Certified Information Privacy Technologist (CIPT) — Questions and Answers
Question 1: Under the US HIPAA Breach Notification Rule, how quickly must covered entities notify affected individuals of an unsecured PHI breach?
- Within 14 days of discovery
- Without unreasonable delay and no later than 60 days after discovery (Correct answer)
- Within 24 hours of discovery
- Only after completing a full forensic investigation, with no time limit
Correct answer: Without unreasonable delay and no later than 60 days after discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and within 60 days of discovering a breach of unsecured PHI.
Question 2: Which Privacy by Design principle emphasizes keeping systems open and verifiable so users can trust that stated privacy practices are actually being followed?
- Visibility and Transparency (Correct answer)
- User-Centric Design
- Privacy as the Default Setting
- Proactive not Reactive
Correct answer: Visibility and Transparency
Visibility and Transparency ensures that business practices and technologies are open to independent verification, building user trust.
Question 3: Which international standard provides guidance on privacy information management systems (PIMS) and is complementary to ISO/IEC 27001?
- ISO/IEC 27701 (Correct answer)
- ISO/IEC 29134
- ISO/IEC 27018
- ISO/IEC 29100
Correct answer: ISO/IEC 27701
ISO/IEC 27701 extends ISO 27001 by specifying requirements and guidance for establishing and continually improving a Privacy Information Management System (PIMS).
Question 4: Which metrics best measure the effectiveness of an organization's breach response capability?
- Annual budget allocated to cybersecurity tools and platforms
- Total number of privacy policies reviewed and updated annually
- Number of employees who completed annual breach response training
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to incidents (Correct answer)
Correct answer: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to incidents
MTTD and MTTR directly measure how quickly an organization identifies and responds to breaches, making them the most meaningful indicators of response effectiveness.
Question 5: What does 'End-to-End Security — Full Lifecycle Protection' require in Privacy by Design?
- Encrypting only data in transit
- Secure retention and deletion of data throughout its entire lifecycle (Correct answer)
- Applying security controls only during user authentication
- Securing only the database layer
Correct answer: Secure retention and deletion of data throughout its entire lifecycle
End-to-End Security means strong security measures protect data from collection through secure destruction at the end of its lifecycle.
Question 6: A web application assigns a random session token instead of embedding the user's account number in the URL. This is an example of which PET?
- Homomorphic encryption
- Tokenization (Correct answer)
- Differential privacy
- Data minimization
Correct answer: Tokenization
Tokenization replaces sensitive values like account numbers with random tokens, reducing the exposure of real identifiers.
Question 7: A company uses automated profiling to make credit decisions with significant effects on individuals. Under GDPR Article 22, what right do affected individuals have?
- The right to compensation for any adverse decision
- The right to opt out of all profiling activities permanently
- The right to erasure of the decision
- The right to obtain human review and contest the decision (Correct answer)
Correct answer: The right to obtain human review and contest the decision
GDPR Article 22 gives individuals the right not to be subject to solely automated decisions with significant effects, and the right to obtain human intervention, express their point of view, and contest the decision.
Question 8: What is the first step an organization should take upon discovering a potential privacy breach?
- Notify all affected individuals immediately
- Contain the breach and preserve evidence (Correct answer)
- Issue a public press release
- Contact law enforcement agencies
Correct answer: Contain the breach and preserve evidence
Containment is the first priority to stop further exposure, followed by evidence preservation to support investigation.
Question 9: After a breach is resolved, which activity is MOST important for preventing future incidents?
- Publishing a formal public apology statement acknowledging the breach
- Increasing the organization's marketing and public relations budget
- Replacing the entire IT or security department responsible for the systems
- Conducting a root cause analysis and implementing corrective controls to address identified vulnerabilities (Correct answer)
Correct answer: Conducting a root cause analysis and implementing corrective controls to address identified vulnerabilities
Root cause analysis identifies the specific weaknesses that enabled the breach, and targeted corrective controls directly address those gaps to prevent recurrence.
Question 10: A data controller conducts profiling that produces legal or similarly significant effects on individuals. Under GDPR, what right do individuals have in this scenario?
- The right to access the source code of the profiling algorithm
- The right to data portability for all profiled data
- The right to erasure of all profile data within 24 hours
- The right not to be subject to solely automated decision-making (Correct answer)
Correct answer: The right not to be subject to solely automated decision-making
GDPR Article 22 gives individuals the right not to be subject to decisions based solely on automated processing, including profiling, that produce significant effects.
Question 11: A privacy risk assessment rates risks using 'likelihood' and 'impact'. What does the combination of these two factors produce?
- A compliance checklist
- A breach notification timeline
- A risk score or risk level (Correct answer)
- A data flow diagram
Correct answer: A risk score or risk level
Risk level = likelihood Ă— impact; this score prioritizes which risks require immediate mitigation versus those that can be monitored.
Question 12: A development team uses data minimization during system design so that only necessary personal data fields are collected. Which Privacy by Design principle does this best reflect?
- End-to-End Security
- Visibility and Transparency
- Proactive not Reactive
- Privacy Embedded into Design (Correct answer)
Correct answer: Privacy Embedded into Design
Privacy Embedded into Design requires integrating privacy controls — including data minimization — directly into the architecture of systems.
Question 13: In the CIPT body of knowledge, which privacy-enhancing technology (PET) allows a verifier to confirm a fact about a user without learning the underlying data?
- Role-based access control
- Transport Layer Security
- Zero-knowledge proof (Correct answer)
- Symmetric encryption
Correct answer: Zero-knowledge proof
A zero-knowledge proof enables one party to prove knowledge of a value to another party without conveying any information beyond the validity of the statement.
Question 14: Which international standard provides a framework for privacy information management systems (PIMS) and can be used to certify an organization's privacy program?
- NIST SP 800-53
- ISO/IEC 27001
- ISO 9001
- ISO/IEC 27701 (Correct answer)
Correct answer: ISO/IEC 27701
ISO/IEC 27701 extends ISO 27001 to address privacy requirements, providing a PIMS framework and enabling organizations to certify their privacy management practices.
Question 15: What is a 'privacy program maturity model' used for?
- Grading individual employee privacy knowledge
- Calculating GDPR fines based on violation severity
- Measuring how advanced and effective an organization's privacy practices are across defined capability levels (Correct answer)
- Ranking countries by the strength of their privacy laws
Correct answer: Measuring how advanced and effective an organization's privacy practices are across defined capability levels
A maturity model (e.g., AICPA Privacy Maturity Model, NIST Privacy Framework) benchmarks the current state of a privacy program and provides a roadmap for improvement.
Question 16: What is the purpose of privacy risk 'scenarios' in a DPIA?
- To estimate the financial cost of compliance
- To describe specific ways that identified threats could materialize and cause harm to data subjects (Correct answer)
- To list all technical security controls in place
- To document regulatory fines received in the past year
Correct answer: To describe specific ways that identified threats could materialize and cause harm to data subjects
Risk scenarios translate abstract threats into concrete narratives showing how a vulnerability could be exploited and what harm would result for individuals.
Question 17: The concept of 'purpose limitation' in European data protection law is most closely aligned with which OECD Privacy Guideline?
- Openness Principle
- Use Limitation Principle (Correct answer)
- Security Safeguards Principle
- Data Quality Principle
Correct answer: Use Limitation Principle
The OECD Use Limitation Principle restricts personal data from being used for purposes other than those specified, mirroring the GDPR's purpose limitation concept.
Question 18: Which software development practice integrates privacy requirements into each sprint or iteration of an Agile project?
- Post-launch privacy audits
- Annual privacy policy updates
- Privacy by Design in Agile (privacy user stories) (Correct answer)
- Waterfall privacy gate reviews
Correct answer: Privacy by Design in Agile (privacy user stories)
Writing privacy user stories and including privacy acceptance criteria in each sprint embeds Privacy by Design into Agile workflows.
Question 19: Which governance mechanism ensures that personal data collected for one purpose is not used for an incompatible second purpose?
- Purpose limitation controls (Correct answer)
- Data retention policies
- Encryption at rest
- Role-based access control
Correct answer: Purpose limitation controls
Purpose limitation controls — including technical restrictions and policy enforcement — prevent data from being repurposed beyond its original, consented-to use.
Question 20: Which role is typically responsible for defining data classification levels and associated handling requirements in a data governance program?
- Data subject
- Data custodian
- Data owner (Correct answer)
- Data processor
Correct answer: Data owner
The data owner (usually a business unit leader) is accountable for data classification decisions and the rules governing how data at each level must be handled.
Question 21: What is a data inventory (or data map) primarily used for in a privacy governance program?
- Tracking server uptime and performance metrics
- Managing software licenses
- Documenting where personal data is collected, stored, processed, and shared (Correct answer)
- Auditing user login activity
Correct answer: Documenting where personal data is collected, stored, processed, and shared
A data inventory catalogs all personal data assets, their locations, purposes, legal bases, and flows, forming the foundation for privacy compliance programs.
Question 22: A privacy engineer proposes using 'k-anonymity' when publishing a dataset. What does this guarantee?
- Data is encrypted with k encryption keys
- Each field is masked with k random characters
- k users must consent before any data is published
- Each record is indistinguishable from at least k-1 other records on quasi-identifiers (Correct answer)
Correct answer: Each record is indistinguishable from at least k-1 other records on quasi-identifiers
k-anonymity ensures that any individual in a dataset cannot be uniquely identified because their quasi-identifier combination matches at least k-1 other individuals.
Question 23: Which document serves as the foundational governance instrument that describes an organization's privacy program scope, objectives, and senior management commitment?
- Privacy notice (external)
- Privacy policy (internal) (Correct answer)
- Incident response plan
- Data processing agreement
Correct answer: Privacy policy (internal)
An internal privacy policy establishes the organization's privacy program framework, assigns responsibilities, and documents management's commitment to privacy as an organizational value.
Question 24: In a data governance program, what is the role of a 'data steward'?
- Responding to data subject access requests
- Managing day-to-day data quality, classification, and compliance for a specific dataset or domain (Correct answer)
- Processing personal data on behalf of the controller
- Setting organization-wide privacy strategy
Correct answer: Managing day-to-day data quality, classification, and compliance for a specific dataset or domain
Data stewards are operational custodians who enforce data governance policies, maintain data quality, and ensure day-to-day compliance within their assigned data domain.
Question 25: A privacy impact assessment (PIA) is most valuable when conducted at which stage of a project?
- During routine maintenance
- After product launch
- When a breach occurs
- Early in the design phase (Correct answer)
Correct answer: Early in the design phase
Conducting a PIA early in design allows privacy risks to be mitigated before costly system changes are required.
Question 26: Which principle from the Fair Information Practice Principles (FIPPs) requires that individuals be able to find out what personal information about them is on record?
- Individual Participation (Correct answer)
- Security Safeguards
- Openness
- Use Limitation
Correct answer: Individual Participation
The Individual Participation principle ensures that individuals have a right to know about and access personal information held about them, and can challenge inaccurate or incomplete data.
Question 27: A privacy engineer is asked to implement a technique that replaces real user identifiers with pseudonyms in a dataset. What technique is being used?
- Anonymization
- Data masking for testing
- Pseudonymization (Correct answer)
- Tokenization of payment data
Correct answer: Pseudonymization
Pseudonymization replaces direct identifiers with artificial identifiers (pseudonyms) so that data can no longer be attributed to a specific individual without additional information.
Question 28: An organization implements automated data expiry rules that delete personal records when their retention period ends. What governance benefit does this provide?
- Reduces the need for user consent mechanisms
- Improves database query speed
- Ensures HIPAA encryption requirements are met
- Reduces risk of holding data beyond its legal or business justification (Correct answer)
Correct answer: Reduces risk of holding data beyond its legal or business justification
Automated retention enforcement ensures data is not held longer than necessary, reducing regulatory exposure and minimizing the dataset affected in a breach.
Question 29: What is the function of 'privacy threat modeling' in system development?
- Encrypting all data fields in the database
- Documenting regulatory requirements applicable to the system
- Writing user-facing privacy notices
- Systematically identifying privacy threats specific to a system's data flows and architecture (Correct answer)
Correct answer: Systematically identifying privacy threats specific to a system's data flows and architecture
Privacy threat modeling (e.g., using LINDDUN) analyzes a system's data flow diagrams to surface privacy-specific threats such as linkability, identifiability, and disclosure.
Question 30: What does 'remediation' mean in a privacy breach response context?
- Immediately deleting all data that was involved in or touched by the breach
- Paying financial compensation to all individuals whose data was involved in the breach
- Publicly disclosing all technical details of the breach to the media and general public
- Actions taken to fix the vulnerabilities, misconfigurations, or weaknesses that caused or enabled the breach (Correct answer)
Correct answer: Actions taken to fix the vulnerabilities, misconfigurations, or weaknesses that caused or enabled the breach
Remediation involves applying patches, reconfiguring systems, and implementing new controls to address the root causes of the breach and harden defenses against future incidents.
Question 31: What is the purpose of a data processing agreement (DPA) between a controller and a processor?
- To contractually bind the processor to process data only on documented instructions and implement adequate safeguards (Correct answer)
- To replace a privacy policy for end users
- To transfer data ownership from controller to processor
- To allow the processor to sell data to third parties
Correct answer: To contractually bind the processor to process data only on documented instructions and implement adequate safeguards
A DPA ensures the processor acts only on the controller's instructions, maintains confidentiality, and implements appropriate technical and organizational security measures.
Question 32: A company collects biometric data in Illinois. Under the Illinois Biometric Information Privacy Act (BIPA), what must the company do BEFORE collection?
- Obtain written release from the subject and publish a retention schedule (Correct answer)
- Notify state regulators within 30 days
- Submit a privacy impact assessment to the Attorney General
- Anonymize the data before storage
Correct answer: Obtain written release from the subject and publish a retention schedule
BIPA requires companies to inform subjects in writing about the collection, its purpose, and duration; and obtain a written release before collecting biometric identifiers or information.
Question 33: An organization in Australia processes personal information under the Australian Privacy Act. Which document sets out the 13 Australian Privacy Principles?
- The Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Correct answer)
- The Notifiable Data Breaches Scheme
- The Privacy Regulation 2013
- The Office of the Australian Information Commissioner guidelines
Correct answer: The Privacy Amendment (Enhancing Privacy Protection) Act 2012
The Privacy Amendment (Enhancing Privacy Protection) Act 2012 replaced the former Information Privacy Principles and National Privacy Principles with the 13 APPs.
Question 34: What is an 'access log' used for from a privacy accountability perspective?
- Blocking unauthorized users in real time
- Creating an auditable record of who accessed personal data, when, and from where (Correct answer)
- Encrypting data transfers between systems
- Measuring application performance
Correct answer: Creating an auditable record of who accessed personal data, when, and from where
Access logs enable post-hoc detection of unauthorized access, support breach investigations, and demonstrate accountability for personal data access to regulators.
Question 35: In Privacy by Design, what does the principle 'Proactive not Reactive' mean?
- Comply with regulations after they are enacted
- Anticipate and prevent privacy-invasive events before they occur (Correct answer)
- React quickly when a data breach happens
- Notify users after collecting their data
Correct answer: Anticipate and prevent privacy-invasive events before they occur
Proactive not Reactive means privacy is built in from the start, preventing incidents rather than remedying them after the fact.
Question 36: A healthcare startup uses de-identified patient data for AI model training. Under HIPAA's Safe Harbor method, how many specific identifiers must be removed?
- 18 (Correct answer)
- 24
- 21
- 15
Correct answer: 18
HIPAA's Safe Harbor de-identification method requires removal of 18 specific categories of identifiers, including names, geographic subdivisions smaller than a state, dates, phone numbers, and others.
Question 37: Which privacy engineering objective focuses on limiting the ability of systems to link data to specific individuals across contexts?
- Manageability
- Data integrity
- Disassociability (Correct answer)
- Predictability
Correct answer: Disassociability
Disassociability is the privacy engineering objective aimed at ensuring data cannot be linked or associated with individuals beyond what is necessary.
Question 38: Which of Ann Cavoukian's seven foundational principles of Privacy by Design states that privacy should be the default setting?
- Full Functionality
- Privacy as the Default Setting (Correct answer)
- Proactive not Reactive
- End-to-End Security
Correct answer: Privacy as the Default Setting
Privacy as the Default Setting means users automatically receive maximum privacy without any required action on their part.
Question 39: Under the Colorado Privacy Act (CPA), what is the maximum civil penalty per intentional violation?
- $7,500 (Correct answer)
- $20,000
- $50,000
- $2,500
Correct answer: $7,500
The Colorado Privacy Act allows the Attorney General to seek civil penalties of up to $20,000 per violation, but enforcement is similar to other state laws with a 60-day cure period in some circumstances.
Question 40: Under GDPR, processing personal data based on legitimate interests requires a balancing test. Which factor weighs AGAINST legitimate interests?
- The processing involves sensitive categories of personal data (Correct answer)
- The data subject can easily opt out
- The processing is limited to what is necessary
- The data subject has a reasonable expectation of the processing
Correct answer: The processing involves sensitive categories of personal data
Processing sensitive categories of personal data weighs heavily against relying on legitimate interests as a legal basis, as such data carries heightened privacy risks requiring stronger justification.
Question 41: Which type of data breach typically poses the HIGHEST risk to individuals' rights and freedoms?
- Accidental email to a wrong internal address containing non-sensitive scheduling data
- Loss of an encrypted device where no decryption key is known to exist
- Temporary loss of access to a public-facing website
- Unauthorized disclosure of combined medical records and financial information enabling identity theft (Correct answer)
Correct answer: Unauthorized disclosure of combined medical records and financial information enabling identity theft
Breaches exposing sensitive categories of data that can enable discrimination, identity theft, or financial harm pose the highest risk under GDPR risk-assessment criteria.
Question 42: What is 'substitute notice' in the context of breach notification laws?
- Notifying regulators in lieu of notifying affected individuals
- Sending a condensed summary notice rather than a full breach disclosure document
- Alternative notification methods such as website posting or media notice when direct contact is impractical or cost-prohibitive (Correct answer)
- Using a third-party vendor to send breach notifications on behalf of the organization
Correct answer: Alternative notification methods such as website posting or media notice when direct contact is impractical or cost-prohibitive
Substitute notice allows organizations to satisfy notification obligations via media notices or website postings when direct individual notification is infeasible due to cost or missing contact information.
Question 43: When must an organization consult with the supervisory authority (e.g., a DPA) after completing a DPIA?
- When processing data of fewer than 500 individuals
- When the DPIA indicates a high residual risk that the organization cannot sufficiently mitigate (Correct answer)
- Only when a data breach has already occurred
- After every DPIA regardless of the findings
Correct answer: When the DPIA indicates a high residual risk that the organization cannot sufficiently mitigate
Prior consultation with the supervisory authority is required when the DPIA shows that high risks remain after the organization's mitigation efforts.
Question 44: Which factor most commonly triggers the requirement to conduct a DPIA under GDPR?
- Storing employee email addresses
- Publishing a public website privacy policy
- Systematic and large-scale processing of sensitive personal data (Correct answer)
- Processing data for payroll purposes
Correct answer: Systematic and large-scale processing of sensitive personal data
GDPR Article 35 requires a DPIA when processing is likely to result in high risk, particularly for large-scale processing of special category data or systematic profiling.
Question 45: The 'Accountability' principle in the OECD Privacy Guidelines assigns responsibility for compliance to which party?
- The supervisory authority
- The data processor
- The data subject
- The data controller (Correct answer)
Correct answer: The data controller
Under the OECD Accountability principle, the data controller is responsible for ensuring the other principles are complied with.
Question 46: What is the role of attorney-client privilege in a privacy breach investigation?
- It shields individual employees from personal liability during the investigation
- It allows the organization to legally avoid notifying supervisory authorities
- It waives affected individuals' rights to notification under applicable breach laws
- It can protect investigation findings from compelled disclosure in litigation when the investigation is directed by legal counsel (Correct answer)
Correct answer: It can protect investigation findings from compelled disclosure in litigation when the investigation is directed by legal counsel
When a breach investigation is conducted under the direction of legal counsel, attorney-client privilege may shield the resulting work product from being used against the organization in subsequent litigation.
Question 47: What is the 'principle of least privilege' as applied to personal data access?
- Administrators should have read-only access to all data
- Users and systems should only have access to the personal data required to perform their specific function (Correct answer)
- All employees should share a single account for simplicity
- Data should be accessible to anyone within the corporate network
Correct answer: Users and systems should only have access to the personal data required to perform their specific function
Least privilege minimizes the number of people and systems with access to personal data, reducing insider threat risk and limiting breach scope.
Question 48: A company's privacy team conducts an internal 'privacy audit' annually. What does this audit primarily assess?
- The number of privacy complaints received that year
- Whether privacy controls are operating effectively and practices align with stated policies and applicable regulations (Correct answer)
- Whether the privacy policy document has been updated
- The cost-effectiveness of privacy technology investments
Correct answer: Whether privacy controls are operating effectively and practices align with stated policies and applicable regulations
A privacy audit tests whether controls are actually working as designed and whether operational practices match written policies and legal requirements.
Question 49: A company processes health data for insurance purposes. Which type of risk assessment is most appropriate given the sensitivity of the data?
- Data Protection Impact Assessment (DPIA) (Correct answer)
- Financial risk audit
- Penetration test only
- Business continuity assessment
Correct answer: Data Protection Impact Assessment (DPIA)
Health data is a special category under GDPR, and processing it at scale for insurance purposes triggers the DPIA requirement due to the high privacy risk involved.
Question 50: In the context of Privacy by Design, what is a 'privacy impact assessment' (PIA) primarily used for during system development?
- Measuring website analytics performance
- Auditing user consent records quarterly
- Documenting data breaches after they occur
- Identifying and mitigating privacy risks before system deployment (Correct answer)
Correct answer: Identifying and mitigating privacy risks before system deployment
A PIA evaluates how a proposed system or process will affect individual privacy and enables teams to address risks before launch.
Question 51: Which element of a privacy program ensures employees know how to recognize and escalate a potential personal data breach?
- Privacy incident reporting channel and training on what constitutes a reportable event (Correct answer)
- Network segmentation controls
- Annual password rotation policy
- Automated data loss prevention (DLP) only
Correct answer: Privacy incident reporting channel and training on what constitutes a reportable event
Effective breach response depends on employees recognizing privacy incidents and knowing how to report them promptly through a clear escalation path.
Question 52: Which practice should businesses adopt to ensure compliance with data privacy laws?
- Collect and store as much customer data as possible
- Gather, handle, and store only necessary customer data (Correct answer)
- Share sensitive customer data with other businesses
- Delete all customer data after its expiration
Correct answer: Gather, handle, and store only necessary customer data
A core principle of data privacy, often referred to as data minimization, dictates that businesses should only collect, process, and retain personal data that is strictly necessary for the specified purpose. Adopting this practice reduces the risk of data breaches, simplifies compliance efforts, and aligns with legal requirements to limit data collection to what is adequate, relevant, and limited to what is necessary.
Question 53: Which control requires that a minimum number of authorized personnel must cooperate to perform a sensitive operation, preventing unilateral action?
- Mandatory access control
- Separation of duties
- Role-based access control
- Multi-party authorization (M-of-N control) (Correct answer)
Correct answer: Multi-party authorization (M-of-N control)
M-of-N (multi-party authorization) requires M out of N designated individuals to approve an action, guarding against insider abuse.
Question 54: A company wants to allow third-party analysis of its customer database without revealing individual records. Which technique best enables this?
- Multi-factor authentication
- Homomorphic encryption (Correct answer)
- Transport Layer Security
- Role-based access control
Correct answer: Homomorphic encryption
Homomorphic encryption allows computations to be performed on encrypted data without decrypting it, preserving privacy during analysis.
Question 55: Which authentication method provides the strongest privacy protection by ensuring that even if a password is stolen, unauthorized access is prevented?
- Long password requirements alone
- IP address allowlisting alone
- Multi-factor authentication (MFA) (Correct answer)
- Security questions only
Correct answer: Multi-factor authentication (MFA)
MFA requires a second factor (e.g., TOTP code, hardware token) in addition to the password, significantly reducing the risk of unauthorized access from credential theft.
Question 56: What is the 'risk of harm' standard primarily used for in breach notification decisions?
- Setting the regulatory reporting timeline after a breach is discovered
- Determining the financial penalties owed to regulators after a breach
- Calculating compensation amounts owed to individual data subjects
- Establishing whether the severity of potential harm to individuals triggers mandatory notification (Correct answer)
Correct answer: Establishing whether the severity of potential harm to individuals triggers mandatory notification
The risk of harm standard acts as a threshold test—notification is required only when a breach creates a sufficient risk of real harm to affected individuals.
Question 57: Which privacy control restricts what a requesting application or user can see based on a defined need-to-know policy?
- Data retention policy
- Breach notification
- Data portability
- Role-based access control (RBAC) (Correct answer)
Correct answer: Role-based access control (RBAC)
RBAC grants access to personal data only to roles with a legitimate need, limiting exposure and supporting least-privilege principles.
Question 58: Which engineering technique adds statistical noise to datasets to protect individual privacy while preserving overall data utility?
- Homomorphic encryption
- Differential privacy (Correct answer)
- Access control lists
- Data tokenization
Correct answer: Differential privacy
Differential privacy injects calibrated noise into query results so that individual records cannot be inferred from aggregate outputs.
Question 59: What is the primary purpose of data minimization as a privacy engineering control?
- Collect only the data necessary for the specified purpose (Correct answer)
- Minimize the number of database tables
- Reduce storage costs by compressing files
- Delete all data older than 90 days
Correct answer: Collect only the data necessary for the specified purpose
Data minimization limits the collection of personal data to what is strictly necessary for a defined purpose, reducing privacy risk.
Question 60: Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals within how many days of discovering a breach?
- 30 calendar days
- 90 calendar days
- 45 calendar days
- 60 calendar days (Correct answer)
Correct answer: 60 calendar days
The HIPAA Breach Notification Rule requires notification to affected individuals without unreasonable delay and no later than 60 calendar days of breach discovery.
Question 61: Which of the following best defines a 'personal data breach' under GDPR Article 4(12)?
- The loss of any device containing encrypted data
- A security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data (Correct answer)
- Any violation of an organization's internal data security policy
- Any unauthorized access to a computer system
Correct answer: A security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data
GDPR Article 4(12) defines a personal data breach as a security incident affecting the confidentiality, integrity, or availability of personal data.
Question 62: K-anonymity ensures that any individual in a dataset is indistinguishable from at least how many other individuals with respect to quasi-identifiers?
- k+1
- k-1
- 2k
- k (Correct answer)
Correct answer: k
In a k-anonymous dataset, every record shares the same quasi-identifier values with at least k-1 other records, making the group size at least k.
Question 63: What is the primary purpose of a privacy incident response plan?
- To provide a structured approach for detecting, containing, and recovering from privacy incidents (Correct answer)
- To transfer breach liability to third-party data processors
- To eliminate the need for cyber liability insurance
- To avoid regulatory fines by demonstrating documented compliance
Correct answer: To provide a structured approach for detecting, containing, and recovering from privacy incidents
An incident response plan provides a systematic, pre-defined process to manage breaches efficiently and minimize harm to individuals.
Question 64: A company uses attribute-based access control (ABAC) to restrict access to medical records. What makes ABAC more privacy-protective than simple RBAC?
- ABAC eliminates the need for encryption
- ABAC automatically deletes access logs after 30 days
- ABAC can incorporate contextual attributes (time, location, data sensitivity) for finer-grained, purpose-aware access decisions (Correct answer)
- ABAC requires no user training
Correct answer: ABAC can incorporate contextual attributes (time, location, data sensitivity) for finer-grained, purpose-aware access decisions
ABAC evaluates multiple attributes — user role, resource sensitivity, time of day, location — enabling dynamic, context-sensitive access decisions that align more precisely with the need-to-know principle.
Question 65: What is the main goal of applying 'data separation' or 'compartmentalization' as a privacy engineering technique?
- Speeding up database queries
- Encrypting data at rest
- Limiting the combination of data that could re-identify individuals (Correct answer)
- Reducing cloud storage costs
Correct answer: Limiting the combination of data that could re-identify individuals
Data separation prevents linking datasets that together could re-identify individuals, limiting the risk of aggregation attacks.
Question 66: What is the 'need-to-know' principle as applied to personal data access in identity management?
- Individuals should only access personal data that is necessary for their specific, current task (Correct answer)
- All senior managers should have unrestricted data access
- Data should be accessible to any authenticated employee
- Access rights should be granted once and never reviewed
Correct answer: Individuals should only access personal data that is necessary for their specific, current task
Need-to-know limits data access to what is required for the immediate, specific task, preventing unnecessary exposure even among authorized users.
Question 67: Which approach involves transferring privacy risk to a third party, such as through cyber liability insurance or vendor contractual indemnification?
- Risk acceptance
- Risk avoidance
- Risk transfer (Correct answer)
- Risk mitigation
Correct answer: Risk transfer
Risk transfer shifts financial or operational consequence of a privacy risk to another party but does not eliminate the underlying risk to data subjects.
Question 68: Which privacy threat category involves an attacker combining publicly available data from multiple sources to re-identify an anonymized individual?
- Aggregation attack (Correct answer)
- SQL injection
- Man-in-the-middle attack
- Phishing attack
Correct answer: Aggregation attack
An aggregation attack combines individually harmless data elements from multiple sources to reconstruct a person's identity or sensitive information.
Question 69: An e-commerce platform stores customer purchase history indefinitely 'just in case it is useful later.' Which privacy principle does this most directly violate?
- Individual participation
- Openness
- Purpose specification (Correct answer)
- Security safeguards
Correct answer: Purpose specification
Purpose specification requires that the purposes for which data is collected be specified before collection; storing data for vague future use violates this.
Question 70: Which term describes the risk that a machine learning model trained on sensitive data can inadvertently memorize and reveal specific training examples?
- Model poisoning
- Data leakage through overfitting (Correct answer)
- Adversarial example attack
- Membership inference risk
Correct answer: Data leakage through overfitting
Overfitted models can memorize training data, allowing adversaries to extract sensitive records through carefully crafted queries.
Question 71: An organization applies different handling rules to 'confidential,' 'internal,' and 'public' data categories. What process created these distinctions?
- Data masking
- Data normalization
- Data lineage tracking
- Data classification (Correct answer)
Correct answer: Data classification
Data classification assigns sensitivity levels to data categories, enabling proportionate controls to be applied based on the level of privacy risk.
Question 72: A healthcare app encrypts data in transit using TLS but stores it in plaintext on the server. Which threat does this configuration leave unaddressed?
- Man-in-the-browser attacks
- Server-side data breach (Correct answer)
- Certificate spoofing
- Network eavesdropping
Correct answer: Server-side data breach
Encrypting only data in transit leaves stored data vulnerable to server compromise; encryption at rest is also required.
Question 73: Which NIST framework provides voluntary guidance for organizations to improve their privacy risk management programs?
- NIST Privacy Framework (PF) 1.0 (Correct answer)
- NIST SP 800-37
- NIST SP 800-171
- NIST Cybersecurity Framework (CSF) 2.0
Correct answer: NIST Privacy Framework (PF) 1.0
The NIST Privacy Framework (2020) provides a voluntary, risk-based tool with Core, Profiles, and Implementation Tiers to help organizations manage privacy risks.
Question 74: The concept of 'privacy by default' in GDPR Article 25 primarily requires that:
- Users must opt-in before any data processing begins
- Data is anonymized by default before any transfer
- All system features be disabled until the user enables them
- The most privacy-protective settings are active without user action (Correct answer)
Correct answer: The most privacy-protective settings are active without user action
Privacy by default means that, by default, only personal data necessary for each specific purpose is processed, without requiring action from the data subject.
Question 75: Which framework component in the NIST Privacy Framework maps most closely to implementing access controls and encryption for personal data?
- Govern-P
- Protect-P (Correct answer)
- Communicate-P
- Detect-P
Correct answer: Protect-P
The Protect-P function in the NIST Privacy Framework covers activities that develop and implement safeguards to prevent privacy incidents.
Question 76: What is a 'privacy champion' network within an organization?
- External privacy consultants hired for annual reviews
- Designated employees embedded in business units who advocate for privacy practices and serve as liaisons to the central privacy team (Correct answer)
- A regulatory body that champions consumer privacy rights
- Software agents that enforce data access policies automatically
Correct answer: Designated employees embedded in business units who advocate for privacy practices and serve as liaisons to the central privacy team
Privacy champions extend the reach of the central privacy team by embedding privacy knowledge and accountability into individual departments across the organization.
Question 77: Which principle in the OECD Privacy Guidelines requires that personal data collected should be relevant to the purposes for which it is used and not excessive?
- Data Quality (Correct answer)
- Use Limitation
- Purpose Specification
- Collection Limitation
Correct answer: Data Quality
The OECD Data Quality principle requires that personal data should be relevant to the purposes for which they are to be used, and should be accurate, complete, and kept up-to-date.
Question 78: Which U.S. federal sector-specific law primarily governs the privacy of student education records?
- GLBA
- HIPAA
- COPPA
- FERPA (Correct answer)
Correct answer: FERPA
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records and gives parents (or eligible students) the right to access and correct those records.
Question 79: Which element is generally NOT required in a breach notification sent directly to affected individuals?
- A list of all employees who handled the breached data internally (Correct answer)
- Steps individuals can take to protect themselves from potential harm
- Description of the types of personal information involved in the breach
- Contact information for the notifying organization
Correct answer: A list of all employees who handled the breached data internally
Breach notifications must help individuals protect themselves but do not require disclosing internal personnel details, which would not aid the affected person.
Question 80: A company's privacy notice is written at a 16th-grade reading level. Which privacy principle does this most directly violate?
- Transparency (right to clear, intelligible information) (Correct answer)
- Storage limitation
- Data minimization
- Purpose limitation
Correct answer: Transparency (right to clear, intelligible information)
Privacy notices must be concise, transparent, and written in plain language so that data subjects can genuinely understand how their data is used.
Question 81: What is a significant impact of data privacy regulations on businesses?
- Decreased compliance costs
- Enhanced brand value
- Simplified data management
- Increased business disruption (Correct answer)
Correct answer: Increased business disruption
Data privacy regulations often necessitate significant changes to business processes, IT systems, and data handling practices. Implementing new compliance measures, conducting data mapping, revising consent mechanisms, and responding to data subject requests can be complex and resource-intensive, leading to operational disruptions and increased costs as businesses adapt to new legal requirements.
Question 82: Which operational practice ensures that privacy controls remain effective as systems, regulations, and threats evolve over time?
- Continuous monitoring and periodic privacy program reviews (Correct answer)
- Delegating all privacy decisions to legal counsel
- A one-time compliance audit at program launch
- Annual policy republication without control testing
Correct answer: Continuous monitoring and periodic privacy program reviews
Continuous monitoring detects control failures and changing risk conditions, while periodic reviews reassess whether the program still meets current regulatory and business requirements.
Question 83: Which US law focuses on safeguarding health-related personal information?
- HIPAA (Correct answer)
- GLBA
- FCRA
- FERPA
Correct answer: HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a landmark US federal law specifically designed to protect sensitive patient health information. It establishes national standards for the security, privacy, and integrity of protected health information (PHI) by covered entities and their business associates, ensuring the confidentiality of medical records.
Question 84: A CIPT is reviewing a new mobile app. She recommends that the app request location permission only when a location-based feature is actively used. Which principle does this reflect?
- Context-aware data collection (purpose limitation) (Correct answer)
- End-to-end encryption
- Full functionality
- Data portability
Correct answer: Context-aware data collection (purpose limitation)
Context-aware data collection ensures personal data is gathered only when directly needed for a specific user action, limiting purpose and minimizing collection.
Question 85: An organization implements 'just-in-time' (JIT) privileged access, granting elevated permissions only for the duration of a specific task. What privacy benefit does this provide?
- Reduces the cost of identity management systems
- Minimizes the window of exposure for sensitive data by eliminating persistent privileged access (Correct answer)
- Allows users to bypass MFA for privileged tasks
- Eliminates the need for audit logs
Correct answer: Minimizes the window of exposure for sensitive data by eliminating persistent privileged access
JIT access ensures that elevated permissions exist only as long as the task requires, dramatically reducing the risk of insider misuse or credential theft of persistent admin accounts.
Question 86: The FTC's Health Breach Notification Rule applies primarily to which type of entity?
- HIPAA-covered entities such as hospitals and health insurers
- State health departments and public health agencies
- All businesses that collect or process any health-related data
- Vendors of personal health records and related apps not subject to HIPAA (Correct answer)
Correct answer: Vendors of personal health records and related apps not subject to HIPAA
The FTC's Health Breach Notification Rule fills the gap left by HIPAA, applying to vendors of personal health records and PHR-related entities that HIPAA does not cover.
Question 87: A data processor experiences a breach affecting EU residents' data. Under GDPR, within what timeframe must the processor notify the controller?
- Without undue delay (Correct answer)
- Within 24 hours
- Within 7 business days
- Within 72 hours
Correct answer: Without undue delay
Under GDPR Article 33(2), processors must notify controllers of a personal data breach without undue delay after becoming aware of it, without a specific hour limit for processor-to-controller notification.
Question 88: A company implements a data minimization strategy where it only collects data fields absolutely necessary for a transaction. Which Fair Information Practice Principle does this best exemplify?
- Purpose specification
- Collection limitation (Correct answer)
- Individual participation
- Use limitation
Correct answer: Collection limitation
Collection limitation is the FIPP that restricts data collection to what is necessary, relevant, and obtained fairly.
Question 89: Under the California Consumer Privacy Act (CCPA), which right allows consumers to prevent a business from selling their personal information?
- Right to access
- Right to deletion
- Right to opt-out of sale (Correct answer)
- Right to non-discrimination
Correct answer: Right to opt-out of sale
The CCPA gives California residents the right to opt out of the sale of their personal information to third parties.
Question 90: What is 'residual risk' in the context of privacy risk management?
- The risk transferred to cyber insurance
- The remaining risk after controls and mitigations have been applied (Correct answer)
- The initial risk before any controls are considered
- The total financial exposure from a data breach
Correct answer: The remaining risk after controls and mitigations have been applied
Residual risk is what remains after all identified controls are implemented; it must be accepted, transferred, or reduced further if it exceeds the organization's risk tolerance.
Certified Information Privacy Technologist (CIPT)
The CIPT certification, offered by IAPP, validates expertise in embedding privacy into technology systems and products. It covers privacy engineering, data lifecycle management, privacy risk management, privacy-enhancing technologies, and privacy by design principles.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds