Certified Information Privacy Professional/US (CIPP/US) Practice Test
The Certified Information Privacy Professional/United States (CIPP/US) credential, administered by the International Association of Privacy Professionals (IAPP), is the global standard for professionals responsible for US private-sector data privacy laws and regulations. This certification validates a comprehensive understanding of the complex American legal landscape governing data protection, including sectoral federal laws, evolving state-level regulations (notably the California Consumer Privacy Act and its successors), and the intricate frameworks for government access to information. Earning the CIPP/US demonstrates mastery of critical concepts such as data lifecycle management, consumer rights, regulatory enforcement, and compliance program development within the US context. It is recognized by employers, regulators, and courts as a benchmark of competency, signaling that the holder possesses the authoritative knowledge required to navigate compliance challenges, mitigate organizational risk, and implement effective privacy programs in one of the world's most dynamic regulatory environments.
Preguntas de Muestra
Prueba algunas preguntas para ver cómo es el examen completo.
30 de 161 respuestas incluyen una referencia verificable.
In 2025, counsel for a university vendor supporting alumni analytics reviews a launch plan. A website incorrectly states that analytics cookies are disabled by default, and the misstatement affects whether users create accounts. the product owner wants the same workflow on mobile. Which response best addresses the CIPP/US issue involving materiality in deception?
In 2025, counsel for a cloud service provider supporting a federal contractor reviews a launch plan. A news-style blog operated by a brand pairs a user photo with a headline implying the user bought addiction-treatment products, although the user only bought vitamins. the contract renewal is scheduled for the next quarter. Which response best addresses the CIPP/US issue involving false light?
Under most state breach notification laws, an "encryption safe harbor" applies when breached data was encrypted. However, a company suffers a breach where encrypted data AND the encryption key were both stolen together in the same incident. Does the encryption safe harbor apply?
In 2025, counsel for a health-tech startup outside HIPAA reviews a launch plan. Support logs containing ID scans are kept indefinitely because storage is cheap and deletion might require engineering work. the security team recently finished tabletop testing. Which response best addresses the CIPP/US issue involving retention limits?
A credit-reporting agency (CRA) includes information in a consumer's credit report indicating the consumer had a judgment for $3,500 entered 8 years ago. The consumer disputes this entry as too old. Under the FCRA's maximum reporting period rules, is this entry permissible?