CMP Risk Management & Compliance 3 — Questions and Answers
Question 1: A planner is using a mobile event app that collects attendee personal data for a European audience. Which regulation governs data handling?
- CCPA
- HIPAA
- GDPR (Correct answer)
- FERPA
Correct answer: GDPR
The General Data Protection Regulation (GDPR) governs the collection and processing of personal data for individuals in the European Union.
Question 2: During an outdoor event, a severe weather warning is issued. What should the emergency action plan prioritize FIRST?
- Contacting the media to announce the delay
- Notifying the catering team to pause food service
- Moving attendees to pre-identified shelter locations (Correct answer)
- Reviewing the force majeure clause in vendor contracts
Correct answer: Moving attendees to pre-identified shelter locations
Life safety is always the first priority in any emergency, requiring immediate movement of attendees to safe shelter.
Question 3: What does a 'force majeure' clause in an event contract primarily protect against?
- Attrition penalties when room block is underperformed
- Cancellation or disruption caused by unforeseeable, uncontrollable events (Correct answer)
- Disputes over audiovisual equipment fees
- Liability for attendee personal injury
Correct answer: Cancellation or disruption caused by unforeseeable, uncontrollable events
Force majeure clauses excuse contract performance when extraordinary events beyond either party's control make performance impossible.
Question 4: Which risk assessment tool plots the likelihood of a risk event against its potential impact?
- SWOT analysis
- Risk register
- Risk matrix (probability-impact grid) (Correct answer)
- Gap analysis
Correct answer: Risk matrix (probability-impact grid)
A risk matrix visually maps probability against impact to help planners prioritize which risks require the most attention.
Question 5: An event venue requires all external vendors to submit certificates of insurance naming the venue as an additional insured. Why?
- To allow the venue to cancel vendor agreements at will
- To ensure the venue is covered under the vendor's policy for liability claims arising from vendor actions (Correct answer)
- To transfer all event liability to vendors
- To comply with fire code requirements
Correct answer: To ensure the venue is covered under the vendor's policy for liability claims arising from vendor actions
Adding the venue as an additional insured on a vendor's policy means the venue has coverage protection if the vendor's actions cause a claim.
Question 6: A conference organizer collects credit card data through an online registration portal. Which standard governs secure handling of this data?
- ISO 9001
- PCI-DSS (Correct answer)
- SOC 2
- NIST 800-53
Correct answer: PCI-DSS
Payment Card Industry Data Security Standard (PCI-DSS) mandates specific controls for any organization that stores, processes, or transmits cardholder data.
Question 7: What is the PRIMARY purpose of conducting a post-event incident debrief after a risk event occurs?
- To assign blame for the incident
- To identify what worked and what failed so future risk plans can be improved (Correct answer)
- To satisfy legal discovery requirements
- To generate content for the event recap report
Correct answer: To identify what worked and what failed so future risk plans can be improved
Post-event debriefs are a learning tool to improve future emergency response plans, not to attribute fault.
A planner is using a mobile event app that collects attendee personal data for a European audience.
Which regulation governs data handling?