IGP Compliance & Risk Management 3 — Questions and Answers
Question 1: Under GDPR, the maximum fine for the most serious violations is:
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 5% of global annual turnover
- €5 million or 1% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR's highest tier of fines is €20 million or 4% of global annual turnover, whichever is higher.
Question 2: A Compliance Management Program (CMP) should be reviewed and updated:
- Only when a new regulation is enacted
- Only after a compliance incident occurs
- On a regular schedule and when significant changes occur (Correct answer)
- Every five years regardless of changes
Correct answer: On a regular schedule and when significant changes occur
An effective CMP requires periodic scheduled reviews as well as triggered reviews when regulations, business operations, or risk profiles change.
Question 3: Which document formally defines an organization's acceptable level of risk exposure?
- Risk treatment plan
- Risk register
- Risk appetite statement (Correct answer)
- Business impact analysis
Correct answer: Risk appetite statement
A risk appetite statement formally articulates the amount and type of risk an organization is willing to accept in pursuit of its objectives.
Question 4: An employee intentionally leaks confidential corporate data to a competitor. This is an example of:
- External threat
- Insider threat (Correct answer)
- Residual risk
- Systemic risk
Correct answer: Insider threat
An insider threat involves a current or former employee, contractor, or partner who misuses authorized access to harm the organization.
Question 5: The California Consumer Privacy Act (CCPA) grants consumers the right to:
- Erasure, access, and portability only for health data
- Know, delete, and opt out of sale of their personal information (Correct answer)
- Restrict automated decision-making and profiling
- Data minimization and purpose limitation enforcement
Correct answer: Know, delete, and opt out of sale of their personal information
CCPA grants California consumers the rights to know what personal information is collected, to delete it, and to opt out of its sale.
Question 6: In the context of compliance audits, 'segregation of duties' (SoD) is a control designed to:
- Ensure only auditors can access financial systems
- Prevent any single individual from controlling all steps of a critical process (Correct answer)
- Separate IT infrastructure across geographic locations
- Divide compliance responsibilities between legal and IT departments
Correct answer: Prevent any single individual from controlling all steps of a critical process
Segregation of duties divides critical tasks among multiple people to reduce the risk of error or fraud by any single individual.
Question 7: Which risk assessment methodology uses numeric values to calculate expected monetary loss from a risk event?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Delphi technique
- Bow-tie analysis
Correct answer: Quantitative risk assessment
Quantitative risk assessment assigns numerical values to likelihood and impact to calculate metrics like Annual Loss Expectancy (ALE).
Under GDPR, the maximum fine for the most serious violations is: