CIPT 2026/2027 QUESTIONS AND SOLUTIONS RATED A+
✔✔Software error - ✔✔The difference between a computed, observed or measured
value or condition and the true, specified or theoretically correct value or condition
✔✔Software failure - ✔✔The inability of a system or component to perform its required
functions within specified performance requirements
✔✔Software harm - ✔✔The actual or potential ill effect or danger to an individual's
personal privacy (sometimes called a hazard)
✔✔Incident response - ✔✔An incident response program should have representatives
from public relations, legal, privacy and security & the webform, email or phone number
should be easily accessible from the privacy notice. Privacy incidents can occur due to
poorly applied security controls.
Ex: improper access controls can permit inappropriate access to data
✔✔Regulations & standards that affect data governance & support internal,
organizational privacy standards - ✔✔- Sarbanes-Oxley (SOX) which aims to improve
corporate accounting
- Basel II, which aims to improve credit risk calculations
- HIPAA Privacy Rule, which requires accounting for medical information disclosures
✔✔Information governance principles - ✔✔1. Accountability
2. Transparency
3. Integrity
4. Protection
5. Compliance
6. Availability
7. Retention
8. Disposition
✔✔Privacy role of the IT professional - ✔✔The privacy professional is a translator sitting
at the center balancing the requirements espoused by various stakeholders &
organizing those requirements into structured themes & elements that enable the
success of each stakeholder as well as the overall success of the enterprise-wide
privacy governance program
✔✔Providing feedback on policies - ✔✔Organizational policies identify key objectives
that must be met, and privacy professionals & engineers define the governance
program and identify manual & automated aspects
✔✔Providing feedback on contractural & regulatory requirements - ✔✔Compliance
offers a structure for the privacy program; reasonable assurance is fundamental in
privacy & compliance
,✔✔Reasonable assurance - ✔✔Requirements & objectives are not absolute, but rather
based upon some criteria that is deemed practical to implement & manage; it affords
flexibility & is greatly valuable for managing potential overengineering of solutions
✔✔Internal controls - ✔✔Objectives tied to practical measurements and designed to
evaluate components governed by the privacy program
✔✔IT & InfoSec support information governance - ✔✔Security reasonably assures that
two parties exchange personal data securely, while privacy reasonably assures that the
authorized parties are using the personal data appropriately
✔✔Taxonomy of privacy problems during information collection - ✔✔- Surveillance
- Interrogation
✔✔Taxonomy of privacy problems during information processing - ✔✔- Aggregation
- Identification
- Insecurity
- Secondary use
- Exclusion
✔✔Taxonomy of privacy problems during information dissemination - ✔✔- Breach of
confidentiality
- Disclosure
- Distortion
- Exposure
- Increased accessibility
- Blackmail
- Appropriation
✔✔Intrusion - ✔✔any action that affects a person's solitude, including their desire to be
alone and their desire to control who has access to their information
✔✔Obstruction - ✔✔any action to interfere with decisions that affect the person's daily
life
✔✔Interference with self-representation - ✔✔any action that alters how an individual is
represented regardless of whether the representation is accurate or a misrepresentation
✔✔Surveillance - ✔✔Involves the observation and/or capturing of an individual's
activities
✔✔Interrogation - ✔✔Involves actively questioning an individual or otherwise probing
for information; privacy violation occurs when questions breach social boundaries
, ✔✔Aggregation - ✔✔Involves combining multiple pieces of information about an
individual to produce a while that is greater than the sum of its parts (e.g., retail
company correlates purchases of unscented lotions, large tote bags and prenatal
vitamins to infer that a customer is pregnant)
✔✔Identification - ✔✔Linking information to specific individuals (e.g., website uses
cookies, recurring IP address or unique device identifier to link an individual's browsing
history to their identity)
✔✔Insecurity - ✔✔Failure to properly protect an individual's information
✔✔Secondary use - ✔✔Involves using an individual's information without consent for
purposes unrelated to the original reasons for which it was collected
✔✔Exclusion - ✔✔Denies an individual knowledge of and/or participation in what is
being done with their information
✔✔Breach of confidentiality - ✔✔Breaking a promise to keep an individual's information
confidential
✔✔Disclosure, as a privacy problem - ✔✔Involves revealing truthful information about
an individual that negatively affects how others view them
✔✔Distortion - ✔✔Involves spreading false & inaccurate information about an individual
✔✔Exposure - ✔✔Results from the revelation of information that we normally conceal
from others including private physical details about our bodies
✔✔Increased accessibility - ✔✔Involves rendering an individual's information more
easily obtainable
✔✔Blackmail - ✔✔Threat to disclose an individual's information against their will
✔✔Appropriation - ✔✔Involves using someone's identity for another person's purposes
✔✔Decisional interference - ✔✔Involves others inserting themselves into a decision-
making process that affects the individual's personal affairs
✔✔Behavioral advertising - ✔✔advertising that targets particular customers based on
their observed online behavior
(obstruction, intrusion, interference with self-representation)
✔✔Cyberbullying - ✔✔abusive attacks on individual targets conducted through
electronic channels (interference with self-representation / personal identity)
✔✔Software error - ✔✔The difference between a computed, observed or measured
value or condition and the true, specified or theoretically correct value or condition
✔✔Software failure - ✔✔The inability of a system or component to perform its required
functions within specified performance requirements
✔✔Software harm - ✔✔The actual or potential ill effect or danger to an individual's
personal privacy (sometimes called a hazard)
✔✔Incident response - ✔✔An incident response program should have representatives
from public relations, legal, privacy and security & the webform, email or phone number
should be easily accessible from the privacy notice. Privacy incidents can occur due to
poorly applied security controls.
