Free IAPP CIPM Exam Questions

Absolute Free CIPM Exam Practice for Comprehensive Preparation 

  • IAPP CIPM Exam Questions
  • Provided By: IAPP
  • Exam: Certified Information Privacy Manager
  • Certification: Certified Information Privacy Manager
  • Total Questions: 278
  • Updated On: Sep 04, 2026
  • Rated: 4.9 |
  • Online Users: 556
Page No. 1 of 56
Add To Cart
  • Question 1
    • What United States federal law requires financial institutions to declare their personal data collection practices? 

      Answer: B
  • Question 2
    • Which of the following controls does the PCI DSS framework NOT require?  

      Answer: A
  • Question 3
    • SCENARIO
      Please use the following to answer the next question:
      It's just what you were afraid of. Without consulting you, the information technology director at your organization
      launched a new initiative to encourage employees to use personal devices for conducting business. The
      initiative made purchasing a new, high-specification laptop computer an attractive option, with discounted
      laptops paid for as a payroll deduction spread over a year of paychecks. The organization is also paying the
      sales taxes. It's a great deal, and after a month, more than half the organization's employees have signed on
      and acquired new laptops. Walking through the facility, you see them happily customizing and comparing notes
      on their new computers, and at the end of the day, most take their laptops with them, potentially carrying
      personal data to their homes or other unknown locations. It's enough to give you data-protection nightmares,
      and you've pointed out to the information technology Director and many others in the organization the potential
      hazards of this new practice, including the inevitability of eventual data loss or theft.
      Today you have in your office a representative of the organization's marketing department who shares with you,
      reluctantly, a story with potentially serious consequences. The night before, straight from work, with laptop in
      hand, he went to the Bull and Horn Pub to play billiards with his friends. A fine night of sport and socializing
      began, with the laptop "safely" tucked on a bench, beneath his jacket. Later that night, when it was time to
      depart, he retrieved the jacket, but the laptop was gone. It was not beneath the bench or on another bench
      nearby. The waitstaff had not seen it. His friends were not playing a joke on him. After a sleepless night, he
      confirmed it this morning, stopping by the pub to talk to the cleanup crew. They had not found it. The laptop was
      missing. Stolen, it seems. He looks at you, embarrassed and upset.
      You ask him if the laptop contains any personal data from clients, and, sadly, he nods his head, yes. He
      believes it contains files on about 100 clients, including names, addresses and governmental identification
      numbers. He sighs and places his head in his hands in despair.
      What should you do first to ascertain additional information about the loss of data? 

      Answer: A
  • Question 4
    • Which of the following is a common disadvantage of a third-party audit?

      Answer: C
  • Question 5
    • SCENARIO
      Please use the following to answer the next question:
      Jonathan recently joined a healthcare payment processing solutions company as a senior privacy manager.
      One morning, Jonathan awakens to several emails informing him that an individual cloud server failed due to a
      flood in its server room, damaging its hardware and destroying all the data the company had stored on that
      drive. Jonathan was not aware that the company had this particular cloud account or that any data was being
      stored there because it was not included in the data mapping or data inventory provided to him by his
      predecessor. Jonathan's predecessor conducted a data inventory and mapping exercise 4 years ago and
      updated it on an annual basis.
      Renee works in the sales department and tells Jonathan that she doesn't think that account had been used
      since the company moved to a bigger cloud vendor three years ago. She also advised him that the account was
      mostly used by Human Resources (HR) and Accounts Payable (AP). Jonathan speaks to both departments and
      learns that each had met with his predecessor multiple times and explained they saved sensitive personal data
      on that drive, including health and financial related personal data and "other stuff." Jonathan also learns that the
      data stored in that account was not backed up pursuant to company policy. Jonathan asks his IT department
      who had access to that particular account and learns that there were no access controls in place, making the
      account available to anyone in the company, despite the purported sensitivity of the data being stored there.
      Jonathan is panicking as the data can't be recovered, and he can't determine exactly what data was saved on
      that account or to whom it belongs. Two days later, the company receives 32 data subject access requests and
      Accounts Payable confirms Jonathan's worry that these data subjects' personal data was likely stored on this
      account. He searches for the company's data subject access request policy, but later learns it doesn't exist.
      Based on the scenario above, what is the most appropriate next step Jonathan should take?

      Answer: A
PAGE: 1 - 56
Add To Cart

© Copyrights DumpsEngine 2026. All Rights Reserved

We use cookies to ensure your best experience. So we hope you are happy to receive all cookies on the DumpsEngine.