CIPT CERTIFIED INFORMATION PRIVACY TECHNOLOGIST
FINAL EXAM 2026/2027 QUESTIONS AND SOLUTIONS
RATED A+
✔✔OBA/OBM - ✔✔Online behavioral advertising/online behavioral marketing
Via third-party tracking (e.g. web cookie) to collect and compile user information
✔✔LBS - ✔✔Location-based services
Computer program-level services that include controls for location and time data
E.g. social networking, entertainment, many via mobile devices
Issues: data collection, consent, data sharing
✔✔P3P Privacy Policies - ✔✔P3P = Platform for Privacy Preferences Project, designed
by the World Wide Web
Consortium (aka W3C)
P3P - a protocol that turns a website's text-based privacy policies into a
machinereadable
format
✔✔When must a PIA be conducted - ✔✔Prior to developing or obtaining and IT system
or process which collects,
stores or discloses personally identifiable information
✔✔Do Not Track - ✔✔Do Not Track protection is a feature that is being worked on by
the World Wide Web Consortium tracking protection working group.
The four major browsers - Safari, Firefox, Chrome and Internet Explorer - have
incorporated the Do Not Track feature.
✔✔Site blockers - ✔✔Site blocking tools such as Adblock Plus, DoNotTrackMe and
Internet Explorer's tracking protection feature block cookies and the connection between
third-party sites and your browser.
✔✔Browsing anonymity - ✔✔Tor and similar services permit you to browse the internet
anonymously. Tor works by directing traffic between two endpoints through multiple
intermediate nodes.
✔✔E-mail anonymity - ✔✔There are several tools like MaskMe and Lockify that allow
you to protect your email. MaskMe lets you create a fake e-mail address that you can
use when signing up for web services so you won't receive their spam
, ✔✔Homomorphic encryption - ✔✔Homomorphic encryption makes it possible to
perform mathematical functions on encrypted data. This reduces the risk of data
exposure while maintaining its utility
✔✔Cross-site scripting (XSS - ✔✔Cross-site scripting embeds client-side script into a
webpage.
The script executes when a user visits the page
✔✔Spam - ✔✔Spam often refers to legitimate but unwanted e-mail. Spam can also
contain phishing, malware or viruses.
✔✔SQL injection - ✔✔SQL injection is where SQL commands are embedded into a
form or website.
✔✔Pharming - ✔✔Pharming is when a person types a legitimate URL into a browser
but is rerouted to a fake website.
✔✔Whaling - ✔✔Whaling is a type of phishing targeted at people who have lots of
money, power or
information, such as C-level executives
✔✔Spear phishing - ✔✔Phishing is where what seems to be reputable company sends
an e-mail to an individual with a link that goes to a fake site that looks like a real site.
✔✔APPEL - ✔✔Application Preference Exchange Language Application Preference
Exchange Language, known as APPEL, is a complimentary specification to P3P that
enables users to express their privacy preferences in an XML document. B
✔✔EPAL - ✔✔Enterprise Privacy Authorization Language Enterprise Privacy
Authorization Language, known as EPAL, was a language developed by IBM based on
the Privacy Rights Markup Language from Zero Knowledge Systems.
✔✔SAML - ✔✔Security Assertion Markup Language Security Assertion Markup
Language, or SAML, is an XML- based format that exchanges data about the identity,
attributes and entitlements of an individual to an application or service
✔✔Pseudonymous - ✔✔Pseudonymous means that while you don't actually know who
a person is, you can tell when
different pieces of data are about the same unidentified person.
✔✔Anonymous - ✔✔Anonymous basically means you have no idea who the person is
or who the data belongs to, and
no way to figure out that information.
FINAL EXAM 2026/2027 QUESTIONS AND SOLUTIONS
RATED A+
✔✔OBA/OBM - ✔✔Online behavioral advertising/online behavioral marketing
Via third-party tracking (e.g. web cookie) to collect and compile user information
✔✔LBS - ✔✔Location-based services
Computer program-level services that include controls for location and time data
E.g. social networking, entertainment, many via mobile devices
Issues: data collection, consent, data sharing
✔✔P3P Privacy Policies - ✔✔P3P = Platform for Privacy Preferences Project, designed
by the World Wide Web
Consortium (aka W3C)
P3P - a protocol that turns a website's text-based privacy policies into a
machinereadable
format
✔✔When must a PIA be conducted - ✔✔Prior to developing or obtaining and IT system
or process which collects,
stores or discloses personally identifiable information
✔✔Do Not Track - ✔✔Do Not Track protection is a feature that is being worked on by
the World Wide Web Consortium tracking protection working group.
The four major browsers - Safari, Firefox, Chrome and Internet Explorer - have
incorporated the Do Not Track feature.
✔✔Site blockers - ✔✔Site blocking tools such as Adblock Plus, DoNotTrackMe and
Internet Explorer's tracking protection feature block cookies and the connection between
third-party sites and your browser.
✔✔Browsing anonymity - ✔✔Tor and similar services permit you to browse the internet
anonymously. Tor works by directing traffic between two endpoints through multiple
intermediate nodes.
✔✔E-mail anonymity - ✔✔There are several tools like MaskMe and Lockify that allow
you to protect your email. MaskMe lets you create a fake e-mail address that you can
use when signing up for web services so you won't receive their spam
, ✔✔Homomorphic encryption - ✔✔Homomorphic encryption makes it possible to
perform mathematical functions on encrypted data. This reduces the risk of data
exposure while maintaining its utility
✔✔Cross-site scripting (XSS - ✔✔Cross-site scripting embeds client-side script into a
webpage.
The script executes when a user visits the page
✔✔Spam - ✔✔Spam often refers to legitimate but unwanted e-mail. Spam can also
contain phishing, malware or viruses.
✔✔SQL injection - ✔✔SQL injection is where SQL commands are embedded into a
form or website.
✔✔Pharming - ✔✔Pharming is when a person types a legitimate URL into a browser
but is rerouted to a fake website.
✔✔Whaling - ✔✔Whaling is a type of phishing targeted at people who have lots of
money, power or
information, such as C-level executives
✔✔Spear phishing - ✔✔Phishing is where what seems to be reputable company sends
an e-mail to an individual with a link that goes to a fake site that looks like a real site.
✔✔APPEL - ✔✔Application Preference Exchange Language Application Preference
Exchange Language, known as APPEL, is a complimentary specification to P3P that
enables users to express their privacy preferences in an XML document. B
✔✔EPAL - ✔✔Enterprise Privacy Authorization Language Enterprise Privacy
Authorization Language, known as EPAL, was a language developed by IBM based on
the Privacy Rights Markup Language from Zero Knowledge Systems.
✔✔SAML - ✔✔Security Assertion Markup Language Security Assertion Markup
Language, or SAML, is an XML- based format that exchanges data about the identity,
attributes and entitlements of an individual to an application or service
✔✔Pseudonymous - ✔✔Pseudonymous means that while you don't actually know who
a person is, you can tell when
different pieces of data are about the same unidentified person.
✔✔Anonymous - ✔✔Anonymous basically means you have no idea who the person is
or who the data belongs to, and
no way to figure out that information.