Information Governance Professional (IGP) Exam — Questions and Answers
Question 1: How does an effective policy support regulatory compliance?
- Only addresses internal rules
- Slows operations
- By ignoring laws
- Handles info per laws and standards (Correct answer)
Correct answer: Handles info per laws and standards
An effective information governance policy supports regulatory compliance by establishing clear guidelines and procedures for how information must be handled in accordance with applicable laws, industry standards, and internal rules. By defining requirements for data privacy, security, retention, and disposal, the policy helps organizations meet their legal obligations. This proactive approach minimizes the risk of non-compliance penalties and reputational damage.
Question 2: How does encryption support data privacy?
- Only for backups
- Is optional
- Protects against unauthorized access (Correct answer)
- Slows data access
Correct answer: Protects against unauthorized access
Encryption supports data privacy by transforming data into a coded format, making it unreadable to anyone without the correct decryption key. This protective measure safeguards information both at rest (e.g., on a server) and in transit (e.g., over a network). By rendering sensitive data unintelligible to unauthorized individuals, encryption effectively prevents unauthorized access and maintains confidentiality.
Question 3: What is the PRIMARY purpose of obtaining IGP certification in Information Governance Professional?
- To satisfy a personal achievement goal
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To bypass educational requirements
- To guarantee employment
Correct answer: To demonstrate verified competency and adherence to professional standards
Certification demonstrates verified competency and adherence to professional standards.
Question 4: Which foundational principle is MOST important for success in Information Governance Professional?
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Specializing in only one narrow area
- Maximizing financial returns
- Maintaining minimum certification requirements
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success requires continuous learning, ethical practice, and focus on quality outcomes.
Question 5: Which approach is MOST important for IGP professionals when applying technical procedures?
- Using the fastest method regardless of standards
- Following personal shortcuts
- Applying the same technique without variation
- Adhering to established protocols while adapting to specific conditions (Correct answer)
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to protocols with professional judgment for adaptation.
Question 6: What role does risk management play in information governance?
- Increase risks
- Identify and mitigate risks (Correct answer)
- Ignore risks
- Only for audits
Correct answer: Identify and mitigate risks
Risk management plays a fundamental role in information governance by systematically identifying, assessing, and mitigating potential risks associated with an organization's information assets. This includes risks related to data breaches, non-compliance, data loss, and unauthorized access. By proactively managing these risks, information governance helps protect the organization's reputation, financial stability, and legal standing.
Question 7: Which risk management approach is MOST effective for IGP professionals when evaluating potential workplace hazards?
- Relying solely on historical accident data
- Delegating all safety decisions to management
- Reactive analysis after incidents occur
- Proactive hazard identification and assessment (Correct answer)
Correct answer: Proactive hazard identification and assessment
Proactive hazard identification and assessment allows professionals to identify and mitigate risks before incidents occur.
Question 8: How does risk management benefit organizations?
- Is optional
- Identify and mitigate threats (Correct answer)
- Creates confusion
- Increases liabilities
Correct answer: Identify and mitigate threats
Risk management benefits organizations by systematically identifying, assessing, and mitigating potential threats and vulnerabilities that could impact their information assets. By proactively addressing risks, organizations can minimize the likelihood of adverse events like data breaches or system failures, and reduce their potential impact. This protects valuable information, ensures business continuity, and safeguards the organization's reputation and financial stability.
Question 9: Under GDPR, the maximum fine for the most serious violations is:
- €20 million or 4% of global annual turnover (Correct answer)
- €10 million or 2% of global annual turnover
- €5 million or 1% of global annual turnover
- €50 million or 5% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR's highest tier of fines is €20 million or 4% of global annual turnover, whichever is higher.
Question 10: What is a compliance audit?
- Only for IT systems
- Evaluate adherence to regulations (Correct answer)
- A financial review
- An informal check
Correct answer: Evaluate adherence to regulations
A compliance audit is a formal, independent examination that evaluates an organization's adherence to specific laws, regulations, industry standards, and internal policies. It assesses whether controls are in place and operating effectively to meet compliance requirements. The audit identifies gaps or non-compliance issues, allowing the organization to take corrective actions and demonstrate due diligence.
Question 11: What role does antivirus software play?
- Install malware
- Ignore threats
- Detect and remove malware (Correct answer)
- Delete important files
Correct answer: Detect and remove malware
Antivirus software plays a critical role in information security by detecting, preventing, and removing malicious software (malware) such as viruses, worms, and Trojans. It scans files and systems for known threats and suspicious behavior, protecting computers and networks from infection. This helps maintain the integrity and availability of data and systems, preventing data loss or compromise.
Question 12: Under the FTC Act, what standard has the FTC used to regulate data privacy practices of US companies?
- Companies must comply with GDPR standards for all US consumers
- All personal data collected must be encrypted using AES-256
- Companies must appoint a DPO if they process data on more than 500 individuals
- Unfair or deceptive acts or practices, including failing to honor stated privacy policies (Correct answer)
Correct answer: Unfair or deceptive acts or practices, including failing to honor stated privacy policies
The FTC uses its Section 5 authority to take action against unfair or deceptive practices, including when companies violate their own privacy policies or fail to adequately protect consumer data.
Question 13: What is a retention schedule?
- Defines record retention time (Correct answer)
- A financial report
- Data backup plan
- Random deletion
Correct answer: Defines record retention time
A retention schedule is a document that defines how long specific types of records must be kept by an organization. It specifies the minimum and maximum periods for which records should be retained, based on legal, regulatory, operational, and historical requirements. This systematic approach ensures compliance, reduces storage costs, and prevents premature or overdue destruction of valuable information.
Question 14: What is the main purpose of a records retention schedule in relation to information security?
- Define encryption algorithms for stored records
- Assign access permissions to records by role
- Determine backup frequency for critical records
- Specify how long records must be kept and when they should be destroyed (Correct answer)
Correct answer: Specify how long records must be kept and when they should be destroyed
A records retention schedule defines required retention periods for each record type and the authorized disposition method, supporting both legal compliance and data minimization.
Question 15: What is the purpose of compliance in information governance?
- Ignore regulations
- Reduce data quality
- Increase risks
- Ensure adherence to laws and policies (Correct answer)
Correct answer: Ensure adherence to laws and policies
The purpose of compliance in information governance is to ensure that an organization adheres to all relevant laws, regulations, and internal policies concerning its information assets. This includes data privacy laws, industry-specific regulations, and contractual obligations. Achieving compliance helps avoid legal penalties, reputational damage, and builds trust with customers and stakeholders.
Question 16: How should records be disposed securely?
- Shred or securely delete (Correct answer)
- Archive indefinitely
- Donate to public
- Throw in trash
Correct answer: Shred or securely delete
Records should be disposed of securely to prevent unauthorized access to sensitive information after it is no longer needed. Methods like shredding physical documents or securely deleting/wiping electronic data ensure that the information is irrecoverable. This practice is vital for maintaining data privacy, complying with regulations, and mitigating the risk of data breaches even after a record's retention period expires.
Question 17: What role does calibration play in maintaining technical accuracy for Information Governance Professional professionals?
- It only matters during inspections
- It is only necessary for new equipment
- It ensures instruments produce accurate, consistent results over time (Correct answer)
- It is optional for advanced professionals
Correct answer: It ensures instruments produce accurate, consistent results over time
Regular calibration ensures instruments continue producing accurate results over time.
Question 18: A privilege log in e-discovery is used to:
- List the names of all custodians who received a legal hold notice
- Track the number of documents reviewed per day by each attorney
- Record the login credentials for e-discovery review platforms
- Identify and describe documents withheld from production based on attorney-client privilege or work product doctrine (Correct answer)
Correct answer: Identify and describe documents withheld from production based on attorney-client privilege or work product doctrine
A privilege log itemizes documents withheld from production, describing each document's date, author, recipients, and basis for the privilege claim without revealing privileged content itself.
Question 19: An IGP professional reviewing a vendor contract should ensure which security clause is included to address data handling after contract termination?
- Intellectual property ownership terms
- Data return and destruction provisions (Correct answer)
- Service level agreement (SLA) for uptime
- Liability caps for business interruptions
Correct answer: Data return and destruction provisions
Data return and destruction provisions ensure that the vendor returns or securely destroys all organizational data once the contract ends, preventing residual data exposure.
Question 20: What does the concept of 'data sovereignty' mean in information governance?
- Users retain ownership of all personal data they create
- Data is subject to the laws of the country where it is physically stored or processed (Correct answer)
- The owner of a dataset has exclusive rights to monetize it
- Encrypted data cannot be subpoenaed by foreign governments
Correct answer: Data is subject to the laws of the country where it is physically stored or processed
Data sovereignty means that data is governed by the legal jurisdiction of the country where it resides or is processed, affecting cross-border transfer rules.
Question 21: Cost-shifting in e-discovery refers to the practice of:
- Moving e-discovery operations to lower-cost offshore service providers
- Allocating internal IT costs across business units that generate ESI
- Requiring junior associates to perform document review instead of senior partners
- A court ordering the requesting party to bear some or all of the responding party's discovery costs (Correct answer)
Correct answer: A court ordering the requesting party to bear some or all of the responding party's discovery costs
Cost-shifting occurs when a court, applying the proportionality analysis under FRCP Rule 26, orders the requesting party to bear some or all of the burden of the responding party's unusually expensive discovery obligations.
Question 22: The ARMA International Generally Accepted Recordkeeping Principles (GARP) include how many core principles?
- 12
- 8 (Correct answer)
- 6
- 10
Correct answer: 8
ARMA's GARP framework consists of 8 core principles: Accountability, Transparency, Integrity, Protection, Compliance, Availability, Retention, and Disposition.
Question 23: A company's Chief Compliance Officer (CCO) reports directly to the Board of Directors. This reporting structure is significant because it:
- Satisfies HIPAA's designated privacy officer requirement
- Eliminates the need for external audits
- Ensures compliance independence from business unit pressure (Correct answer)
- Reduces the cost of compliance operations
Correct answer: Ensures compliance independence from business unit pressure
A CCO reporting to the Board rather than operational management preserves independence and ensures compliance concerns reach the highest governance level without being filtered.
Question 24: Which security principle ensures that no single individual can complete a critical process alone, reducing fraud risk?
- Separation of duties (Correct answer)
- Need to know
- Defense in depth
- Least privilege
Correct answer: Separation of duties
Separation of duties requires that critical tasks be divided among multiple individuals, so no single person can both initiate and approve a transaction or action.
Question 25: What is the benefit of policy review and updates?
- Is optional
- Confuses employees
- Increases risks
- Keeps policies current (Correct answer)
Correct answer: Keeps policies current
Regular policy review and updates are essential in information governance to ensure that policies remain current, effective, and compliant with evolving legal, regulatory, and technological landscapes. Information environments and business needs are constantly changing, so outdated policies can lead to compliance gaps or inefficiencies. Periodic reviews allow organizations to adapt their governance framework to new challenges and opportunities, maintaining its relevance and efficacy.
Question 26: An organization receives a ransomware attack that encrypts all files on a shared drive. Which backup strategy would BEST minimize data loss?
- Daily incremental backups stored offline or in an isolated environment (Correct answer)
- Real-time replication to another folder on the same drive
- Monthly full backups stored in the cloud
- Weekly full backups stored on the same network
Correct answer: Daily incremental backups stored offline or in an isolated environment
Daily incremental backups stored offline or in an air-gapped environment ensure minimal data loss and prevent ransomware from encrypting backup copies.
Question 27: What does 'records appraisal' determine in an archival or records management context?
- The monetary insurance value of physical records
- The security classification level of sensitive records
- Whether records are authentic originals or copies
- The long-term historical, legal, fiscal, or administrative value of records to determine retention (Correct answer)
Correct answer: The long-term historical, legal, fiscal, or administrative value of records to determine retention
Records appraisal is the process of evaluating records to determine their value and how long they should be retained, balancing business, legal, and historical considerations.
Question 28: In a risk register, the 'inherent risk' rating represents risk:
- That cannot be mitigated under any circumstances
- Identified through penetration testing
- Before any controls are applied (Correct answer)
- After all controls have been applied
Correct answer: Before any controls are applied
Inherent risk is the raw or untreated risk level that exists before any controls or mitigations are applied.
Question 29: Spoliation of evidence in e-discovery refers to:
- The destruction, alteration, or failure to preserve evidence that should have been retained (Correct answer)
- The process of converting paper documents to electronic format
- The practice of redacting privileged information before production
- The deliberate encryption of records to prevent unauthorized access
Correct answer: The destruction, alteration, or failure to preserve evidence that should have been retained
Spoliation is the destruction, alteration, or failure to preserve evidence once a preservation obligation has attached, and can result in court sanctions including adverse inference instructions.
Question 30: When classifying information in an IG program, which factor is MOST important when determining security controls?
- The age of the information
- The size of the data set
- The file format of the document
- The sensitivity and criticality of the information (Correct answer)
Correct answer: The sensitivity and criticality of the information
Security controls in an IG program are driven by the sensitivity (confidentiality) and criticality (availability/integrity) of the information, not its format or size.
Question 31: Which statement BEST describes the relationship between Information Governance Professional certification and industry evolution?
- Certification requirements never change
- Requirements evolve periodically to reflect advances in knowledge and practice (Correct answer)
- Requirements become less stringent over time
- Changes only occur when government mandates them
Correct answer: Requirements evolve periodically to reflect advances in knowledge and practice
Certification requirements evolve to keep pace with professional and technological advances.
Question 32: What is the role of governance in risk management?
- Is unnecessary
- Only for IT
- Create confusion
- Set policies and oversight (Correct answer)
Correct answer: Set policies and oversight
Governance in risk management involves establishing the framework, policies, and oversight necessary to effectively manage risks across the organization. It sets the strategic direction, defines roles and responsibilities, and ensures that risk management activities are aligned with organizational objectives. Effective governance provides the structure and accountability needed for a robust and consistent approach to risk.
Question 33: A retention schedule assigns a seven-year retention period to financial records. When does the retention clock typically begin?
- The date the retention schedule was last updated
- The date the record was filed or closed (Correct answer)
- The date the record was created
- The fiscal year end in which the record was created
Correct answer: The date the record was filed or closed
Retention periods for most records begin when the record's active use concludes, typically upon filing or closure of the matter rather than at creation.
Question 34: Which technology helps prevent unauthorized access?
- Public sharing
- Open networks
- Access controls such as passwords (Correct answer)
- Weak passwords
Correct answer: Access controls such as passwords
Access controls, such as strong passwords, multi-factor authentication, and role-based access, are fundamental technologies that help prevent unauthorized access to systems and data. They ensure that only authenticated and authorized individuals can gain entry to specific resources. By verifying user identities and permissions, these controls act as a critical barrier against malicious actors and insider threats.
Question 35: What role does documentation play in compliance?
- Increases risks
- Evidence of policy adherence (Correct answer)
- Is unnecessary
- Slows processes
Correct answer: Evidence of policy adherence
Documentation plays a critical role in compliance by providing tangible evidence of an organization's adherence to policies, procedures, and regulatory requirements. It records decisions, processes, controls, and actions taken, demonstrating due diligence and accountability. In the event of an audit or legal inquiry, comprehensive documentation is essential to prove compliance and defend against potential liabilities.
Question 36: How does the IGP body of knowledge relate to daily professional practice?
- It only applies during exams
- It is theoretical with limited application
- It is only for academic research
- It provides the foundational framework guiding decision-making and standard practices (Correct answer)
Correct answer: It provides the foundational framework guiding decision-making and standard practices
The body of knowledge provides the framework guiding daily decision-making and practices.
Question 37: Which risk management approach is MOST effective for IGP professionals when evaluating potential workplace hazards?
- Proactive hazard identification and assessment (Correct answer)
- Delegating all safety decisions to management
- Relying solely on historical accident data
- Reactive analysis after incidents occur
Correct answer: Proactive hazard identification and assessment
Proactive hazard identification and assessment allows professionals to identify and mitigate risks before incidents occur.
Question 38: Why is continuous monitoring important?
- Slows response
- Increases risk
- Detect new risks promptly (Correct answer)
- Is optional
Correct answer: Detect new risks promptly
Continuous monitoring is important because the threat landscape and organizational environment are constantly evolving. It allows organizations to detect new risks, vulnerabilities, or changes in existing risk profiles promptly. By continuously observing systems, processes, and external factors, organizations can respond quickly to emerging threats, maintain security effectiveness, and ensure ongoing compliance.
Question 39: Which component of a compliance program is responsible for receiving and investigating reports of policy violations without fear of retaliation?
- Legal hold management
- Data stewardship committee
- Records retention schedule
- Whistleblower or hotline program (Correct answer)
Correct answer: Whistleblower or hotline program
A whistleblower or ethics hotline program provides a confidential channel for employees to report misconduct without fear of retaliation.
Question 40: Which standard provides a globally recognized framework specifically for information security management systems (ISMS)?
- ISO/IEC 27001 (Correct answer)
- NIST SP 800-53
- COBIT 5
- ARMA Generally Accepted Recordkeeping Principles
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS.
Question 41: In e-discovery terminology, a 'custodian' is best defined as:
- The court-appointed official responsible for maintaining case records
- A third-party vendor holding data on behalf of an organization
- The IT administrator responsible for backup tape management
- An individual who has possession, custody, or control over relevant ESI (Correct answer)
Correct answer: An individual who has possession, custody, or control over relevant ESI
A custodian is an individual who has possession, custody, or control over potentially relevant ESI, and is typically identified for legal hold notices and data collection.
Question 42: In an IG framework, a 'policy' differs from a 'procedure' primarily because a policy:
- Defines technical configurations for IT systems
- Describes step-by-step instructions for task completion
- Assigns specific roles to named individuals
- States the organization's intent and high-level rules (Correct answer)
Correct answer: States the organization's intent and high-level rules
Policies express organizational intent and mandatory rules, while procedures provide the step-by-step instructions for implementing those policies.
Question 43: A company's IG framework should address privacy requirements under which US federal law applicable to healthcare information?
- COPPA
- HIPAA (Correct answer)
- GLBA
- FERPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) governs the privacy and security of protected health information (PHI) and must be addressed in healthcare IG frameworks.
Question 44: How does the IGP body of knowledge relate to daily professional practice?
- It is theoretical with limited application
- It only applies during exams
- It provides the foundational framework guiding decision-making and standard practices (Correct answer)
- It is only for academic research
Correct answer: It provides the foundational framework guiding decision-making and standard practices
The body of knowledge provides the framework guiding daily decision-making and practices.
Question 45: Which term describes Electronically Stored Information as defined under the Federal Rules of Civil Procedure?
- Email messages archived by a third-party provider
- Only structured data held in enterprise databases
- Information created, stored, or transmitted in electronic form that may be subject to discovery (Correct answer)
- Any information stored on paper or electronic media
Correct answer: Information created, stored, or transmitted in electronic form that may be subject to discovery
ESI under the FRCP broadly includes any information created, stored, or transmitted in electronic form, encompassing emails, documents, databases, voicemails, and metadata.
Question 46: An information governance maturity model is primarily used to:
- Set quarterly sales goals for the compliance department
- Determine software licensing costs for records management tools
- Assess and benchmark the sophistication of an organization's IG program over time (Correct answer)
- Rank employees based on their IG knowledge
Correct answer: Assess and benchmark the sophistication of an organization's IG program over time
Maturity models provide a structured way to assess where an organization's IG program stands and chart a path for continuous improvement.
Question 47: What is the primary purpose of a Security Information and Event Management (SIEM) system?
- Automatically patch vulnerabilities on servers
- Aggregate and correlate security logs for threat detection (Correct answer)
- Manage user identity provisioning
- Encrypt emails sent between employees
Correct answer: Aggregate and correlate security logs for threat detection
SIEM systems collect, aggregate, and correlate security event logs from multiple sources to enable real-time threat detection and incident response.
Question 48: How should Information Governance Professional professionals handle procedures that have been updated or revised?
- Continue using the original method
- Only apply updates to new cases
- Wait for mandatory enforcement
- Review updates, complete required training, and implement revised procedures (Correct answer)
Correct answer: Review updates, complete required training, and implement revised procedures
Professionals must review changes, complete training, and implement revised procedures.
Question 49: A data subject requests deletion of their personal data under CCPA. Under which circumstance may the business lawfully refuse?
- The consumer did not provide opt-in consent originally
- The data is necessary to complete a transaction the consumer requested (Correct answer)
- The business employs fewer than 50 people
- The data is more than two years old
Correct answer: The data is necessary to complete a transaction the consumer requested
CCPA allows businesses to deny deletion requests when the data is necessary to complete a transaction the consumer requested or reasonably anticipated.
Question 50: How does information governance impact data privacy?
- Only for public data
- Protects personal and sensitive data (Correct answer)
- Has no impact
- Reduces data availability
Correct answer: Protects personal and sensitive data
Information governance (IG) provides the overarching framework of policies, processes, and controls for managing information assets. By establishing clear guidelines for data handling, storage, and access, IG ensures that personal and sensitive data is protected throughout its lifecycle. This proactive approach helps organizations comply with privacy regulations and mitigate the risks of data breaches or misuse.
Question 51: What is the primary purpose of an information governance framework?
- Manage information securely and effectively (Correct answer)
- Ignore compliance requirements
- Increase data redundancy
- To delete all data
Correct answer: Manage information securely and effectively
The primary purpose of an information governance (IG) framework is to manage an organization's information assets securely, effectively, and compliantly throughout their lifecycle. It establishes policies, processes, and controls to ensure information is accurate, accessible, protected, and retained or disposed of appropriately. This holistic approach maximizes information value while minimizing risks and costs.
Question 52: Which foundational principle is MOST important for success in Information Governance Professional?
- Maximizing financial returns
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maintaining minimum certification requirements
- Specializing in only one narrow area
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success requires continuous learning, ethical practice, and focus on quality outcomes.
Question 53: What is personally identifiable information (PII)?
- Information identifying individuals (Correct answer)
- Product specifications
- General company info
- Public data
Correct answer: Information identifying individuals
Personally identifiable information (PII) refers to any data that can be used to directly or indirectly identify an individual. Examples include names, addresses, social security numbers, email addresses, and biometric data. Protecting PII is a cornerstone of data privacy, as its compromise can lead to identity theft, fraud, or other personal harm.
Question 54: When a IGP professional encounters an unexpected result during a procedure, the FIRST action should be to:
- Report without preliminary assessment
- Continue and address it later
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
- Repeat the procedure immediately
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess unexpected results is critical for safety and quality.
Question 55: In an IG program, what is the primary purpose of a data map or data inventory?
- Catalog where personal and sensitive data is created, stored, used, and shared (Correct answer)
- Track software licensing compliance across the enterprise
- Document the geographic location of all company offices
- Monitor employee access to corporate email systems
Correct answer: Catalog where personal and sensitive data is created, stored, used, and shared
A data map catalogs the full lifecycle of data — where it originates, how it flows, where it is stored, and who accesses it — enabling effective governance and risk management.
Question 56: In risk management, the term 'residual risk' refers to:
- Risk identified but not yet assessed
- Risk that has been fully eliminated by controls
- Risk transferred to a third party
- Risk remaining after controls have been applied (Correct answer)
Correct answer: Risk remaining after controls have been applied
Residual risk is the level of risk that remains after risk treatment or controls have been implemented.
Question 57: What is 'pseudonymization' of personal data?
- Permanently deleting identifying information from a dataset
- Replacing identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information (Correct answer)
- Masking personal data when displayed on screen
- Encrypting personal data so only authorized parties can access it
Correct answer: Replacing identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information
Pseudonymization replaces direct identifiers with artificial ones, reducing privacy risk while allowing re-identification if the key is available, unlike anonymization which is irreversible.
Question 58: In electronic records management, what is 'format migration' intended to prevent?
- Loss of access to records due to obsolete file formats or technology (Correct answer)
- Unauthorized modification of official records
- Unauthorized access to archived records
- Duplication of records across multiple systems
Correct answer: Loss of access to records due to obsolete file formats or technology
Format migration converts records from obsolete or at-risk file formats to current ones to ensure long-term accessibility and usability as technology evolves.
Question 59: Which approach BEST supports continuous improvement of an IG framework over time?
- Delegating all IG improvement decisions to an external consultant
- Replacing the IG team annually to bring fresh perspectives
- Establishing ongoing monitoring, periodic audits, and a feedback loop that drives policy revisions (Correct answer)
- Implementing a one-time IG audit with no follow-up
Correct answer: Establishing ongoing monitoring, periodic audits, and a feedback loop that drives policy revisions
Continuous improvement requires regular audits, monitoring of compliance metrics, and a formal feedback process to update policies as regulations, technology, and business needs evolve.
Question 60: A 'heat map' in risk management visually plots risks according to:
- Threat actor sophistication vs. asset value
- Cost of mitigation vs. regulatory requirement
- Likelihood and potential impact (Correct answer)
- Data sensitivity vs. retention period
Correct answer: Likelihood and potential impact
A risk heat map plots risks on a two-axis grid of likelihood (probability) and impact (severity) to prioritize response.
Question 61: Which privacy-enhancing technique allows analysis of aggregate data trends without exposing individual records?
- Access control lists
- Data anonymization and aggregation (Correct answer)
- Full database encryption
- Digital watermarking
Correct answer: Data anonymization and aggregation
Anonymization and aggregation strip or obscure individual identifiers so that statistical analysis can occur without revealing personal information.
Question 62: HIPAA's Minimum Necessary Standard requires covered entities to:
- Encrypt all PHI at rest and in transit
- Retain medical records for a minimum of 10 years
- Limit PHI access and disclosure to the minimum needed for the intended purpose (Correct answer)
- Obtain written consent before any PHI disclosure
Correct answer: Limit PHI access and disclosure to the minimum needed for the intended purpose
The Minimum Necessary Standard limits access to and use of PHI to only what is needed to accomplish the intended purpose.
Question 63: What is the primary function of a Public Key Infrastructure (PKI)?
- Provide two-factor authentication for remote users
- Issue and manage digital certificates that bind public keys to identities (Correct answer)
- Scan email attachments for malware
- Manage firewall rules across the enterprise
Correct answer: Issue and manage digital certificates that bind public keys to identities
PKI is a framework that issues, manages, and revokes digital certificates that cryptographically bind a public key to an entity's identity.
Question 64: How does multi-factor authentication enhance security?
- Is optional
- Reduces security
- Only for admins
- Requires multiple verification methods (Correct answer)
Correct answer: Requires multiple verification methods
Multi-factor authentication (MFA) enhances security by requiring users to provide two or more different verification methods to prove their identity. This typically combines something the user knows (like a password), something they have (like a phone or token), and/or something they are (like a fingerprint). Even if one factor is compromised, the additional factors prevent unauthorized access, significantly strengthening account security.
Question 65: How are controls used in risk management?
- Ignore risks
- Increase risks
- Only for audits
- Reduce risk likelihood or impact (Correct answer)
Correct answer: Reduce risk likelihood or impact
Controls are integral to risk management as they are measures implemented to reduce the likelihood or impact of identified risks. These can be preventative (e.g., access controls to stop unauthorized access) or detective (e.g., monitoring systems to identify breaches). By applying appropriate controls, organizations can effectively manage and mitigate threats to their information assets and operations.
Question 66: Which framework provides a risk-based approach to managing cybersecurity that is widely used as a voluntary standard in the US?
- NIST Cybersecurity Framework (CSF) (Correct answer)
- PCI DSS
- ISO 27001
- COBIT 2019
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework provides a voluntary, risk-based framework organized around five functions (Identify, Protect, Detect, Respond, Recover) for managing cybersecurity risk.
Question 67: Which type of malware disguises itself as legitimate software but performs malicious actions when executed?
- Worm
- Rootkit
- Adware
- Trojan horse (Correct answer)
Correct answer: Trojan horse
A Trojan horse masquerades as benign or useful software while secretly performing malicious functions such as opening backdoors or stealing credentials.
Question 68: Chain of custody documentation in e-discovery is primarily maintained to:
- Reduce the cost of document review by tracking reviewer hours
- Identify which custodians are most likely to have relevant information
- Establish the business value of the information collected
- Demonstrate that evidence was handled properly and has not been altered since collection (Correct answer)
Correct answer: Demonstrate that evidence was handled properly and has not been altered since collection
Chain of custody documentation records who collected, handled, and transferred ESI at each step to demonstrate the integrity of evidence and that it has not been tampered with or altered.
Question 69: Which element distinguishes a 'standard' from a 'policy' in an IG framework hierarchy?
- Standards are written by vendors; policies are written internally
- Standards apply only to IT systems while policies apply to all information
- Standards provide specific, measurable requirements that support policy compliance (Correct answer)
- Standards are optional; policies are mandatory
Correct answer: Standards provide specific, measurable requirements that support policy compliance
Standards define specific, quantifiable requirements (e.g., password length minimums) that operationalize policies, making compliance measurable and auditable.
Question 70: Under HIPAA, what is the minimum necessary standard?
- Covered entities must retain PHI for a minimum of six years
- Covered entities must limit PHI use and disclosure to the minimum necessary for the intended purpose (Correct answer)
- Covered entities must encrypt all PHI at rest
- Covered entities must obtain written consent before any PHI disclosure
Correct answer: Covered entities must limit PHI use and disclosure to the minimum necessary for the intended purpose
The HIPAA minimum necessary standard requires covered entities to make reasonable efforts to use, disclose, or request only the minimum amount of PHI needed to accomplish the intended purpose.
Question 71: Under NIST SP 800-53, which control family addresses audit and accountability requirements?
- Audit and Accountability (AU) (Correct answer)
- Access Control (AC)
- Incident Response (IR)
- System and Communications Protection (SC)
Correct answer: Audit and Accountability (AU)
NIST SP 800-53's Audit and Accountability (AU) control family covers requirements for creating, protecting, and retaining audit records.
Question 72: Which of the following is a key characteristic of an effective IG policy lifecycle?
- Policies are distributed only to senior management
- Policies are created solely by IT without business input
- Policies undergo regular review and updates to reflect regulatory and business changes (Correct answer)
- Policies are written once and never revised
Correct answer: Policies undergo regular review and updates to reflect regulatory and business changes
Effective IG policies must be periodically reviewed and updated to remain aligned with evolving laws, regulations, business needs, and technology changes.
Question 73: What is the primary purpose of an IG policy exception process?
- To allow employees to permanently opt out of all IG requirements
- To provide a controlled, documented mechanism for temporarily deviating from a policy when business needs require it (Correct answer)
- To automatically exempt executives from compliance obligations
- To replace the policy with a more lenient standard
Correct answer: To provide a controlled, documented mechanism for temporarily deviating from a policy when business needs require it
An exception process allows documented, risk-assessed deviations from policy when strict adherence is impractical, maintaining governance while accommodating legitimate business needs.
Question 74: Which approach is MOST important for IGP professionals when applying technical procedures?
- Applying the same technique without variation
- Adhering to established protocols while adapting to specific conditions (Correct answer)
- Following personal shortcuts
- Using the fastest method regardless of standards
Correct answer: Adhering to established protocols while adapting to specific conditions
Technical procedures require adherence to protocols with professional judgment for adaptation.
Question 75: Which of the following BEST describes the purpose of a data classification policy?
- To organize files into folders on a shared drive
- To define the hierarchy of employees who can delete records
- To assign sensitivity levels to information to guide handling and protection requirements (Correct answer)
- To set performance benchmarks for data processing systems
Correct answer: To assign sensitivity levels to information to guide handling and protection requirements
Data classification policies assign sensitivity tiers (e.g., Public, Internal, Confidential, Restricted) to information so appropriate controls can be applied.
Question 76: Which regulatory requirement is UNIVERSAL across all Information Governance Professional practice settings?
- Using specific proprietary software
- Working exclusively during business hours
- Maintaining current certification and continuing education (Correct answer)
- Limiting services to local jurisdictions
Correct answer: Maintaining current certification and continuing education
Maintaining current certification and continuing education is a universal regulatory requirement.
Question 77: Which of the following would be considered a 'defensible disposition' practice in IG?
- Destroying records according to documented retention schedules after confirming no legal holds apply (Correct answer)
- Randomly deleting files when storage is running low
- Allowing individual employees to decide when to delete their own emails
- Retaining all records indefinitely to avoid any potential legal risk
Correct answer: Destroying records according to documented retention schedules after confirming no legal holds apply
Defensible disposition requires systematic destruction based on approved retention schedules, with legal hold checks and documented authorization to withstand legal scrutiny.
Question 78: Which statement BEST describes the relationship between Information Governance Professional certification and industry evolution?
- Certification requirements never change
- Changes only occur when government mandates them
- Requirements become less stringent over time
- Requirements evolve periodically to reflect advances in knowledge and practice (Correct answer)
Correct answer: Requirements evolve periodically to reflect advances in knowledge and practice
Certification requirements evolve to keep pace with professional and technological advances.
Question 79: A company discovers that a third-party vendor has been improperly handling customer PII. Under a risk management framework, this is best classified as:
- Third-party/supply chain risk (Correct answer)
- Operational risk
- Reputational risk
- Strategic risk
Correct answer: Third-party/supply chain risk
Risks arising from vendor or supplier relationships are classified as third-party or supply chain risk in standard risk frameworks.
Question 80: Which of the following is the BEST example of a preventive compliance control?
- Requiring dual authorization for large financial transactions (Correct answer)
- Reviewing audit logs after a data breach
- Conducting a root cause analysis after a policy violation
- Generating monthly compliance status reports
Correct answer: Requiring dual authorization for large financial transactions
Preventive controls stop violations before they occur; dual authorization prevents unauthorized transactions from being processed in the first place.
Question 81: A company conducts a Business Impact Analysis (BIA). What does the Recovery Time Objective (RTO) define?
- The total cost of recovering from a major incident
- The minimum backup frequency required for critical systems
- The maximum amount of data loss measured in time that is acceptable
- The maximum acceptable time to restore a system after a disruption (Correct answer)
Correct answer: The maximum acceptable time to restore a system after a disruption
RTO defines the maximum tolerable duration of downtime for a business process or system before the disruption causes unacceptable harm to the organization.
Question 82: Which of the following BEST describes 'information governance' as distinct from 'records management'?
- Information governance is limited to legal and compliance departments
- Records management is a newer discipline that has replaced information governance
- Information governance focuses only on physical documents while records management covers digital files
- Information governance is a broader strategic framework that encompasses records management along with data governance, privacy, security, and compliance (Correct answer)
Correct answer: Information governance is a broader strategic framework that encompasses records management along with data governance, privacy, security, and compliance
IG is a holistic, strategic discipline that encompasses records management and extends to include data governance, privacy, security, compliance, and risk management across all information assets.
Question 83: The concept of 'information stewardship' in IG frameworks refers to:
- Designated individuals responsible for overseeing the quality and governance of specific data domains (Correct answer)
- Automated software that classifies documents without human intervention
- The legal department's control over litigation records
- The CIO's authority to purchase information technology
Correct answer: Designated individuals responsible for overseeing the quality and governance of specific data domains
Information stewards are accountable business representatives who oversee the accuracy, accessibility, and appropriate use of information within their domain.
Question 84: An organization in California collects personal data from 80,000 consumers annually. Under CCPA, which obligation applies?
- The organization must register with the California Attorney General
- The organization must provide notice, opt-out rights, and a privacy policy meeting CCPA requirements (Correct answer)
- The organization is exempt because it has fewer than 100,000 consumers
- The organization must obtain opt-in consent before collecting any data
Correct answer: The organization must provide notice, opt-out rights, and a privacy policy meeting CCPA requirements
A business that buys, sells, receives, or shares the personal information of 100,000 or more consumers or households annually is subject to CCPA—80,000 alone may not trigger the threshold but combined factors could, and notice/opt-out requirements apply when thresholds are met.
Question 85: Which factor MOST significantly affects the quality of technical outcomes in IGP practice?
- The time of day
- Speed of procedure completion
- The brand of equipment
- The practitioner's training, preparation, and attention to detail (Correct answer)
Correct answer: The practitioner's training, preparation, and attention to detail
Quality depends primarily on training, preparation, and attention to detail.
Question 86: What distinguishes a Information Governance Professional certified professional from a non-certified practitioner?
- Certified professionals only work in larger organizations
- There is no meaningful difference
- Certified professionals always have more experience
- Certification validates competency through standardized assessment against benchmarks (Correct answer)
Correct answer: Certification validates competency through standardized assessment against benchmarks
Certification provides objective validation of competency through standardized assessment.
Question 87: Under GDPR, which IG principle requires that personal data be kept only as long as necessary for its stated purpose?
- Integrity and confidentiality
- Storage limitation (Correct answer)
- Purpose limitation
- Data minimization
Correct answer: Storage limitation
GDPR's storage limitation principle requires that personal data not be kept longer than necessary for the purposes for which it was collected.
Question 88: Under the NIST Risk Management Framework (RMF), which step involves continuously tracking security controls over time?
- Authorize
- Implement
- Assess
- Monitor (Correct answer)
Correct answer: Monitor
The Monitor step in the NIST RMF involves ongoing assessment of security controls to detect changes that may affect risk posture.
Question 89: Under the EU-US Data Privacy Framework, what must US organizations do to lawfully receive personal data from the EU?
- Establish a legal entity within the EU
- Self-certify with the US Department of Commerce and commit to framework principles (Correct answer)
- Sign standard contractual clauses with every EU data exporter
- Obtain explicit consent from every EU data subject
Correct answer: Self-certify with the US Department of Commerce and commit to framework principles
Under the EU-US Data Privacy Framework, US organizations must self-certify their compliance with the framework's principles to the US Department of Commerce to lawfully receive EU personal data.
Question 90: Which governance body is typically responsible for approving enterprise-level IG policies?
- IT Help Desk
- Executive leadership or a steering committee (Correct answer)
- External auditors
- Individual department managers
Correct answer: Executive leadership or a steering committee
Enterprise IG policies require approval at the executive or steering committee level to ensure enterprise-wide authority and cross-departmental compliance.
Question 91: What does a Records Management Program 'vital records' designation indicate?
- Records that are used daily by employees
- Records essential for an organization to resume critical functions after a disaster (Correct answer)
- Records with the longest retention periods
- Records that require executive-level approval to access
Correct answer: Records essential for an organization to resume critical functions after a disaster
Vital records are those deemed essential for an organization to reconstruct its operations and meet its obligations after an emergency, making their protection a business continuity priority.
Question 92: When an organization undergoes a merger, which IG activity is MOST urgent to perform regarding information assets?
- Conducting an information inventory and gap analysis of both organizations' IG frameworks (Correct answer)
- Transferring all IT systems to the acquiring company's platform within 30 days
- Suspending all IG policies until the merger is complete
- Immediately deleting all records from the acquired company
Correct answer: Conducting an information inventory and gap analysis of both organizations' IG frameworks
A merger requires an information inventory and gap analysis to identify IG framework differences, redundancies, and risks before integration decisions are made.
Question 93: In IGP practice, what happens when regulations are updated?
- Professionals must update knowledge and practices to meet new requirements (Correct answer)
- Previous certifications are revoked
- Existing professionals are grandfathered in
- Changes apply only to new professionals
Correct answer: Professionals must update knowledge and practices to meet new requirements
All professionals must update their knowledge and practices when regulations change.
Question 94: What distinguishes a Information Governance Professional certified professional from a non-certified practitioner?
- Certification validates competency through standardized assessment against benchmarks (Correct answer)
- Certified professionals always have more experience
- Certified professionals only work in larger organizations
- There is no meaningful difference
Correct answer: Certification validates competency through standardized assessment against benchmarks
Certification provides objective validation of competency through standardized assessment.
Question 95: In Information Governance Professional practice, what is the CORRECT sequence when performing a technical procedure?
- Execute, then plan and review
- Plan, prepare, execute, verify, and document (Correct answer)
- Execute immediately and document only if issues arise
- Document, execute, then plan
Correct answer: Plan, prepare, execute, verify, and document
The correct sequence follows: plan, prepare, execute, verify, and document.
Question 96: In records management, what distinguishes a 'record' from a 'non-record'?
- Records require encryption; non-records do not
- Records are stored on-premises; non-records are in the cloud
- Records are digital; non-records are physical
- Records document organizational activities and have ongoing value; non-records are transitory (Correct answer)
Correct answer: Records document organizational activities and have ongoing value; non-records are transitory
Records are documents that provide evidence of organizational activities and have ongoing business, legal, or historical value, distinguishing them from transitory non-records like draft copies.
Question 97: Which ISO standard specifically addresses records management systems and their requirements?
- ISO 15489 (Correct answer)
- ISO 31000
- ISO 27001
- ISO 9001
Correct answer: ISO 15489
ISO 15489 is the international standard specifically dedicated to records management, covering principles and implementation guidelines.
Question 98: A gap analysis in IG framework development is used to:
- Identify differences between the current state and desired IG program maturity (Correct answer)
- Train employees on records management procedures
- Audit vendor compliance with data sharing agreements
- Calculate the cost of IG technology investments
Correct answer: Identify differences between the current state and desired IG program maturity
A gap analysis compares the organization's current IG capabilities and practices against its desired or required state to prioritize improvements.
Question 99: In Information Governance Professional, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To ensure personnel can respond effectively in emergencies (Correct answer)
- To satisfy insurance requirements only
- To evaluate employee performance reviews
- To reduce daily workload
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies.
Question 100: Metadata in ESI production is significant in e-discovery because it:
- Automatically determines the relevance of a document to the litigation
- Provides context such as creation date, author, modification history, and file path that can be critical evidence (Correct answer)
- Reduces the file size of produced documents for faster transmission
- Replaces the need for custodian depositions about document origins
Correct answer: Provides context such as creation date, author, modification history, and file path that can be critical evidence
Metadata embedded in ESI provides critical context including who created or modified a document, when it was accessed, and where it was stored, all of which can serve as important evidence in litigation.
Question 101: Which scenario BEST illustrates a failure of IG policy enforcement?
- The IT team upgrades the records management system during off-hours
- A manager approves deletion of records still under a legal hold (Correct answer)
- Legal counsel reviews contracts before they are signed
- An employee requests access to a restricted database and is denied
Correct answer: A manager approves deletion of records still under a legal hold
Deleting records subject to a legal hold violates IG policy and can result in spoliation sanctions, making it a clear enforcement failure.
Information Governance Professional (IGP) Exam
The IGP certification validates an individual's knowledge and skills in information governance, encompassing legal, regulatory, and business requirements for information management.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds