the app1?

A.

Bluetooth

A.

Bluetooth

Answers
B.

Deep learning

B.

Deep learning

Answers
C.

Near Field Communication (NFC)

C.

Near Field Communication (NFC)

Answers
D.

Radio-Frequency Identification (RFID)

D.

Radio-Frequency Identification (RFID)

Answers
Suggested answer: A

Explanation:

Bluetooth technology can enable devices to communicate with each other over short distances. This makes it well-suited for contact tracing applications where proximity between individuals needs to be detected. Deep learning (option B), Near Field Communication (NFC) (option C), and Radio- Frequency Identification (RFID) (option D) are technologies that could also have potential uses in a contact tracing app but may not be as well-suited as Bluetooth.

An organization needs to be able to manipulate highly sensitive personal information without revealing the contents of the data to the users. The organization should investigate the use of?

A.

Advanced Encryption Standard (AES)

A.

Advanced Encryption Standard (AES)

Answers
B.

Homomorphic encryption

B.

Homomorphic encryption

Answers
C.

Quantum encryption

C.

Quantum encryption

Answers
D.

Pseudonymization

D.

Pseudonymization

Answers
Suggested answer: B

A healthcare provider would like to data mine information for research purposes however the Chief Privacy Officer is concerned medical data of individuals may be disclosed overcome the concern, which is the preferred technique for protecting such data while still allowing for analysis?

A.

Access Control

A.

Access Control

Answers
B.

Encryption

B.

Encryption

Answers
C.

Isolation

C.

Isolation

Answers
D.

Perturbation

D.

Perturbation

Answers
Suggested answer: D

A privacy technologist has been asked to aid in a forensic investigation on the darknet following the compromise of a company's personal dat a. This will primarily involve an understanding of which of the following privacy-preserving techniques?

A.

Encryption

A.

Encryption

Answers
B.

Do Not Track

B.

Do Not Track

Answers
C.

Masking

C.

Masking

Answers
D.

Tokenization

D.

Tokenization

Answers
Suggested answer: A

Which of these is considered an ethical dark pattern on privacy?

A.

Using attractive designs to influence an individual.

A.

Using attractive designs to influence an individual.

Answers
B.

Rewarding users for providing more personal information

B.

Rewarding users for providing more personal information

Answers
C.

Giving users more privacy options in relation to their personal information

C.

Giving users more privacy options in relation to their personal information

Answers
D.

Providing dear and simple privacy notices to users

D.

Providing dear and simple privacy notices to users

Answers
Suggested answer: B

Which concept related to privacy choice is demonstrated by highlighting and bolding the "accept" button on a cookies notice while maintaining standard text format for other options?

A.

Illuminating

A.

Illuminating

Answers
B.

Nudging

B.

Nudging

Answers
C.

Suppression

C.

Suppression

Answers
D.

Tagging

D.

Tagging

Answers
Suggested answer: B

Truncating the last octet of an IP address because it is NOT needed is an example of which privacy principle?

A.

Use Limitation

A.

Use Limitation

Answers
B.

Data Minimization

B.

Data Minimization

Answers
C.

Purpose Limitation

C.

Purpose Limitation

Answers
D.

Security Safeguards

D.

Security Safeguards

Answers
Suggested answer: B

Explanation:

Data minimization is a privacy principle that involves collecting and processing only the minimum amount of personal data necessary for a specific purpose.

Total 220 questions
Go to page: of 22