A valid argument against data minimization is that it?
A. Increases the chance that someone can be identified from data.
B. Can have an adverse effect on data quality.
C. Decreases the speed of data transfers.
D. Can limit business opportunities.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Which is NOT a suitable action to apply to data when the retention period ends?
A. De-identification.
B. Aggregation.
C. Retagging.
D. Deletion.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Revocation and reissuing of compromised credentials is impossible for which of the following authentication techniques?
A. Radio frequency identification.
B. Picture passwords.
C. Biometric data.
D. Personal identification number.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Users of a web-based email service have their accounts breached through compromised login credentials.
Which possible consequences of the breach illustrate the two categories of Calo's Harm Dimensions?
A. Identity theft and embarrassment.
B. Financial loss and solicitation.
C. Identity theft and the leaking of information.
D. Financial loss and blackmail.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
A laundry company is collecting, with user consent, the geolocation of its customers to analyze movement patterns and determine potential locations for joint services with marketing partners. What type of concern is raised by this practice?
A. Ethical.
B. Technical.
C. Behavioral.
D. Legal.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
A privacy engineer has been asked to review an online account login page. He finds there is no limitation on the number of invalid login attempts a user can make when logging into their online account.
What would be the best recommendation to minimize the potential privacy risk from this weakness?
A. Enforce strong password and account credentials.
B. Implement strong Transport Layer Security (TLS) to ensure an encrypted link.
C. Develop server-side input validation checks.
D. Implement a CAPTCHA system.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
SCENARIO
Please use the following to answer the next question:
Chuck, a compliance auditor for a consulting firm focusing on healthcare clients, was required to travel to the client's office to perform an onsite review of the client's operations. He rented a car from Finley Motors upon arrival at the airport as so he could commute to and from the client's office. The car rental agreement was electronically signed by Chuck and included his name, address, driver's license, make/model of the car, billing rate, and additional details describing the rental transaction. On the second night, Chuck was caught by a red light camera not stopping at an intersection on his way to dinner. Chuck returned the car back to the car rental agency at the end week without mentioning the infraction and Finley Motors emailed a copy of the final receipt to the address on file.
Local law enforcement later reviewed the red light camera footage. As Finley Motors is the registered owner of the car, a notice was sent to them indicating the infraction and fine incurred. This notice included the license plate number, occurrence date and time, a photograph of the driver, and a web portal link to a video clip of the violation for further review. Finley Motors, however, was not responsible for the violation as they were not driving the car at the time and transferred the incident to AMP Payment Resources for further review. AMP Payment Resources identified Chuck as the driver based on the rental agreement he signed when picking up the car and then contacted Chuck directly through a written letter regarding the infraction to collect the fine.
After reviewing the incident through the AMP Payment Resources' web portal, Chuck paid the fine using his personal credit card. Two weeks later, Finley Motors sent Chuck an email promotion offering 10% off a future rental.
What should Finley Motors have done to incorporate the transparency principle of Privacy by Design (PbD)?
A. Documented that Finley Motors has a legitimate interest to share Chuck's information.
B. Provided notice of data sharing practices within the electronically signed rental agreement.
C. Signed a data sharing agreement with AMP Payment Resources.
D. Obtained verbal consent from Chuck and recorded it within internal systems.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
How can bias be mitigated when designing automated decision-making tools?
A. Use open-source libraries.
B. Over-represent some population groups to ensure proper algorithmic learning.
C. Ensure population groups are proportionately represented in feature development.
D. Provide the tool with access to all population attributes.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 9:
What Privacy by Design (PbD) element should include a de-identification or deletion plan?
A. Security
B. Categorization.
C. Remediation.
D. Retention.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
1028 お客様のコメント





Izumi -
無駄なく効率よく短時間で合格レベルに到達することができる,CIPT受験者必携の1冊ってじっかんしました。助かりました。