Information Governance Professional (IGP) Exam — Questions and Answers
Question 1: In IGP practice, what happens when regulations are updated?
- Previous certifications are revoked
- Existing professionals are grandfathered in
- Changes apply only to new professionals
- Professionals must update knowledge and practices to meet new requirements (Correct answer)
Correct answer: Professionals must update knowledge and practices to meet new requirements
All professionals must update their knowledge and practices when regulations change.
Question 2: What is the primary purpose of an IG policy exception process?
- To replace the policy with a more lenient standard
- To provide a controlled, documented mechanism for temporarily deviating from a policy when business needs require it (Correct answer)
- To automatically exempt executives from compliance obligations
- To allow employees to permanently opt out of all IG requirements
Correct answer: To provide a controlled, documented mechanism for temporarily deviating from a policy when business needs require it
An exception process allows documented, risk-assessed deviations from policy when strict adherence is impractical, maintaining governance while accommodating legitimate business needs.
Question 3: Which cloud deployment model provides dedicated infrastructure for a single organization, offering the highest level of control and security?
- Private cloud (Correct answer)
- Hybrid cloud
- Public cloud
- Community cloud
Correct answer: Private cloud
A private cloud provides cloud infrastructure exclusively for one organization, giving maximum control over security configurations and data isolation.
Question 4: Which policy element defines the consequences for employees who violate IG requirements?
- Scope statement
- Glossary of terms
- Purpose and objectives section
- Enforcement and sanctions clause (Correct answer)
Correct answer: Enforcement and sanctions clause
The enforcement and sanctions clause specifies disciplinary actions that may result from policy violations, making the policy credible and actionable.
Question 5: In the context of IG frameworks, 'accountability' means that:
- All employees share equal responsibility for all information assets
- Accountability is distributed equally across all departments
- A senior executive or designated officer is responsible for the IG program and its outcomes (Correct answer)
- Only IT staff are accountable for data security incidents
Correct answer: A senior executive or designated officer is responsible for the IG program and its outcomes
Accountability requires that a senior executive or designated officer take ownership of the IG program, ensuring it is resourced, enforced, and aligned with organizational goals.
Question 6: A Chief Information Governance Officer (CIGO) is MOST responsible for:
- Directly managing individual employee compliance with IT security policies
- Overseeing the enterprise IG program, ensuring alignment with strategy, and driving policy adoption across business units (Correct answer)
- Managing the organization's IT infrastructure and helpdesk
- Conducting financial audits of the IG department's budget
Correct answer: Overseeing the enterprise IG program, ensuring alignment with strategy, and driving policy adoption across business units
The CIGO provides strategic leadership for the enterprise IG program, aligning IG initiatives with organizational objectives and driving cross-functional adoption.
Question 7: An employee intentionally leaks confidential corporate data to a competitor. This is an example of:
- External threat
- Systemic risk
- Insider threat (Correct answer)
- Residual risk
Correct answer: Insider threat
An insider threat involves a current or former employee, contractor, or partner who misuses authorized access to harm the organization.
Question 8: What role does risk management play in information governance?
- Identify and mitigate risks (Correct answer)
- Increase risks
- Only for audits
- Ignore risks
Correct answer: Identify and mitigate risks
Risk management plays a fundamental role in information governance by systematically identifying, assessing, and mitigating potential risks associated with an organization's information assets. This includes risks related to data breaches, non-compliance, data loss, and unauthorized access. By proactively managing these risks, information governance helps protect the organization's reputation, financial stability, and legal standing.
Question 9: Which documentation practice BEST demonstrates regulatory compliance for IGP certified professionals?
- Relying on memory for routine procedures
- Keeping informal handwritten notes
- Maintaining organized, dated, and signed records of all activities (Correct answer)
- Filing documents only when audited
Correct answer: Maintaining organized, dated, and signed records of all activities
Organized, dated, and signed records demonstrate systematic regulatory compliance.
Question 10: Which foundational principle is MOST important for success in Information Governance Professional?
- Maintaining minimum certification requirements
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Specializing in only one narrow area
- Maximizing financial returns
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success requires continuous learning, ethical practice, and focus on quality outcomes.
Question 11: Which compliance framework is specifically designed to protect cardholder data for organizations that process credit card transactions?
- SOX
- ISO 27001
- PCI DSS (Correct answer)
- HIPAA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) mandates security controls for any organization that stores, processes, or transmits cardholder data.
Question 12: Which type of malware disguises itself as legitimate software but performs malicious actions when executed?
- Adware
- Rootkit
- Worm
- Trojan horse (Correct answer)
Correct answer: Trojan horse
A Trojan horse masquerades as benign or useful software while secretly performing malicious functions such as opening backdoors or stealing credentials.
Question 13: An IGP professional reviewing a vendor contract should ensure which security clause is included to address data handling after contract termination?
- Intellectual property ownership terms
- Service level agreement (SLA) for uptime
- Liability caps for business interruptions
- Data return and destruction provisions (Correct answer)
Correct answer: Data return and destruction provisions
Data return and destruction provisions ensure that the vendor returns or securely destroys all organizational data once the contract ends, preventing residual data exposure.
Question 14: Which authentication method is considered MOST secure for remote access to sensitive systems?
- Multi-factor authentication combining something you know, have, and are (Correct answer)
- Certificate-based authentication alone
- Single-factor authentication with a strong password
- Biometric authentication alone
Correct answer: Multi-factor authentication combining something you know, have, and are
Multi-factor authentication combining knowledge, possession, and inherence factors is most secure because compromising any single factor is insufficient for unauthorized access.
Question 15: Under FRCP Rule 37(e), a court may impose sanctions for failure to preserve ESI only if:
- The party who lost ESI fails to pay the opposing party's legal fees voluntarily
- ESI that should have been preserved is lost because a party failed to take reasonable steps and the ESI cannot be restored (Correct answer)
- The opposing party files a motion within 30 days of discovering the loss
- Any ESI relevant to the case is lost, regardless of the reason
Correct answer: ESI that should have been preserved is lost because a party failed to take reasonable steps and the ESI cannot be restored
FRCP Rule 37(e) allows sanctions only when ESI that should have been preserved under a litigation hold is lost due to a party's failure to take reasonable steps, and the ESI cannot be restored or replaced through additional discovery.
Question 16: A company stores customer PII in a database. Which technique replaces sensitive values with non-sensitive placeholders while preserving referential integrity?
- Redaction
- Hashing
- Encryption
- Tokenization (Correct answer)
Correct answer: Tokenization
Tokenization substitutes sensitive data values with non-sensitive tokens that can reference the original data, preserving system functionality without exposing PII.
Question 17: What role does antivirus software play?
- Install malware
- Ignore threats
- Delete important files
- Detect and remove malware (Correct answer)
Correct answer: Detect and remove malware
Antivirus software plays a critical role in information security by detecting, preventing, and removing malicious software (malware) such as viruses, worms, and Trojans. It scans files and systems for known threats and suspicious behavior, protecting computers and networks from infection. This helps maintain the integrity and availability of data and systems, preventing data loss or compromise.
Question 18: What is the PRIMARY reason for regulatory compliance in the Information Governance Professional profession?
- To create additional paperwork
- To protect public safety, ensure quality, and maintain professional integrity (Correct answer)
- To justify higher service fees
- To avoid penalties and fines only
Correct answer: To protect public safety, ensure quality, and maintain professional integrity
Regulatory compliance protects public safety, ensures quality, and maintains professional integrity.
Question 19: How should organizations enforce information governance policies?
- Only punish violations
- Training and consistent application (Correct answer)
- Ignore policies
- Allow exceptions freely
Correct answer: Training and consistent application
Organizations should enforce information governance policies through a combination of comprehensive training and consistent application across all departments and employees. Training ensures that everyone understands their responsibilities and the importance of the policies. Consistent application, supported by monitoring and accountability, embeds these practices into the organizational culture, making compliance a routine part of daily operations rather than an exception.
Question 20: In an IG framework, a 'policy' differs from a 'procedure' primarily because a policy:
- Assigns specific roles to named individuals
- Defines technical configurations for IT systems
- Describes step-by-step instructions for task completion
- States the organization's intent and high-level rules (Correct answer)
Correct answer: States the organization's intent and high-level rules
Policies express organizational intent and mandatory rules, while procedures provide the step-by-step instructions for implementing those policies.
Question 21: Which technology helps prevent unauthorized access?
- Access controls such as passwords (Correct answer)
- Weak passwords
- Open networks
- Public sharing
Correct answer: Access controls such as passwords
Access controls, such as strong passwords, multi-factor authentication, and role-based access, are fundamental technologies that help prevent unauthorized access to systems and data. They ensure that only authenticated and authorized individuals can gain entry to specific resources. By verifying user identities and permissions, these controls act as a critical barrier against malicious actors and insider threats.
Question 22: Which statement BEST describes the relationship between Information Governance Professional certification and industry evolution?
- Certification requirements never change
- Requirements evolve periodically to reflect advances in knowledge and practice (Correct answer)
- Requirements become less stringent over time
- Changes only occur when government mandates them
Correct answer: Requirements evolve periodically to reflect advances in knowledge and practice
Certification requirements evolve to keep pace with professional and technological advances.
Question 23: How does the IGP body of knowledge relate to daily professional practice?
- It only applies during exams
- It is theoretical with limited application
- It provides the foundational framework guiding decision-making and standard practices (Correct answer)
- It is only for academic research
Correct answer: It provides the foundational framework guiding decision-making and standard practices
The body of knowledge provides the framework guiding daily decision-making and practices.
Question 24: Which encryption standard is currently recommended by NIST for protecting sensitive US government data at rest?
- 3DES with 168-bit keys
- RC4 with 128-bit keys
- AES-256 (Correct answer)
- Blowfish with 256-bit keys
Correct answer: AES-256
NIST recommends AES-256 for protecting sensitive government data at rest, as 3DES is deprecated and RC4/Blowfish are not approved for federal use.
Question 25: When a IGP professional encounters an unexpected result during a procedure, the FIRST action should be to:
- Repeat the procedure immediately
- Report without preliminary assessment
- Continue and address it later
- Stop, assess the situation, and determine whether to proceed or seek guidance (Correct answer)
Correct answer: Stop, assess the situation, and determine whether to proceed or seek guidance
Stopping to assess unexpected results is critical for safety and quality.
Question 26: What is the PRIMARY reason for regulatory compliance in the Information Governance Professional profession?