Ex: improper access controls can permit inappropriate access to data
✔✔Regulations & standards that affect data governance & support internal,
organizational privacy standards - ✔✔- Sarbanes-Oxley (SOX) which aims to improve
corporate accounting
- Basel II, which aims to improve credit risk calculations
- HIPAA Privacy Rule, which requires accounting for medical information disclosures
✔✔Information governance principles - ✔✔1. Accountability
2. Transparency
3. Integrity
4. Protection
5. Compliance
6. Availability
7. Retention
8. Disposition
✔✔Privacy role of the IT professional - ✔✔The privacy professional is a translator sitting
at the center balancing the requirements espoused by various stakeholders &
organizing those requirements into structured themes & elements that enable the
success of each stakeholder as well as the overall success of the enterprise-wide
privacy governance program
✔✔Providing feedback on policies - ✔✔Organizational policies identify key objectives
that must be met, and privacy professionals & engineers define the governance
program and identify manual & automated aspects
✔✔Providing feedback on contractural & regulatory requirements - ✔✔Compliance
offers a structure for the privacy program; reasonable assurance is fundamental in
privacy & compliance
,✔✔Reasonable assurance - ✔✔Requirements & objectives are not absolute, but rather
based upon some criteria that is deemed practical to implement & manage; it affords
flexibility & is greatly valuable for managing potential overengineering of solutions
✔✔Internal controls - ✔✔Objectives tied to practical measurements and designed to
evaluate components governed by the privacy program
✔✔IT & InfoSec support information governance - ✔✔Security reasonably assures that
two parties exchange personal data securely, while privacy reasonably assures that the
authorized parties are using the personal data appropriately
✔✔Taxonomy of privacy problems during information collection - ✔✔- Surveillance
- Interrogation
✔✔Taxonomy of privacy problems during information processing - ✔✔- Aggregation
- Identification
- Insecurity
- Secondary use
- Exclusion
✔✔Taxonomy of privacy problems during information dissemination - ✔✔- Breach of
confidentiality
- Disclosure
- Distortion
- Exposure
- Increased accessibility
- Blackmail
- Appropriation
✔✔Intrusion - ✔✔any action that affects a person's solitude, including their desire to be
alone and their desire to control who has access to their information
✔✔Obstruction - ✔✔any action to interfere with decisions that affect the person's daily
life
✔✔Interference with self-representation - ✔✔any action that alters how an individual is
represented regardless of whether the representation is accurate or a misrepresentation
✔✔Surveillance - ✔✔Involves the observation and/or capturing of an individual's
activities
✔✔Interrogation - ✔✔Involves actively questioning an individual or otherwise probing
for information; privacy violation occurs when questions breach social boundaries
, ✔✔Aggregation - ✔✔Involves combining multiple pieces of information about an
individual to produce a while that is greater than the sum of its parts (e.g., retail
company correlates purchases of unscented lotions, large tote bags and prenatal
vitamins to infer that a customer is pregnant)
✔✔Identification - ✔✔Linking information to specific individuals (e.g., website uses
cookies, recurring IP address or unique device identifier to link an individual's browsing
history to their identity)
✔✔Insecurity - ✔✔Failure to properly protect an individual's information
✔✔Secondary use - ✔✔Involves using an individual's information without consent for
purposes unrelated to the original reasons for which it was collected
✔✔Exclusion - ✔✔Denies an individual knowledge of and/or participation in what is
being done with their information
✔✔Breach of confidentiality - ✔✔Breaking a promise to keep an individual's information
confidential
✔✔Disclosure, as a privacy problem - ✔✔Involves revealing truthful information about
an individual that negatively affects how others view them
✔✔Distortion - ✔✔Involves spreading false & inaccurate information about an individual
✔✔Exposure - ✔✔Results from the revelation of information that we normally conceal
from others including private physical details about our bodies
✔✔Increased accessibility - ✔✔Involves rendering an individual's information more
easily obtainable
✔✔Blackmail - ✔✔Threat to disclose an individual's information against their will
✔✔Appropriation - ✔✔Involves using someone's identity for another person's purposes
✔✔Decisional interference - ✔✔Involves others inserting themselves into a decision-
making process that affects the individual's personal affairs
✔✔Behavioral advertising - ✔✔advertising that targets particular customers based on
their observed online behavior
(obstruction, intrusion, interference with self-representation)
✔✔Cyberbullying - ✔✔abusive attacks on individual targets conducted through
electronic channels (interference with self-representation / personal identity)