CyberVista Test CyberVista Data Security and Privacy 2 — Questions and Answers
Question 1: Under GDPR, organizations are required to report a personal data breach to the supervisory authority within:
- 24 hours of discovery
- 48 hours of discovery
- 72 hours of discovery (Correct answer)
- 7 days of discovery
Correct answer: 72 hours of discovery
GDPR Article 33 requires that a personal data breach likely to result in risk to individuals must be reported to the relevant supervisory authority within 72 hours of becoming aware of it.
Question 2: The California Consumer Privacy Act (CCPA) grants California residents the right to:
- Demand encryption of their stored personal data
- Know what personal information is collected and request its deletion (Correct answer)
- Sue companies for any data collection without consent
- Opt out of all data processing activities
Correct answer: Know what personal information is collected and request its deletion
CCPA gives California residents the right to know what personal data is being collected, the right to delete it, the right to opt out of its sale, and the right to non-discrimination for exercising these rights.
Question 3: Which of the following is considered Protected Health Information (PHI) under HIPAA?
- Aggregated, de-identified patient statistics
- A patient's name combined with their medical diagnosis (Correct answer)
- General wellness information in a fitness app
- Anonymized clinical trial data
Correct answer: A patient's name combined with their medical diagnosis
PHI is individually identifiable health information that includes any combination of an identifier (such as a name) and health-related data (such as a diagnosis or treatment).
Question 4: Privacy by Design (PbD) is a framework that requires privacy to be:
- Added to systems as a patch after deployment
- Embedded into system design from the outset rather than retrofitted (Correct answer)
- Enforced solely through legal compliance audits
- Managed exclusively by the legal and compliance department
Correct answer: Embedded into system design from the outset rather than retrofitted
Privacy by Design mandates that privacy protections be proactively built into technology and business processes from the earliest design stage, not added as an afterthought.
Question 5: The 'Right to be Forgotten' (Right to Erasure) under GDPR allows individuals to:
- Prevent any data from being collected about them in the first place
- Request deletion of their personal data under certain conditions (Correct answer)
- Sue organizations for historical data breaches
- Access all data an organization holds about them at any time
Correct answer: Request deletion of their personal data under certain conditions
GDPR Article 17 gives individuals the right to request erasure of their personal data when it is no longer necessary, consent is withdrawn, or the data was unlawfully processed.
Question 6: Which role under GDPR is responsible for ensuring that an organization's data processing activities comply with the regulation?
- Chief Information Security Officer (CISO)
- Data Protection Officer (DPO) (Correct answer)
- Chief Privacy Officer (CPO)
- Information Assurance Manager (IAM)
Correct answer: Data Protection Officer (DPO)
The Data Protection Officer (DPO) is a role mandated by GDPR for certain organizations, responsible for overseeing data protection strategy and ensuring compliance with the regulation.
Question 7: An organization collects customer email addresses only for order confirmations but later uses them for marketing campaigns without re-obtaining consent. This violates which privacy principle?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Data accuracy
Correct answer: Purpose limitation
The purpose limitation principle requires that personal data be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
Under GDPR, organizations are required to report a personal data breach to the supervisory authority within: