CIPT Exam Questions with Correct Answers
Access Control Entry
An element in an access control list (ACL). Each ACE controls, monitors, or records access
to an object by a specified user.
Access Control List
A list of access control entries (ACE) that apply to an object. Each ACE controls or monitors
access to an object by a specified user.
Discretionary access control list (DACL)
The ACL controls access
System access control list (SACL)
ACL monitors access in a security event log which can comprise part of an audit trail.
Accountability
A fair information practices principle, when personal information is to be transferred to
another person or organization, the personal information controller should obtain the consent
of the individual /exercise due diligence & take reasonable steps to ensure that the recipient
person/organization will protect the information consistently with other fair use principles.
Active Data Collection
When an end user deliberately provides information, typically through the use of web forms,
text boxes, check boxes or radio buttons.
Passive Data Collection
Collecting data from a data subject that is unaware of such collection.
,First-party Collection
A data subject provides personal data to the collector directly, through a form or survey that
is sent to the collector upon the data subject submitting the information
Surveillance Collection
Collection by way of observing the data stream produced by a given data subject without
interference in the data subject's activity.
Repurposing
Taking information collected for one purpose and using it for another purpose later on.
Third-party Collection
Transferring data collected to another collector for their use and repurposing.
Risk Controls
Administrative Controls, Technical Controls, & Physical Controls
Risk Responses
Accept, Transfer, Mitigate, Avoid
Functional Requirements
Specific function intended for a system
Types of data collection
- First party
- Surveillance
- Repurposing
- Third party
,Nonfunctional Requirements
Constraint or property of a system that an engineer can trace to functional requirements or
design elements
Legal Standards
Nonfunctional requirements or properties that cut across a system's design and functionality
Legal Rules
Specific steps to comply with privacy law
Childrens Online Privacy Protection Act - COPPA
Obtain verifiable parental consent before any collection, use, and/or disclosure of personal
information from children under 13
Fingerprinting
K-Annoynominity
Authentication
- What you know
- What you have
- Where you are
- What you are
AdChoices
Digital Advertising Alliance program to promote awareness and choice in advertising for
internet users. DAA member websites have AdChoices icon near ads or at the bottom of their
pages for users to set preferences for behavioral advertising on that website.
, Adequate Level of Protection
A label that the EU may apply to third-party countries who have committed to protect data
through domestic law making or international commitments. Conferring of the label requires
a proposal by the European Commission, an Article 29 Working Group Opinion, an opinion
of the article 31 Management Committee, a right of scrutiny by the European Parliament and
adoption by the European Commission.
Advanced Encryption Standard (AES)
Type of symmetric encryption. An encryption algorithm for security sensitive non-classified
material by the U.S. Government. In 2001 to replace the previous algorithm, the Date
Encryption Standard (DES).
Adverse Action
Under the Fair Credit Reporting Act, the term "adverse action" is defined very broadly to
include all business, credit and employment actions affecting consumers that can be
considered to have a negative impact, such as denying or canceling credit or insurance, or
denying employment or promotion. No adverse action occurs in a credit transaction where the
creditor makes a counteroffer that is accepted by the consumer. Such an action requires that
the decision maker furnish the recipient of the adverse action with a copy of the credit report
leading to the adverse action.
Agile Development Model
A process of software system and product design that incorporates new system requirements
during the actual creation of the system, as opposed to the Plan-Driven Development Model.
Anonymization
Access Control Entry
An element in an access control list (ACL). Each ACE controls, monitors, or records access
to an object by a specified user.
Access Control List
A list of access control entries (ACE) that apply to an object. Each ACE controls or monitors
access to an object by a specified user.
Discretionary access control list (DACL)
The ACL controls access
System access control list (SACL)
ACL monitors access in a security event log which can comprise part of an audit trail.
Accountability
A fair information practices principle, when personal information is to be transferred to
another person or organization, the personal information controller should obtain the consent
of the individual /exercise due diligence & take reasonable steps to ensure that the recipient
person/organization will protect the information consistently with other fair use principles.
Active Data Collection
When an end user deliberately provides information, typically through the use of web forms,
text boxes, check boxes or radio buttons.
Passive Data Collection
Collecting data from a data subject that is unaware of such collection.
,First-party Collection
A data subject provides personal data to the collector directly, through a form or survey that
is sent to the collector upon the data subject submitting the information
Surveillance Collection
Collection by way of observing the data stream produced by a given data subject without
interference in the data subject's activity.
Repurposing
Taking information collected for one purpose and using it for another purpose later on.
Third-party Collection
Transferring data collected to another collector for their use and repurposing.
Risk Controls
Administrative Controls, Technical Controls, & Physical Controls
Risk Responses
Accept, Transfer, Mitigate, Avoid
Functional Requirements
Specific function intended for a system
Types of data collection
- First party
- Surveillance
- Repurposing
- Third party
,Nonfunctional Requirements
Constraint or property of a system that an engineer can trace to functional requirements or
design elements
Legal Standards
Nonfunctional requirements or properties that cut across a system's design and functionality
Legal Rules
Specific steps to comply with privacy law
Childrens Online Privacy Protection Act - COPPA
Obtain verifiable parental consent before any collection, use, and/or disclosure of personal
information from children under 13
Fingerprinting
K-Annoynominity
Authentication
- What you know
- What you have
- Where you are
- What you are
AdChoices
Digital Advertising Alliance program to promote awareness and choice in advertising for
internet users. DAA member websites have AdChoices icon near ads or at the bottom of their
pages for users to set preferences for behavioral advertising on that website.
, Adequate Level of Protection
A label that the EU may apply to third-party countries who have committed to protect data
through domestic law making or international commitments. Conferring of the label requires
a proposal by the European Commission, an Article 29 Working Group Opinion, an opinion
of the article 31 Management Committee, a right of scrutiny by the European Parliament and
adoption by the European Commission.
Advanced Encryption Standard (AES)
Type of symmetric encryption. An encryption algorithm for security sensitive non-classified
material by the U.S. Government. In 2001 to replace the previous algorithm, the Date
Encryption Standard (DES).
Adverse Action
Under the Fair Credit Reporting Act, the term "adverse action" is defined very broadly to
include all business, credit and employment actions affecting consumers that can be
considered to have a negative impact, such as denying or canceling credit or insurance, or
denying employment or promotion. No adverse action occurs in a credit transaction where the
creditor makes a counteroffer that is accepted by the consumer. Such an action requires that
the decision maker furnish the recipient of the adverse action with a copy of the credit report
leading to the adverse action.
Agile Development Model
A process of software system and product design that incorporates new system requirements
during the actual creation of the system, as opposed to the Plan-Driven Development Model.
Anonymization