Question 1
An organization wants to demonstrate its compliance with privacy laws through documented policies and procedures. What principle best describes this approach?
Show answer & explanation
Correct answer: A - Accountability
10 free, exam-style Certified Information Privacy Manager (CIPM) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CIPM practice test to study every exam domain.
These 10 free CIPM questions are organized by exam domain, so you can see how each part of the Certified Information Privacy Manager blueprint is tested. Reveal the answer and explanation under each question.
An organization wants to demonstrate its compliance with privacy laws through documented policies and procedures. What principle best describes this approach?
Correct answer: A - Accountability
When establishing AI governance policies, what role should the privacy team play?
Correct answer: B - Defining policies for data minimization and bias testing
During vendor assessment, the processor cannot demonstrate SOC 2 compliance or alternative security attestation. What action is required?
Correct answer: B - Conduct assessment or select alternative vendor
Scenario: During vendor assessment, you discover a cloud provider's subprocessor is in a country without adequacy decision. What is required?
Correct answer: B - Conducting TIA and ensuring SCCs with safeguards
A company trains a facial recognition AI on employee photos without consent. What principle is violated?
Correct answer: B - Data minimization, purpose limitation, and consent
Scenario: A privacy audit reveals 23% of staff have not completed annual training. Your response should include:
Correct answer: B - Implementing mandatory training and tracking compliance
Privacy program shows 95% policy compliance, yet customer complaints increased 40%. What does this indicate?
Correct answer: B - Metrics focus on wrong indicators
When breach notification timing is legally required (72 hours), but investigation is incomplete, what should you communicate?
Correct answer: B - Provide initial notification with known facts
Under GDPR, how long does an organization have to respond to a DSAR?
Correct answer: A - 1 month, extendable to 3 months
A breach affects 500 EU residents, 1000 California residents, and 300 Virginia residents. What notification obligations exist?
Correct answer: B - Notify per each jurisdiction's requirements
Practice hundreds more CIPM questions with instant scoring, weak-area drills, and full exam simulations.