- To create additional paperwork
- To justify higher service fees
- To protect public safety, ensure quality, and maintain professional integrity (Correct answer)
- To avoid penalties and fines only
Correct answer: To protect public safety, ensure quality, and maintain professional integrity
Regulatory compliance protects public safety, ensures quality, and maintains professional integrity.
Question 27: Which of the following is the BEST example of a preventive compliance control?
- Generating monthly compliance status reports
- Requiring dual authorization for large financial transactions (Correct answer)
- Reviewing audit logs after a data breach
- Conducting a root cause analysis after a policy violation
Correct answer: Requiring dual authorization for large financial transactions
Preventive controls stop violations before they occur; dual authorization prevents unauthorized transactions from being processed in the first place.
Question 28: Which statement BEST describes the relationship between Information Governance Professional certification and industry evolution?
- Certification requirements never change
- Requirements become less stringent over time
- Requirements evolve periodically to reflect advances in knowledge and practice (Correct answer)
- Changes only occur when government mandates them
Correct answer: Requirements evolve periodically to reflect advances in knowledge and practice
Certification requirements evolve to keep pace with professional and technological advances.
Question 29: What is the significance of 'chain of custody' documentation for records in legal proceedings?
- It establishes that records have been controlled and preserved without unauthorized alteration (Correct answer)
- It confirms records were stored in an approved government facility
- It proves the records were created by a licensed professional
- It demonstrates the records have been independently audited
Correct answer: It establishes that records have been controlled and preserved without unauthorized alteration
Chain of custody documentation tracks who had possession of records and what was done with them, establishing that the records were not tampered with and are admissible as evidence.
Question 30: Under the GDPR, what right allows individuals to request that their personal data be erased?
- Right to restriction of processing
- Right to erasure (right to be forgotten) (Correct answer)
- Right to data portability
- Right of access
Correct answer: Right to erasure (right to be forgotten)
Article 17 of the GDPR grants individuals the right to erasure, allowing them to request deletion of their personal data under specific circumstances.
Question 31: Under Sarbanes-Oxley (SOX), what is the retention requirement for audit workpapers?
- 10 years
- 7 years (Correct answer)
- 3 years
- 5 years
Correct answer: 7 years
SOX Section 802 requires that audit and review workpapers be retained for seven years from the end of the fiscal period covered by the audit.
Question 32: Which records management principle holds that records of the same origin should not be mixed with records from other origins?
- Chain of custody
- Original order
- Authenticity
- Provenance (respect des fonds) (Correct answer)
Correct answer: Provenance (respect des fonds)
Provenance, or respect des fonds, is the archival principle that records from one creator should be kept separate from those of another creator to preserve their context and meaning.
Question 33: A privilege log in e-discovery is used to:
- Track the number of documents reviewed per day by each attorney
- Record the login credentials for e-discovery review platforms
- Identify and describe documents withheld from production based on attorney-client privilege or work product doctrine (Correct answer)
- List the names of all custodians who received a legal hold notice
Correct answer: Identify and describe documents withheld from production based on attorney-client privilege or work product doctrine
A privilege log itemizes documents withheld from production, describing each document's date, author, recipients, and basis for the privilege claim without revealing privileged content itself.
Question 34: Global deduplication in e-discovery processing eliminates:
- Documents that are irrelevant to the litigation after attorney review
- Documents that have been reviewed by more than one attorney
- All email threads keeping only the most recent message in a chain
- Identical documents across the entire document collection regardless of which custodian possessed them (Correct answer)
Correct answer: Identical documents across the entire document collection regardless of which custodian possessed them
Global deduplication removes exact duplicate documents across the entire collection, reducing review volume by eliminating documents that multiple custodians received, as opposed to per-custodian deduplication.
Question 35: Why is stakeholder engagement important in governance?
- Ensures policy relevance and support (Correct answer)
- Is unnecessary
- Slows decision-making
- Only for legal teams
Correct answer: Ensures policy relevance and support
Stakeholder engagement is crucial in information governance because it ensures that policies are relevant, practical, and receive widespread support across the organization. By involving representatives from various departments—such as legal, IT, HR, and business units—policies can be developed that address diverse needs and perspectives. This collaborative approach fosters buy-in and makes the implementation of governance initiatives more successful.
Question 36: A retention schedule assigns a seven-year retention period to financial records. When does the retention clock typically begin?
- The fiscal year end in which the record was created
- The date the record was created
- The date the retention schedule was last updated
- The date the record was filed or closed (Correct answer)
Correct answer: The date the record was filed or closed
Retention periods for most records begin when the record's active use concludes, typically upon filing or closure of the matter rather than at creation.
Question 37: A gap analysis in IG framework development is used to:
- Audit vendor compliance with data sharing agreements
- Train employees on records management procedures
- Calculate the cost of IG technology investments
- Identify differences between the current state and desired IG program maturity (Correct answer)
Correct answer: Identify differences between the current state and desired IG program maturity
A gap analysis compares the organization's current IG capabilities and practices against its desired or required state to prioritize improvements.
Question 38: Which governance body is typically responsible for approving enterprise-level IG policies?
- Individual department managers
- IT Help Desk
- External auditors
- Executive leadership or a steering committee (Correct answer)
Correct answer: Executive leadership or a steering committee
Enterprise IG policies require approval at the executive or steering committee level to ensure enterprise-wide authority and cross-departmental compliance.
Question 39: What distinguishes a Information Governance Professional certified professional from a non-certified practitioner?
- Certified professionals only work in larger organizations
- Certified professionals always have more experience
- There is no meaningful difference
- Certification validates competency through standardized assessment against benchmarks (Correct answer)
Correct answer: Certification validates competency through standardized assessment against benchmarks
Certification provides objective validation of competency through standardized assessment.
Question 40: Which of the following would be considered a 'defensible disposition' practice in IG?
- Allowing individual employees to decide when to delete their own emails
- Destroying records according to documented retention schedules after confirming no legal holds apply (Correct answer)
- Retaining all records indefinitely to avoid any potential legal risk
- Randomly deleting files when storage is running low
Correct answer: Destroying records according to documented retention schedules after confirming no legal holds apply
Defensible disposition requires systematic destruction based on approved retention schedules, with legal hold checks and documented authorization to withstand legal scrutiny.
Question 41: Why is security awareness training important?
- Increases risk
- Educates users on threats (Correct answer)
- Is unnecessary
- Only for IT staff
Correct answer: Educates users on threats
Security awareness training is vital because it educates employees about various cyber threats like phishing, malware, and social engineering. By understanding these risks and best practices, users become a crucial first line of defense, significantly reducing the likelihood of human error leading to a security incident.
Question 42: Which of the following BEST describes 'information governance' as distinct from 'records management'?
- Records management is a newer discipline that has replaced information governance
- Information governance is limited to legal and compliance departments
- Information governance is a broader strategic framework that encompasses records management along with data governance, privacy, security, and compliance (Correct answer)
- Information governance focuses only on physical documents while records management covers digital files
Correct answer: Information governance is a broader strategic framework that encompasses records management along with data governance, privacy, security, and compliance
IG is a holistic, strategic discipline that encompasses records management and extends to include data governance, privacy, security, compliance, and risk management across all information assets.
Question 43: What is the role of access controls?
- Open access
- Not important
- Limit access to authorized users (Correct answer)
- Only for IT staff
Correct answer: Limit access to authorized users
The role of access controls is to restrict and manage who can view, modify, or delete specific information or systems. By implementing mechanisms like passwords, multi-factor authentication, and role-based access, organizations ensure that only authorized users have appropriate access. This is a fundamental security measure to protect sensitive data from unauthorized access and maintain its confidentiality and integrity.
Question 44: A data protection impact assessment (DPIA) under GDPR is mandatory when processing is likely to result in:
- Processing by any company with more than 250 employees
- High risk to the rights and freedoms of natural persons (Correct answer)
- Any collection of personal data from EU residents
- Cross-border transfers to countries with adequacy decisions
Correct answer: High risk to the rights and freedoms of natural persons
GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to the rights and freedoms of individuals.
Question 45: Which approach BEST supports continuous improvement of an IG framework over time?
- Implementing a one-time IG audit with no follow-up
- Establishing ongoing monitoring, periodic audits, and a feedback loop that drives policy revisions (Correct answer)
- Replacing the IG team annually to bring fresh perspectives
- Delegating all IG improvement decisions to an external consultant
Correct answer: Establishing ongoing monitoring, periodic audits, and a feedback loop that drives policy revisions
Continuous improvement requires regular audits, monitoring of compliance metrics, and a formal feedback process to update policies as regulations, technology, and business needs evolve.
Question 46: When classifying information in an IG program, which factor is MOST important when determining security controls?
- The size of the data set
- The file format of the document
- The sensitivity and criticality of the information (Correct answer)
- The age of the information
Correct answer: The sensitivity and criticality of the information
Security controls in an IG program are driven by the sensitivity (confidentiality) and criticality (availability/integrity) of the information, not its format or size.
Question 47: Why is continuous monitoring important?
- Increases risk
- Is optional
- Slows response
- Detect new risks promptly (Correct answer)
Correct answer: Detect new risks promptly
Continuous monitoring is important because the threat landscape and organizational environment are constantly evolving. It allows organizations to detect new risks, vulnerabilities, or changes in existing risk profiles promptly. By continuously observing systems, processes, and external factors, organizations can respond quickly to emerging threats, maintain security effectiveness, and ensure ongoing compliance.
Question 48: An organization wants to ensure that only authorized users access specific cloud resources. Which control best enforces this at the identity layer?
- Network firewall rules
- Role-Based Access Control (RBAC) (Correct answer)
- Intrusion detection signatures
- SSL/TLS certificates
Correct answer: Role-Based Access Control (RBAC)
RBAC restricts cloud resource access based on users' assigned roles, ensuring only authorized individuals can access specific resources.
Question 49: Which term describes the process of converting paper records to electronic format while ensuring authenticity and reliability?
- Digital transformation
- Data migration
- Digitization with quality assurance (Correct answer)
- Electronic discovery
Correct answer: Digitization with quality assurance
Digitization with quality assurance involves scanning paper records and applying controls to verify the resulting digital copies are authentic, accurate, and complete representations of the originals.
Question 50: A company receives a litigation hold notice after existing records have already been scheduled for destruction. What is the correct action?
- Suspend the destruction and preserve all potentially relevant records (Correct answer)
- Destroy only records not mentioned in the notice
- Proceed with destruction since it was already scheduled
- Transfer the records to outside counsel immediately
Correct answer: Suspend the destruction and preserve all potentially relevant records
A litigation hold supersedes any existing retention schedules and requires immediate suspension of destruction for all potentially relevant records.
Question 51: What is the benefit of policy review and updates?
- Is optional
- Keeps policies current (Correct answer)
- Confuses employees
- Increases risks
Correct answer: Keeps policies current
Regular policy review and updates are essential in information governance to ensure that policies remain current, effective, and compliant with evolving legal, regulatory, and technological landscapes. Information environments and business needs are constantly changing, so outdated policies can lead to compliance gaps or inefficiencies. Periodic reviews allow organizations to adapt their governance framework to new challenges and opportunities, maintaining its relevance and efficacy.
Question 52: Which framework provides a risk-based approach to managing cybersecurity that is widely used as a voluntary standard in the US?
- COBIT 2019
- PCI DSS
- ISO 27001
- NIST Cybersecurity Framework (CSF) (Correct answer)
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework provides a voluntary, risk-based framework organized around five functions (Identify, Protect, Detect, Respond, Recover) for managing cybersecurity risk.
Question 53: Which element is typically NOT included in a Data Processing Agreement (DPA) between a controller and processor?
- The obligations and rights of the controller
- The processor's marketing strategy for the data (Correct answer)
- The subject matter and duration of processing
- Security measures the processor must implement
Correct answer: The processor's marketing strategy for the data
DPAs under GDPR Article 28 must include processing scope, security measures, and rights/obligations, but a processor's marketing strategy for the data would violate the purpose limitation principle.
Question 54: Which documentation practice BEST demonstrates regulatory compliance for IGP certified professionals?
- Keeping informal handwritten notes
- Filing documents only when audited
- Maintaining organized, dated, and signed records of all activities (Correct answer)
- Relying on memory for routine procedures
Correct answer: Maintaining organized, dated, and signed records of all activities
Organized, dated, and signed records demonstrate systematic regulatory compliance.
Question 55: When a IGP professional identifies a potential regulatory violation, the CORRECT first step is to:
- Discuss it casually with coworkers
- Address it only if directly affected
- Document the violation and report through proper channels (Correct answer)
- Wait to see if it resolves on its own
Correct answer: Document the violation and report through proper channels
Proper documentation and reporting through established channels ensures accountability.
Question 56: Which scenario BEST illustrates a failure of IG policy enforcement?
- The IT team upgrades the records management system during off-hours
- A manager approves deletion of records still under a legal hold (Correct answer)
- Legal counsel reviews contracts before they are signed
- An employee requests access to a restricted database and is denied
Correct answer: A manager approves deletion of records still under a legal hold
Deleting records subject to a legal hold violates IG policy and can result in spoliation sanctions, making it a clear enforcement failure.
Question 57: In the context of information security, what does 'non-repudiation' ensure?
- Data remains unchanged during transmission
- Users are authenticated before access is granted
- Data cannot be read by unauthorized parties
- A sender cannot deny having sent a message (Correct answer)
Correct answer: A sender cannot deny having sent a message
Non-repudiation provides proof of the origin and integrity of data, ensuring that a sender cannot later deny having sent a message or performed an action.
Question 58: A company conducts a Business Impact Analysis (BIA). What does the Recovery Time Objective (RTO) define?
- The minimum backup frequency required for critical systems
- The total cost of recovering from a major incident
- The maximum amount of data loss measured in time that is acceptable
- The maximum acceptable time to restore a system after a disruption (Correct answer)
Correct answer: The maximum acceptable time to restore a system after a disruption
RTO defines the maximum tolerable duration of downtime for a business process or system before the disruption causes unacceptable harm to the organization.
Question 59: An organization receives a ransomware attack that encrypts all files on a shared drive. Which backup strategy would BEST minimize data loss?
- Daily incremental backups stored offline or in an isolated environment (Correct answer)
- Real-time replication to another folder on the same drive
- Monthly full backups stored in the cloud
- Weekly full backups stored on the same network
Correct answer: Daily incremental backups stored offline or in an isolated environment
Daily incremental backups stored offline or in an air-gapped environment ensure minimal data loss and prevent ransomware from encrypting backup copies.
Question 60: When conducting a risk assessment for IGP operations, which factor should receive the HIGHEST priority?
- Time required for safety training
- Convenience for daily operations
- Cost of implementing safety measures
- Probability and severity of potential harm (Correct answer)
Correct answer: Probability and severity of potential harm
The probability and severity of potential harm are the primary factors in risk assessment.
Question 61: A records retention schedule that conflicts with a legal hold should be:
- Applied as written since the schedule takes precedence
- Escalated to HR for employee discipline
- Suspended for the records covered by the legal hold until it is lifted (Correct answer)
- Deleted from the system to avoid confusion
Correct answer: Suspended for the records covered by the legal hold until it is lifted
Legal holds override normal retention schedules; records subject to a hold must be preserved until the hold is lifted, regardless of their scheduled destruction date.
Question 62: Which foundational principle is MOST important for success in Information Governance Professional?
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Specializing in only one narrow area
- Maintaining minimum certification requirements
- Maximizing financial returns
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success requires continuous learning, ethical practice, and focus on quality outcomes.
Question 63: How should Information Governance Professional professionals handle procedures that have been updated or revised?
- Only apply updates to new cases
- Wait for mandatory enforcement
- Review updates, complete required training, and implement revised procedures (Correct answer)
- Continue using the original method
Correct answer: Review updates, complete required training, and implement revised procedures
Professionals must review changes, complete training, and implement revised procedures.
Question 64: Which attack type involves inserting malicious SQL commands into an input field to manipulate a database?
- Man-in-the-middle attack
- Brute force attack
- Cross-site scripting (XSS)
- SQL injection (Correct answer)
Correct answer: SQL injection
SQL injection attacks exploit inadequate input validation by inserting SQL commands that manipulate or expose database contents.
Question 65: What is 'pseudonymization' of personal data?
- Replacing identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information (Correct answer)
- Permanently deleting identifying information from a dataset
- Encrypting personal data so only authorized parties can access it
- Masking personal data when displayed on screen
Correct answer: Replacing identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information
Pseudonymization replaces direct identifiers with artificial ones, reducing privacy risk while allowing re-identification if the key is available, unlike anonymization which is irreversible.
Question 66: What is the PRIMARY purpose of obtaining IGP certification in Information Governance Professional?
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To bypass educational requirements
- To guarantee employment
- To satisfy a personal achievement goal
Correct answer: To demonstrate verified competency and adherence to professional standards
Certification demonstrates verified competency and adherence to professional standards.
Question 67: Which practice best supports 'privacy by design' in a new software system that processes personal data?
- Embedding privacy controls and data minimization into the system's architecture from the start (Correct answer)
- Conducting an annual privacy audit once the system has been in production for one year
- Hiring a DPO to review the system after it is deployed
- Adding a privacy policy page to the system's help documentation after launch
Correct answer: Embedding privacy controls and data minimization into the system's architecture from the start
Privacy by design requires integrating privacy protections into the system's architecture proactively from the earliest design stages rather than adding them afterward.
Question 68: What is encryption used for in information security?
- Ignore data
- Encode data for protection (Correct answer)
- To speed up processing
- To delete data
Correct answer: Encode data for protection
Encryption is used in information security to encode data, transforming it into an unreadable format that protects it from unauthorized access. This process makes the data unintelligible to anyone without the correct decryption key. It is a vital tool for safeguarding sensitive information both when it is stored (data at rest) and when it is transmitted across networks (data in transit).
Question 69: What must an organization do to its records retention schedules when a litigation hold is issued?
- Transfer all records to the opposing counsel immediately
- Suspend the normal retention and disposition schedule for records covered by the hold (Correct answer)
- Permanently destroy all records covered by the hold to avoid disclosure
- Accelerate the destruction of records not covered by the hold
Correct answer: Suspend the normal retention and disposition schedule for records covered by the hold
When a litigation hold is issued, the organization must suspend the normal records retention and disposition schedule for any records that fall within the scope of the hold to prevent spoliation.
Question 70: What is the MOST effective way for new IGP professionals to build competency?
- Focusing solely on advanced topics
- Studying certification materials exclusively
- Learning through trial and error
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building competency requires formal education, mentored practice, and ongoing development.
Question 71: Which metric is MOST useful for measuring IG policy compliance?
- Percentage of employees who have completed required IG training (Correct answer)
- Annual IG budget expenditure
- Number of IG policies published on the intranet
- Total number of records stored in the repository
Correct answer: Percentage of employees who have completed required IG training
Training completion rates directly indicate whether employees have been exposed to and acknowledged IG requirements, serving as a key compliance metric.
Question 72: In records management, what distinguishes a 'record' from a 'non-record'?
- Records are digital; non-records are physical
- Records are stored on-premises; non-records are in the cloud
- Records document organizational activities and have ongoing value; non-records are transitory (Correct answer)
- Records require encryption; non-records do not
Correct answer: Records document organizational activities and have ongoing value; non-records are transitory
Records are documents that provide evidence of organizational activities and have ongoing business, legal, or historical value, distinguishing them from transitory non-records like draft copies.
Question 73: Which element distinguishes a 'standard' from a 'policy' in an IG framework hierarchy?
- Standards are optional; policies are mandatory
- Standards apply only to IT systems while policies apply to all information
- Standards are written by vendors; policies are written internally
- Standards provide specific, measurable requirements that support policy compliance (Correct answer)
Correct answer: Standards provide specific, measurable requirements that support policy compliance
Standards define specific, quantifiable requirements (e.g., password length minimums) that operationalize policies, making compliance measurable and auditable.
Question 74: In the context of compliance audits, 'segregation of duties' (SoD) is a control designed to:
- Ensure only auditors can access financial systems
- Prevent any single individual from controlling all steps of a critical process (Correct answer)
- Separate IT infrastructure across geographic locations
- Divide compliance responsibilities between legal and IT departments
Correct answer: Prevent any single individual from controlling all steps of a critical process
Segregation of duties divides critical tasks among multiple people to reduce the risk of error or fraud by any single individual.
Question 75: The principle of proportionality in e-discovery requires that:
- The burden and cost of discovery must be proportional to the needs of the case (Correct answer)
- Discovery costs must not exceed 10% of the amount in controversy
- Each party must produce an equal volume of documents
- All ESI must be reviewed by at least two attorneys before production
Correct answer: The burden and cost of discovery must be proportional to the needs of the case
FRCP Rule 26(b)(1) embeds proportionality, requiring that the scope of discovery be proportional to the needs of the case considering factors like the amount in controversy, importance of the issues, and the burden of discovery.
Question 76: Under the FTC Act, what standard has the FTC used to regulate data privacy practices of US companies?
- Companies must comply with GDPR standards for all US consumers
- Unfair or deceptive acts or practices, including failing to honor stated privacy policies (Correct answer)
- All personal data collected must be encrypted using AES-256
- Companies must appoint a DPO if they process data on more than 500 individuals
Correct answer: Unfair or deceptive acts or practices, including failing to honor stated privacy policies
The FTC uses its Section 5 authority to take action against unfair or deceptive practices, including when companies violate their own privacy policies or fail to adequately protect consumer data.
Question 77: Why is employee training important in risk management?
- Ensures understanding of risks (Correct answer)
- Increases risks
- Only for managers
- Is optional
Correct answer: Ensures understanding of risks
Employee training is important in risk management because employees are often the first line of defense against various risks, including cybersecurity threats and operational errors. Training ensures they understand potential risks, their role in mitigating them, and the proper procedures to follow. This knowledge empowers them to identify and report risks, adhere to security protocols, and contribute to a stronger overall risk posture for the organization.
Question 78: How should Information Governance Professional professionals handle procedures that have been updated or revised?
- Only apply updates to new cases
- Continue using the original method
- Review updates, complete required training, and implement revised procedures (Correct answer)
- Wait for mandatory enforcement
Correct answer: Review updates, complete required training, and implement revised procedures
Professionals must review changes, complete training, and implement revised procedures.
Question 79: What is the PRIMARY purpose of obtaining IGP certification in Information Governance Professional?
- To satisfy a personal achievement goal
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To guarantee employment
- To bypass educational requirements
Correct answer: To demonstrate verified competency and adherence to professional standards
Certification demonstrates verified competency and adherence to professional standards.
Question 80: When an organization undergoes a merger, which IG activity is MOST urgent to perform regarding information assets?
- Conducting an information inventory and gap analysis of both organizations' IG frameworks (Correct answer)
- Transferring all IT systems to the acquiring company's platform within 30 days
- Suspending all IG policies until the merger is complete
- Immediately deleting all records from the acquired company
Correct answer: Conducting an information inventory and gap analysis of both organizations' IG frameworks
A merger requires an information inventory and gap analysis to identify IG framework differences, redundancies, and risks before integration decisions are made.
Question 81: Which of the following best describes a Key Risk Indicator (KRI)?
- A forward-looking metric that signals increasing risk exposure (Correct answer)
- A financial ratio used to assess vendor creditworthiness
- A metric that measures compliance with a specific regulation
- A historical log of past risk events and their outcomes
Correct answer: A forward-looking metric that signals increasing risk exposure
KRIs are predictive metrics that provide early warning signals of increasing risk before an adverse event occurs.
Question 82: What is personally identifiable information (PII)?
- Product specifications
- Public data
- Information identifying individuals (Correct answer)
- General company info
Correct answer: Information identifying individuals
Personally identifiable information (PII) refers to any data that can be used to directly or indirectly identify an individual. Examples include names, addresses, social security numbers, email addresses, and biometric data. Protecting PII is a cornerstone of data privacy, as its compromise can lead to identity theft, fraud, or other personal harm.
Question 83: The California Consumer Privacy Act (CCPA) grants consumers the right to:
- Erasure, access, and portability only for health data
- Restrict automated decision-making and profiling
- Know, delete, and opt out of sale of their personal information (Correct answer)
- Data minimization and purpose limitation enforcement
Correct answer: Know, delete, and opt out of sale of their personal information
CCPA grants California consumers the rights to know what personal information is collected, to delete it, and to opt out of its sale.
Question 84: Which of the following is a key characteristic of an effective IG policy lifecycle?
- Policies undergo regular review and updates to reflect regulatory and business changes (Correct answer)
- Policies are created solely by IT without business input
- Policies are written once and never revised
- Policies are distributed only to senior management
Correct answer: Policies undergo regular review and updates to reflect regulatory and business changes
Effective IG policies must be periodically reviewed and updated to remain aligned with evolving laws, regulations, business needs, and technology changes.
Question 85: In information governance, what does a Data Loss Prevention (DLP) system primarily do?
- Backs up data to offsite locations
- Monitors and restricts unauthorized transfer of sensitive data (Correct answer)
- Encrypts data stored on endpoints
- Scans for malware on corporate networks
Correct answer: Monitors and restricts unauthorized transfer of sensitive data
DLP systems detect and prevent unauthorized transmission or exfiltration of sensitive information across network, endpoint, and cloud channels.
Question 86: What is a common cause of data breaches?
- Regular updates
- Strong encryption
- Weak passwords and phishing (Correct answer)
- Multi-factor authentication
Correct answer: Weak passwords and phishing
Weak passwords are easily compromised through guessing or brute-force attacks, while phishing schemes trick users into divulging sensitive information. Both methods exploit human vulnerabilities and are among the most common and effective ways attackers gain unauthorized access, leading to significant data breaches.
Question 87: What is the purpose of a Certificate Revocation List (CRL) in a PKI environment?
- Track certificate issuance costs for audit purposes
- List all certificates due for renewal in the next 30 days
- Identify digital certificates that have been invalidated before their expiration date (Correct answer)
- Store the private keys of revoked certificates
Correct answer: Identify digital certificates that have been invalidated before their expiration date
A CRL is a list maintained by a Certificate Authority that contains serial numbers of certificates revoked due to compromise, policy violations, or other reasons.
Question 88: What is the MOST effective way for new IGP professionals to build competency?
- Learning through trial and error
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Studying certification materials exclusively
- Focusing solely on advanced topics
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building competency requires formal education, mentored practice, and ongoing development.
Question 89: When conducting a risk assessment for IGP operations, which factor should receive the HIGHEST priority?
- Convenience for daily operations
- Probability and severity of potential harm (Correct answer)
- Time required for safety training
- Cost of implementing safety measures
Correct answer: Probability and severity of potential harm
The probability and severity of potential harm are the primary factors in risk assessment.
Question 90: In Information Governance Professional, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To evaluate employee performance reviews
- To reduce daily workload
- To ensure personnel can respond effectively in emergencies (Correct answer)
- To satisfy insurance requirements only
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies.
Question 91: In Information Governance Professional, what is the PRIMARY purpose of conducting regular safety drills and exercises?
- To ensure personnel can respond effectively in emergencies (Correct answer)
- To evaluate employee performance reviews
- To satisfy insurance requirements only
- To reduce daily workload
Correct answer: To ensure personnel can respond effectively in emergencies
Regular safety drills ensure that all personnel are prepared to respond effectively during actual emergencies.
Question 92: Under the principle of 'least privilege' in information governance, access to sensitive information should be granted:
- Based on seniority and years of service
- Only to the minimum number of users required to perform their job functions (Correct answer)
- At the discretion of each department head without central oversight
- To all employees to maximize productivity
Correct answer: Only to the minimum number of users required to perform their job functions
Least privilege limits information access to only those who need it to perform their duties, reducing the risk of unauthorized disclosure or misuse.
Question 93: How does compliance impact organizational reputation?
- Builds trust and credibility (Correct answer)
- Has no effect
- Decreases trust
- Only affects finances
Correct answer: Builds trust and credibility
Compliance significantly impacts organizational reputation by demonstrating a commitment to ethical practices, legal adherence, and responsible data handling. Organizations that consistently comply with regulations build trust and credibility with customers, partners, and the public. Conversely, non-compliance can lead to severe reputational damage, eroding trust and potentially affecting customer loyalty and market value.
Question 94: In Information Governance Professional practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Document it for the next safety audit
- Continue working and report at end of shift
- Immediately secure the area and report the hazard (Correct answer)
- Wait for a supervisor to notice the issue
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels.
Question 95: Which term describes Electronically Stored Information as defined under the Federal Rules of Civil Procedure?
- Only structured data held in enterprise databases
- Any information stored on paper or electronic media
- Information created, stored, or transmitted in electronic form that may be subject to discovery (Correct answer)
- Email messages archived by a third-party provider
Correct answer: Information created, stored, or transmitted in electronic form that may be subject to discovery
ESI under the FRCP broadly includes any information created, stored, or transmitted in electronic form, encompassing emails, documents, databases, voicemails, and metadata.
Question 96: What is the BEST way for a Information Governance Professional professional to stay current with regulatory changes?
- Monitor regulatory bodies, attend CE, and participate in professional associations (Correct answer)
- Depend on colleagues to share updates
- Check regulations only during renewal
- Rely solely on employer notifications
Correct answer: Monitor regulatory bodies, attend CE, and participate in professional associations
Staying current requires monitoring agencies, attending CE, and participating in professional associations.
Question 97: Which data privacy concept gives individuals the right to receive their personal data in a structured, commonly used, machine-readable format?
- Right to erasure
- Right to object
- Right to restriction of processing
- Right to data portability (Correct answer)
Correct answer: Right to data portability
The right to data portability, established under GDPR Article 20, allows individuals to receive and transfer their personal data in a reusable format.
Question 98: In an IG program, what is the primary purpose of a data map or data inventory?
- Monitor employee access to corporate email systems
- Document the geographic location of all company offices
- Catalog where personal and sensitive data is created, stored, used, and shared (Correct answer)
- Track software licensing compliance across the enterprise
Correct answer: Catalog where personal and sensitive data is created, stored, used, and shared
A data map catalogs the full lifecycle of data — where it originates, how it flows, where it is stored, and who accesses it — enabling effective governance and risk management.
Question 99: Which factor MOST significantly affects the quality of technical outcomes in IGP practice?
- Speed of procedure completion
- The brand of equipment
- The time of day
- The practitioner's training, preparation, and attention to detail (Correct answer)
Correct answer: The practitioner's training, preparation, and attention to detail
Quality depends primarily on training, preparation, and attention to detail.
Question 100: A multinational company transferring EU personal data to the US in the absence of an adequacy decision should use which approved mechanism?
- An internal data governance policy approved by the DPO
- Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs) (Correct answer)
- Pseudonymization applied before transfer
- A self-certification letter from the receiving company
Correct answer: Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs)
GDPR Chapter V allows cross-border data transfers via approved safeguards including BCRs and SCCs when no adequacy decision exists.
Question 101: Which concept describes the practice of granting users only the minimum access rights necessary to perform their job functions?
- Separation of duties
- Defense in depth
- Least privilege (Correct answer)
- Need to know
Correct answer: Least privilege
The principle of least privilege limits user permissions to the minimum required for their role, reducing the attack surface if credentials are compromised.
Information Governance Professional (IGP) Exam
The IGP certification validates an individual's knowledge and skills in information governance, encompassing legal, regulatory, and business requirements for information management.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds