CIPA Data Security & Privacy Compliance 5 — Questions and Answers
Question 1: A healthcare organization wants to share patient data with researchers while removing all 18 HIPAA identifiers. This process is formally called:
- Pseudonymization
- Anonymization
- De-identification (Correct answer)
- Tokenization
Correct answer: De-identification
HIPAA's Safe Harbor and Expert Determination methods describe de-identification as the removal of the 18 specified identifiers so data is no longer considered PHI.
Question 2: Under the NIST Cybersecurity Framework, which function focuses on developing and implementing activities to identify the occurrence of a cybersecurity event?
- Identify
- Protect
- Detect (Correct answer)
- Respond
Correct answer: Detect
The 'Detect' function of the NIST CSF encompasses continuous monitoring and anomaly detection to discover cybersecurity events in a timely manner.
Question 3: A company's privacy policy states it will only use email addresses for order confirmations but then uses them for promotional campaigns. This violates which key privacy principle?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Data accuracy
Correct answer: Purpose limitation
Purpose limitation requires that personal data collected for one specific purpose not be used for a different, incompatible purpose without additional consent.
Question 4: An identity thief uses stolen credentials to access multiple accounts by testing username/password pairs obtained from other data breaches. This attack is called:
- Password spraying
- Credential stuffing (Correct answer)
- Dictionary attack
- Rainbow table attack
Correct answer: Credential stuffing
Credential stuffing automates the testing of stolen username/password combinations from one breach against other websites, exploiting password reuse.
Question 5: Which US law specifically regulates the accuracy, fairness, and privacy of information in consumer credit reporting files?
- GLBA
- FCRA (Correct answer)
- ECPA
- COPPA
Correct answer: FCRA
The Fair Credit Reporting Act (FCRA) governs the collection, dissemination, and use of consumer credit information, including consumer rights to dispute inaccuracies.
Question 6: A CIPA candidate reviews an organization's incident response plan. Which phase comes immediately after 'Containment' in the NIST SP 800-61 incident response lifecycle?
- Detection and Analysis
- Preparation
- Eradication (Correct answer)
- Post-Incident Activity
Correct answer: Eradication
NIST SP 800-61 orders the phases as Preparation → Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity.
Question 7: An organization uses a third-party cloud provider to process personal data. Under GDPR, the organization is best described as the:
- Data processor
- Data controller (Correct answer)
- Sub-processor
- Data custodian
Correct answer: Data controller
The entity that determines the purposes and means of processing personal data is the data controller; the cloud provider acting on its instructions is the data processor.
A healthcare organization wants to share patient data with researchers while removing all 18 HIPAA identifiers.
This process is formally called: