Free IAPP CIPT practice questions

10 free IAPP CIPT practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 325 questions. Work through them, then open each answer to check your reasoning.

Question 1

What would be an example of an organization transferring the risks associated with a data breach?

  1. Using a third-party service to process credit card transactions.
  2. Encrypting sensitive personal data during collection and storage
  3. Purchasing insurance to cover the organization in case of a breach.
  4. Applying industry standard data handling practices to the organization' practices.
Show answer and explanation

Correct answer: C. Purchasing insurance to cover the organization in case of a breach.

case of a breach. Risk transfer shifts the financial consequences of an event to another party, and insurance is the classic example. Buying breach coverage means the insurer absorbs defined costs such as notification, forensics and legal claims if an incident occurs. The organization still owns the underlying risk and its obligations, but the monetary exposure now sits with the carrier.

Why the other options are wrong

  • A. Outsourcing card processing shifts handling of the data but the organization remains accountable for the breach and its costs, so this is risk reduction through scope limitation rather than transfer.
  • B. Encryption is a technical control that lowers the likelihood and impact of exposure, which makes it mitigation.
  • D. Adopting industry standard handling practices reduces the chance of an incident and is therefore mitigation, not transfer.

Question 2

Which of the following is considered a client-side IT risk?

  1. Security policies focus solely on internal corporate obligations.
  2. An organization increases the number of applications on its server.
  3. An employee stores his personal information on his company laptop.
  4. IDs used to avoid the use of personal data map to personal data in another database.
Show answer and explanation

Correct answer: C. An employee stores his personal information on his company laptop.

company laptop. Client-side risks originate from the end-user device or client system. An employee storing personal information on a company laptop represents a client-side risk because the vulnerability exists on the employee's device where data could be accessed, lost, or stolen. Security policies (A) relate to organizational governance. Server application management (B) is a server-side concern. Database linkage (D) is a data architecture issue, not client-side.

Why the other options are wrong

  • A. This describes a policy governance issue, not a client-side technical risk.
  • B. Server application management is a server-side operational concern.
  • D. Database cross-linking is a data architecture vulnerability, not client-side.

Question 3

Show the case study this question is based on

SCENARIO

Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.

As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, `I don't know what you are doing, but keep doing it!" But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.

At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. `Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should.` Sam said, `I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase.` Carol replied, `Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?" `˜I can," said Jane. `But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy.` Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. `Sam and Jane, you have done such a great job that one of the biggest names in the glass business

wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."

What type of principles would be the best guide for Jane's ideas regarding a new data management program?

  1. Collection limitation principles.
  2. Vendor management principles.
  3. Incident preparedness principles.
  4. Fair Information Practice Principles
Show answer and explanation

Correct answer: D. Fair Information Practice Principles

Fair Information Practice Principles (FIPPs) provide comprehensive guidance on responsible data management practices, including collection, use, retention, security, access, and customer control, exactly what Jane describes when she mentions best practices for data management and customers' ability to manage their personal information. Collection limitation principles (A) address only one aspect of data handling. Vendor management (B) and incident preparedness (C) are specific operational concerns rather than foundational data management frameworks.

Why the other options are wrong

  • A. Collection limitation addresses only what data is gathered, not the full data management lifecycle Jane proposes.
  • B. Vendor management principles address third-party oversight, not fundamental data handling practices.
  • C. Incident preparedness focuses on breach response, not proactive data management best practices.

Question 4

Show the case study this question is based on

SCENARIO

Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.

As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, `I don't know what you are doing, but keep doing it!" But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.

At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. `Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should.` Sam said, `I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase.` Carol replied, `Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?" `˜I can," said Jane. `But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy.` Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. `Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."

Which regulator has jurisdiction over the shop's data management practices?

  1. The Federal Trade Commission.
  2. The Department of Commerce.
  3. The Data Protection Authority.
  4. The Federal Communications Commission.
Show answer and explanation

Correct answer: A. The Federal Trade Commission.

The shop is a U.S. business collecting customer personal information in the course of commerce, which places it under the Federal Trade Commission. Section 5 of the FTC Act lets the FTC act against unfair or deceptive practices, including failing to safeguard customer data or breaking privacy promises made to consumers. That is the authority most likely to examine how Sam and Jane collect, store and share the customer list.

Why the other options are wrong

  • B. The Department of Commerce develops policy and standards frameworks but does not enforce privacy or data security against retailers.
  • C. Data protection authorities are supervisory bodies created under European law and have no jurisdiction over a U.S. boutique's domestic practices.
  • D. The Federal Communications Commission oversees telecommunications and broadcast carriers, not a glass shop's customer records.

Question 5

Show the case study this question is based on

SCENARIO

Carol was a U.S.-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.

As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, `I don't know what you are doing, but keep doing it!" But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane's first impressions.

At the meeting, Carol could not wait to hear Jane's thoughts, but she was unprepared for what Jane had to say. `Carol, I know that he doesn't realize it, but some of Sam's efforts to increase sales have put you in a vulnerable position. You are not protecting customers' personal information like you should.` Sam said, `I am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers' names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase.` Carol replied, `Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?" `˜I can," said Jane. `But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy.` Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year, Carol shared some exciting news. `Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out! And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand."

When initially collecting personal information from customers, what should Jane be guided by?

  1. Onward transfer rules.
  2. Digital rights management.
  3. Data minimization principles.
  4. Vendor management principles
Show answer and explanation

Correct answer: C. Data minimization principles.

Data minimization principles guide organizations to collect only the personal information necessary for the stated purpose. When initially collecting customer information, Jane should be guided by what data is actually needed rather than gathering excessive information. Onward transfer rules (A) address how data is shared after collection. Digital rights management (B) concerns content protection, not data collection practices. Vendor management (D) addresses third-party oversight, not initial collection decisions.

Why the other options are wrong

  • A. Onward transfer rules apply to secondary uses and sharing, not initial collection decisions.
  • B. Digital rights management pertains to content and intellectual property protection, not personal data collection.
  • D. Vendor management principles govern third-party relationships, not the organization's own collection practices.

Question 6

A key principle of an effective privacy policy is that it should be?

  1. Written in enough detail to cover the majority of likely scenarios.
  2. Made general enough to maximize flexibility in its application.
  3. Presented with external parties as the intended audience.
  4. Designed primarily by the organization's lawyers.
Show answer and explanation

Correct answer: A. Written in enough detail to cover the majority of likely scenarios.

scenarios. An effective privacy policy should be detailed enough to address foreseeable scenarios and provide clear guidance on how the organization handles personal information. This specificity ensures employees understand requirements and customers know what to expect. Being too general (B) creates ambiguity and inconsistent application. External audiences (C) should understand policies, but the primary audience is internal stakeholders and employees who implement them. Lawyer-driven design (D) alone produces overly restrictive language; effective policies balance legal protection with operational clarity and customer transparency.

Why the other options are wrong

  • B. Excessive generality creates implementation gaps and allows inconsistent data handling practices.
  • C. While external parties should comprehend policies, the primary intended audience is internal staff responsible for implementation.
  • D. Over-reliance on lawyer design produces overly complex or restrictive policies; business stakeholders must also guide development.

Question 7

What was the first privacy framework to be developed?

  1. OECD Privacy Principles.
  2. Generally Accepted Privacy Principles.
  3. Code of Fair Information Practice Principles (FIPPs).
  4. The Asia-Pacific Economic Co-operation (APEC) Privacy Framework.
Show answer and explanation

Correct answer: C. Code of Fair Information Practice Principles (FIPPs).

The Code of Fair Information Practice Principles (FIPPs), developed in the 1970s, was the first comprehensive privacy framework established, emerging from U.S. government work on privacy concerns. The OECD Privacy Principles (A) came later in 1980, adapting and building upon FIPPs concepts. GAPP (B) was developed in the 2000s. The APEC Privacy Framework (D) is more recent, established in 2004.

Why the other options are wrong

  • A. OECD Privacy Principles followed and were influenced by earlier FIPPs frameworks.
  • B. Generally Accepted Privacy Principles were developed decades after FIPPs.
  • D. The APEC Privacy Framework was established in 2004, well after FIPPs.

Question 8

Which of the following became a foundation for privacy principles and practices of countries and organizations across the globe?

  1. The Personal Data Ordinance.
  2. The EU Data Protection Directive.
  3. The Code of Fair Information Practices.
  4. The Organization for Economic Co-operation and Development (OECD) Privacy Principles.
Show answer and explanation

Correct answer: D. The Organization for Economic Co-operation and Development (OECD) Privacy Principles.

Development (OECD) Privacy Principles. The OECD Privacy Principles, established in 1980, became the foundational framework adopted and adapted by countries and organizations globally, including influencing the EU Directive and becoming the basis for privacy practices worldwide. The Personal Data Ordinance (A) is not a recognized global framework. The EU Data Protection Directive (B), while influential in Europe, is regional and came after OECD principles. The Code of Fair Information Practices (C), while historically first, had more limited geographic adoption than OECD principles.

Why the other options are wrong

  • A. The Personal Data Ordinance is not a recognized international privacy framework.
  • B. The EU Directive is an important European instrument but represents regional governance, not global foundation.
  • C. While FIPPs were historically first, OECD principles achieved broader global adoption and influence.

Question 9

Show the case study this question is based on

SCENARIO

Kyle is a new security compliance manager who will be responsible for coordinating and executing controls to ensure compliance with the company's information security policy and industry standards. Kyle is also new to the company, where collaboration is a core value. On his first day of new-hire orientation, Kyle's schedule included participating in meetings and observing work in the IT and compliance departments.

Kyle spent the morning in the IT department, where the CIO welcomed him and explained that her department was responsible for IT governance.

The CIO and Kyle engaged in a conversation about the importance of identifying meaningful IT governance metrics. Following their conversation, the CIO introduced Kyle to Ted and Barney. Ted is implementing a plan to encrypt data at the transportation level of the organization's wireless network. Kyle would need to get up to speed on the project and suggest ways to monitor effectiveness once the implementation was complete. Barney explained that his short-term goals are to establish rules governing where data can be placed and to minimize the use of offline data storage.

Kyle spent the afternoon with Jill, a compliance specialist, and learned that she was exploring an initiative for a compliance program to follow self-regulatory privacy principles. Thanks to a recent internship, Kyle had some experience in this area and knew where Jill could find some support. Jill also shared results of the company's privacy risk assessment, noting that the secondary use of personal information was considered a high risk.

By the end of the day, Kyle was very excited about his new job and his new company. In fact, he learned about an open position for someone with strong qualifications and experience with access privileges, project standards board approval processes, and application-level obligations, and couldn't wait to recommend his friend Ben who would be perfect for the job.

Ted's implementation is most likely a response to what incident?

  1. Encryption keys were previously unavailable to the organization's cloud storage host.
  2. Signatureless advanced malware was detected at multiple points on the organization's networks.
  3. Cyber criminals accessed proprietary data by running automated authentication attacks on the organization's network.
  4. Confidential information discussed during a strategic teleconference was intercepted by the organization's top competitor.
Show answer and explanation

Correct answer: D. Confidential information discussed during a strategic teleconference was intercepted by the organization's top competitor.

teleconference was intercepted by the organization's top competitor. Ted is implementing encryption at the transportation level of the wireless network, which protects data in transit. This is a direct response to an incident where data was intercepted during transmission. Option D describes confidential information being intercepted during a teleconference, which represents data compromise during wireless transmission, the exact scenario that transportation-level encryption prevents. Options A, B, and C address different security concerns (key management, malware detection, and authentication attacks respectively) that would not specifically drive a transportation-layer encryption implementation.

Why the other options are wrong

  • A. Encryption key availability affects cloud storage security, not wireless network transportation-layer encryption.
  • B. Malware detection would prompt endpoint protection and network monitoring, not specifically transportation-level encryption.
  • C. Authentication attacks would trigger access control and authentication mechanism improvements, not wireless data-in-transit encryption.

Question 10

Show the case study this question is based on

SCENARIO

Kyle is a new security compliance manager who will be responsible for coordinating and executing controls to ensure compliance with the company's information security policy and industry standards. Kyle is also new to the company, where collaboration is a core value. On his first day of new-hire orientation, Kyle's schedule included participating in meetings and observing work in the IT and compliance departments.

Kyle spent the morning in the IT department, where the CIO welcomed him and explained that her department was responsible for IT governance.

The CIO and Kyle engaged in a conversation about the importance of identifying meaningful IT governance metrics. Following their conversation, the CIO introduced Kyle to Ted and Barney. Ted is implementing a plan to encrypt data at the transportation level

of the organization's wireless network. Kyle would need to get up to speed on the project and suggest ways to monitor effectiveness once the implementation was complete. Barney explained that his short-term goals are to establish rules governing where data can be placed and to minimize the use of offline data storage.

Kyle spent the afternoon with Jill, a compliance specialist, and learned that she was exploring an initiative for a compliance program to follow self-regulatory privacy principles. Thanks to a recent internship, Kyle had some experience in this area and knew where Jill could find some support. Jill also shared results of the company's privacy risk assessment, noting that the secondary use of personal information was considered a high risk.

By the end of the day, Kyle was very excited about his new job and his new company. In fact, he learned about an open position for someone with strong qualifications and experience with access privileges, project standards board approval processes, and application-level obligations, and couldn't wait to recommend his friend Ben who would be perfect for the job.

Which of the following should Kyle recommend to Jill as the best source of support for her initiative?

  1. Investors.
  2. Regulators.
  3. Industry groups.
  4. Corporate researchers.
Show answer and explanation

Correct answer: C. Industry groups.

Jill is establishing a compliance program based on self-regulatory privacy principles. Self- regulatory privacy principles are developed and promoted by industry groups such as privacy trade associations and industry consortiums that establish best practices and standards for their sectors. Industry groups provide the established frameworks, guidelines, and peer support necessary for implementing self-regulatory approaches. Option A (investors) focus on financial returns, Option B (regulators) enforce legal requirements rather than self-regulatory frameworks, and Option D (corporate researchers) lack the cross-industry perspective and established privacy principles that industry groups provide.

Why the other options are wrong

  • A. Investors are concerned with financial performance and returns, not privacy program frameworks.
  • B. Regulators enforce mandatory legal compliance, not self-regulatory privacy principles.
  • D. Corporate researchers may lack the broad industry perspective and established self- regulatory standards.

That was 10 of 325.

The full IAPP CIPT pack has all 325 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack