CIPA Data Security & Privacy Compliance 3 — Questions and Answers
Question 1: A data breach notification under most US state laws must be sent to affected residents within a specific timeframe. What is the most commonly required window across US states?
- 24 hours
- 30–72 hours
- 30–90 days (Correct answer)
- 6 months
Correct answer: 30–90 days
Most US state breach notification laws require notification to affected residents within 30 to 90 days of discovering the breach.
Question 2: Which concept ensures that a user or system is granted only the minimum level of access necessary to perform their job function?
- Separation of duties
- Principle of least privilege (Correct answer)
- Defense in depth
- Zero trust
Correct answer: Principle of least privilege
The principle of least privilege limits access rights to only what is strictly required for a user's role, reducing the attack surface.
Question 3: Under PCI DSS, what is the maximum number of days that audit logs must be retained?
- 30 days
- 6 months
- 1 year (Correct answer)
- 3 years
Correct answer: 1 year
PCI DSS Requirement 10.7 mandates that audit logs be retained for at least one year, with three months immediately available for analysis.
Question 4: A company wants to share customer data with a marketing analytics vendor without exposing actual PII. Which technique replaces real data with fictional but realistic data?
- Tokenization
- Data masking (Correct answer)
- Hashing
- Encryption
Correct answer: Data masking
Data masking substitutes real PII with fictitious but realistic values, allowing analytics to proceed without exposing actual customer information.
Question 5: Which GDPR legal basis is most appropriate when a business processes personal data to fulfill a contract with the data subject?
- Legitimate interests
- Vital interests
- Contractual necessity (Correct answer)
- Explicit consent
Correct answer: Contractual necessity
GDPR Article 6(1)(b) allows processing without consent when it is necessary for the performance of a contract with the data subject.
Question 6: Under FERPA, which entity type is primarily responsible for protecting student education records?
- Parents of college students
- Educational institutions that receive federal funding (Correct answer)
- State departments of education only
- Private employers who request transcripts
Correct answer: Educational institutions that receive federal funding
FERPA applies to educational agencies and institutions that receive funds from the US Department of Education, making them the primary responsible parties.
Question 7: A company collects health data through a fitness app that is not covered by HIPAA. Which privacy framework or law is most likely to apply in the US?
- HIPAA Privacy Rule
- FTC Act Section 5 (unfair or deceptive practices) (Correct answer)
- GLBA Safeguards Rule
- FERPA
Correct answer: FTC Act Section 5 (unfair or deceptive practices)
Non-HIPAA health apps fall under FTC jurisdiction; the FTC Act Section 5 prohibits unfair or deceptive acts, including mishandling health data.
A data breach notification under most US state laws must be sent to affected residents within a specific timeframe.
What is the most commonly required window across US states?