CIPT CERTIFIED INFORMATION PRIVACY TECHNOLOGIST
UPDATED EXAM SCRIPT 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔Anonymous - ✔✔Anonymous basically means you have no idea who the person is
or who the data belongs to, and
no way to figure out that information.
✔✔Basel III Encryption - ✔✔Basel III mandates encryption of financial data for EU
companies. HIPAA mandates the encryption of sensitive health information for
American companies
✔✔symmetric encryption - ✔✔Symmetric encryption uses the same key for encrypting
and decrypting data. It's a great means for encrypting data that needs to be sent to
multiple people.
✔✔asymmetric encryption or Public Key - ✔✔Asymmetric encryption uses one key for
encrypting data and a different key for decrypting the same data.
✔✔hashing - ✔✔Hashing enables you to encrypt data in a way that can't be decrypted.
✔✔Web Beacons - ✔✔Web beacons are practically invisible. They are used to either
drop web cookies or track individuals using their IP address.
✔✔Locally shared objects - ✔✔Locally shared objects come in different forms: HTML5
storage, civilized storage and flash storage are a few examples. In
✔✔Open ID - ✔✔• Open ID is the most common single sign-on mechanism used over
the Internet. It is used by LinkedIn, Facebook and Google to provide authentication
services
✔✔Role-based access control - ✔✔Users are placed into security groups that match
their roles in the organization, and those groups are provided access to resources.
✔✔User-based access control - ✔✔user-based access control provides a simple and
effective control mechanism. However, an administrator is required to add, edit or
remove users or to change access levels.
✔✔Least privilege access - ✔✔Granting the lowest possible access
✔✔Choice/Consent - ✔✔Individuals must be able to consent or reject to certain uses of
their personal information, particularly with regard to secondary uses and marketing
purposes
, ✔✔Opt in: - ✔✔Require affirmative consent from the individual. In other words, action
must be taken by the individual to START the processing of personal information for
secondary uses or disclosures.
✔✔Opt Out: - ✔✔Requires the implicit consent of the individual. Here consent is
assumed because the individual has not stated a desire otherwise.
✔✔Access/Participation - ✔✔An individual must be able to view the data an entity has
on record
✔✔Integrity/Security - ✔✔Data must be accurate, up-to-date, complete and not stored
longer than necessary.
✔✔Enforcement/Redress - ✔✔An individual must be able to file complaints with the
entity have their issues addressed
✔✔Persistent Data Storage - ✔✔Data stored beyond current transaction Transaction
history can be stored and retrieved later
✔✔Transient Data Storage - ✔✔Data stored for the current transaction, deleted
afterwards
Fewer privacy implications than persistent storage
✔✔Anonymity-based techniques - ✔✔Such techniques are focused on making an
individual's identity or personal information not identifiable
✔✔Obfuscation-based techniques - ✔✔In order to make it more difficult to link de-
identified information back to individuals, obfuscation-based techniques disguise
location and time information by decreasing precision/accuracy and adding confusion to
the data.
✔✔De-identification - ✔✔De-identification refers to the process in which sensitive data
is treated in such a way that the individual cannot be identified
✔✔Data mining - ✔✔Data mining companies will often gather personal information from
dentists, doctors, nurses or pharmacists.
✔✔Privacy by Policy - ✔✔.Notice and choice‖ approach founded on FTC Fair
Information Practice Principles
• Objectives:
o Inform users on data being collected
o Present choices for sharing data (e.g. secondary uses of data)
o Give users access to data for review/correction/removal purposes
o Protect security of data
UPDATED EXAM SCRIPT 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔Anonymous - ✔✔Anonymous basically means you have no idea who the person is
or who the data belongs to, and
no way to figure out that information.
✔✔Basel III Encryption - ✔✔Basel III mandates encryption of financial data for EU
companies. HIPAA mandates the encryption of sensitive health information for
American companies
✔✔symmetric encryption - ✔✔Symmetric encryption uses the same key for encrypting
and decrypting data. It's a great means for encrypting data that needs to be sent to
multiple people.
✔✔asymmetric encryption or Public Key - ✔✔Asymmetric encryption uses one key for
encrypting data and a different key for decrypting the same data.
✔✔hashing - ✔✔Hashing enables you to encrypt data in a way that can't be decrypted.
✔✔Web Beacons - ✔✔Web beacons are practically invisible. They are used to either
drop web cookies or track individuals using their IP address.
✔✔Locally shared objects - ✔✔Locally shared objects come in different forms: HTML5
storage, civilized storage and flash storage are a few examples. In
✔✔Open ID - ✔✔• Open ID is the most common single sign-on mechanism used over
the Internet. It is used by LinkedIn, Facebook and Google to provide authentication
services
✔✔Role-based access control - ✔✔Users are placed into security groups that match
their roles in the organization, and those groups are provided access to resources.
✔✔User-based access control - ✔✔user-based access control provides a simple and
effective control mechanism. However, an administrator is required to add, edit or
remove users or to change access levels.
✔✔Least privilege access - ✔✔Granting the lowest possible access
✔✔Choice/Consent - ✔✔Individuals must be able to consent or reject to certain uses of
their personal information, particularly with regard to secondary uses and marketing
purposes
, ✔✔Opt in: - ✔✔Require affirmative consent from the individual. In other words, action
must be taken by the individual to START the processing of personal information for
secondary uses or disclosures.
✔✔Opt Out: - ✔✔Requires the implicit consent of the individual. Here consent is
assumed because the individual has not stated a desire otherwise.
✔✔Access/Participation - ✔✔An individual must be able to view the data an entity has
on record
✔✔Integrity/Security - ✔✔Data must be accurate, up-to-date, complete and not stored
longer than necessary.
✔✔Enforcement/Redress - ✔✔An individual must be able to file complaints with the
entity have their issues addressed
✔✔Persistent Data Storage - ✔✔Data stored beyond current transaction Transaction
history can be stored and retrieved later
✔✔Transient Data Storage - ✔✔Data stored for the current transaction, deleted
afterwards
Fewer privacy implications than persistent storage
✔✔Anonymity-based techniques - ✔✔Such techniques are focused on making an
individual's identity or personal information not identifiable
✔✔Obfuscation-based techniques - ✔✔In order to make it more difficult to link de-
identified information back to individuals, obfuscation-based techniques disguise
location and time information by decreasing precision/accuracy and adding confusion to
the data.
✔✔De-identification - ✔✔De-identification refers to the process in which sensitive data
is treated in such a way that the individual cannot be identified
✔✔Data mining - ✔✔Data mining companies will often gather personal information from
dentists, doctors, nurses or pharmacists.
✔✔Privacy by Policy - ✔✔.Notice and choice‖ approach founded on FTC Fair
Information Practice Principles
• Objectives:
o Inform users on data being collected
o Present choices for sharing data (e.g. secondary uses of data)
o Give users access to data for review/correction/removal purposes
o Protect security of data