CIPT CERTIFIED
INFORMATION PRIVACY
TECHNOLOGIST
PRACTICE EXAM 90
QUESTIONS
Question 1: A data-retention exception allows records to be preserved for an active legal hold. Which implementation is best?
Choices:
1) Copy every record to personal laptops 2) Disable all deletion jobs globally 3) Remove retention metadata from the aected system 4) Apply a documented hold ag to aected records while normal deletion continues for other records Correct Answer: Apply a documented hold ag to aected records while normal deletion continues for other records Explanation: A scoped legal-hold mechanism preserves only aected records and allows ordinary retention rules to continue elsewhere. Global suspension increases unnecessary retention.Page 1
Question 2: A partner needs to verify that a customer is over 18 but does not need the birth date. Which disclosure approach best minimizes data sharing?
Choices:
1) Send all government-issued identiers 2) Send the full identity record 3) Provide only an age-eligibility assertion 4) Send the birth date plus address
Correct Answer: Provide only an age-eligibility assertion
Explanation: An eligibility assertion communicates the fact the partner needs while withholding unnecessary underlying identity data.Question 3: An intrusion detection system alerts on repeated attempts to access a restricted customer database from an unusual host. What is the system primarily providing?
Choices:
1) Permanent anonymization of the database 2) Detection of suspicious activity that may indicate an attempted privacy or security incident 3) Automatic legal authorization for processing 4) Proof that no attacker succeeded Correct Answer: Detection of suspicious activity that may indicate an attempted privacy or security incident Explanation: Intrusion detection identies suspicious patterns that warrant investigation. An alert does not establish legal authority, anonymize data or prove that access was unsuccessful.Page 2
Question 4: A recommendation engine is lawful in a jurisdiction but systematically disadvantages a protected group because of biased training data. What should a privacy technologist conclude?
Choices:
1) The system may still present ethical and discrimination risks requiring mitigation 2) Lawfulness alone resolves the issue 3) Encryption will automatically remove the bias 4) The model should be deployed unchanged if accuracy is high Correct Answer: The system may still present ethical and discrimination risks requiring mitigation Explanation: Legal permissibility does not eliminate ethical responsibilities. A privacy technologist should evaluate discriminatory eects, data provenance, model behavior and mitigation even when the processing is otherwise lawful.
Question 5: A consent dashboard lets a user enable analytics but combines
advertising and location tracking into the same toggle. What is the most privacy- preserving improvement?
Choices:
1) Provide granular controls for materially dierent processing purposes 2) Remove all toggles and rely on a privacy policy 3) Ask for consent only after data has been collected 4) Enable all purposes by default Correct Answer: Provide granular controls for materially dierent processing purposes Explanation: Granular controls improve meaningful choice by separating distinct purposes.Bundling unrelated processing can obscure user control and make consent less specic.Page 3