CIPM IAPP EXAM QUESTIONS AND
CORRECT ANSWERS
When an individual is unable to provide their point, this may result with the exclusion of
elements of a measurement when conveying results - Answer-Semi-attachment
This measurement completely excludes certain elements from the data population, thus
providing on a partial set of data and leading to false assumptions - Answer-Biased
Sample
An ethical issue, this occurs when data is knowingly and purposely omitted that may
have a detrimental effect on the metric or metric owner - Answer-Intentional Deciet
This is slightly adjusting measurements to provide the appearance of success or other-
than-actual results, leading the reviewer to believe the metric is more successful than it
actually may be - Answer-Massaging the Numbers
Per recent industry surveys, Chief Information Security Officers seem to prefer which
type of measurements? - Answer-Qualitative measurements
This type of metric evolves with time - Answer-Dynamic measurements
The distinction between direct and indirect metrics is based on what? - Answer-The way
a metric is measured
Size is an example of what type of metric - Answer-Direct
Quality or complexity can only be measured how? - Answer-Indirectly by extrapolation
from other measured factors
The privacy professional must guard against improper conclusions such as these -
Answer-Faulty Assumptions, Selective Use, Well-chosen Average, Semi-attachment,
Biased Sample, Intentional Deceit, Massaging the Numbers, Overgeneralization
This conclusion is based on the occurrence of concurrent events without substantive
evidence correlating the events - Answer-Faulty Assumptions
This is a specific subset of information is extrapolated from the larger data set, which
leads to invalid/incorrect conclusions. - Answer-Selective Use
Many times the mean is used for a metric, but it is sometimes more appropriate to use
the median or mode rather than the true mean/average - Answer-Well-chosen Average
,This occurs when inferences are made concerning a general data population that leads
to poor conclusions - Answer-Over-generalizations
As a basic business practice in the selection of metrics, the privacy professional should
select how many key privacy metrics that focus on the key organizational objectives -
Answer-Three to five
This is a data pattern that shows trends in an upwards or downward tendency i.e,
privacy breaches over time - Answer-Time series
This is an indicator used to measure the financial gain/loss (or value) of a project in
relation to its cost - Answer-Return on Investment (ROI)
Return on Investment (ROI) is measured how - Answer-(Benefits - Costs) / Costs
Privacy ROI defines metrics to measure the effectiveness of investments to protect
investments in what? - Answer-Physical assets, Personnel assets, IT assets,
Operational assets
This term relates to the protection of hardware, software, and data against physical
threats, to reduce or prevent disruptions to operations and services and loss of assets -
Answer-Physical assets
These are measures to reduce the likelihood and severity of accidental and intentional
alteration, destruction, misappropriation, misuse, misconfiguration, unauthorized
distribution and unavailability of an organization's logical and physical assets, as the
result of action or inaction by insiders and known outsiders, like business partners -
Answer-Personnel assets
Inherent technical features that collectively protect the organizational infrastructure,
achieving and sustaining confidentiality, integrity, availability, and accountability. -
Answer-IT assets
As it relates to ROI metrics, the first step is to identify and characterize the ROI metric to
address what? - Answer-The specific risk that control or feature is supposed to mitigate
As it relates to ROI metrics, the second step is to define what - Answer-the value of the
asset
This is the ability to rapidly adapt and respond to business disruptions and to maintain
continuous business operations - Answer-Business Resiliency
The privacy professional or organization should include in the privacy budget the costs
to generate what? - Answer-metrics
, The most time consuming task of a privacy professional was of a strategic nature, which
was what? - Answer-advising the organization on privacy issues
What are the phases of the privacy operational life cycle - Answer-o Assess (measure)
o Protect (improve) \n\n o Sustain (evaluate) \n\n o Respond (support)
What are the PMM maturity levels? - Answer-Ad hoc, Repeatable, Defined, Managed,
Optimized
This PMM maturity level indicates procedures or processes are generally informal,
incomplete, and inconsistently applied - Answer-Ad hoc
This PMM maturity level indicates procedures or processes exist; however, they are not
fully documented and do not cover all relevant aspects - Answer-Repeatable
This PMM maturity level indicates procedures or processes are fully documented and
implemented and cover all relevant aspects - Answer-Defined
This PMM maturity level indicates that reviews are conducted to assess the
effectiveness of the controls in place - Answer-Managed
This PMM maturity level indicates that regular review and feedback is used to ensure
continuous improvement towards optimization of the given process - Answer-Optimized
What are the seven foundational principles of PbD? - Answer-Proactive not Reactive-
Preventative not Remedial; Privacy as the Default Setting; Privacy Embedded into
Design; Full Functionality-Positive Sum not Zero-sum; End-to-End Security-Full Life
Cycle Protection; Visibility and Transparency; Respect for User Privacy
This ensures that privacy and security controls and aligned with an organization's
tolerance for risk and its compliance with regulations and commitment to building a
sustainable privacy-minded culture - Answer-PbD paradigm
One tool used to determine whether a PIA should be conducted is called what? -
Answer-Privacy Threshold Analysis (PTA)
These type of assessments further assist the privacy professional in the Protect phase -
Answer-PIA, risk assessments, security assessments
This is a policy-based approach to manage the flow of information through a life cycle
from creation to final disposition - Answer-DLM/ILM
Main drivers of DLM/ILM - Answer-1. Enterprise data growth 2. Growth in unstructured
data \n\n 3. Limitations in relational database management system performance \n\n 4.
Information access and security concerns\n5. Lack of effective methods for classifying
data \n6. Difficulty in assessing productivity of systems, applications and databases
CORRECT ANSWERS
When an individual is unable to provide their point, this may result with the exclusion of
elements of a measurement when conveying results - Answer-Semi-attachment
This measurement completely excludes certain elements from the data population, thus
providing on a partial set of data and leading to false assumptions - Answer-Biased
Sample
An ethical issue, this occurs when data is knowingly and purposely omitted that may
have a detrimental effect on the metric or metric owner - Answer-Intentional Deciet
This is slightly adjusting measurements to provide the appearance of success or other-
than-actual results, leading the reviewer to believe the metric is more successful than it
actually may be - Answer-Massaging the Numbers
Per recent industry surveys, Chief Information Security Officers seem to prefer which
type of measurements? - Answer-Qualitative measurements
This type of metric evolves with time - Answer-Dynamic measurements
The distinction between direct and indirect metrics is based on what? - Answer-The way
a metric is measured
Size is an example of what type of metric - Answer-Direct
Quality or complexity can only be measured how? - Answer-Indirectly by extrapolation
from other measured factors
The privacy professional must guard against improper conclusions such as these -
Answer-Faulty Assumptions, Selective Use, Well-chosen Average, Semi-attachment,
Biased Sample, Intentional Deceit, Massaging the Numbers, Overgeneralization
This conclusion is based on the occurrence of concurrent events without substantive
evidence correlating the events - Answer-Faulty Assumptions
This is a specific subset of information is extrapolated from the larger data set, which
leads to invalid/incorrect conclusions. - Answer-Selective Use
Many times the mean is used for a metric, but it is sometimes more appropriate to use
the median or mode rather than the true mean/average - Answer-Well-chosen Average
,This occurs when inferences are made concerning a general data population that leads
to poor conclusions - Answer-Over-generalizations
As a basic business practice in the selection of metrics, the privacy professional should
select how many key privacy metrics that focus on the key organizational objectives -
Answer-Three to five
This is a data pattern that shows trends in an upwards or downward tendency i.e,
privacy breaches over time - Answer-Time series
This is an indicator used to measure the financial gain/loss (or value) of a project in
relation to its cost - Answer-Return on Investment (ROI)
Return on Investment (ROI) is measured how - Answer-(Benefits - Costs) / Costs
Privacy ROI defines metrics to measure the effectiveness of investments to protect
investments in what? - Answer-Physical assets, Personnel assets, IT assets,
Operational assets
This term relates to the protection of hardware, software, and data against physical
threats, to reduce or prevent disruptions to operations and services and loss of assets -
Answer-Physical assets
These are measures to reduce the likelihood and severity of accidental and intentional
alteration, destruction, misappropriation, misuse, misconfiguration, unauthorized
distribution and unavailability of an organization's logical and physical assets, as the
result of action or inaction by insiders and known outsiders, like business partners -
Answer-Personnel assets
Inherent technical features that collectively protect the organizational infrastructure,
achieving and sustaining confidentiality, integrity, availability, and accountability. -
Answer-IT assets
As it relates to ROI metrics, the first step is to identify and characterize the ROI metric to
address what? - Answer-The specific risk that control or feature is supposed to mitigate
As it relates to ROI metrics, the second step is to define what - Answer-the value of the
asset
This is the ability to rapidly adapt and respond to business disruptions and to maintain
continuous business operations - Answer-Business Resiliency
The privacy professional or organization should include in the privacy budget the costs
to generate what? - Answer-metrics
, The most time consuming task of a privacy professional was of a strategic nature, which
was what? - Answer-advising the organization on privacy issues
What are the phases of the privacy operational life cycle - Answer-o Assess (measure)
o Protect (improve) \n\n o Sustain (evaluate) \n\n o Respond (support)
What are the PMM maturity levels? - Answer-Ad hoc, Repeatable, Defined, Managed,
Optimized
This PMM maturity level indicates procedures or processes are generally informal,
incomplete, and inconsistently applied - Answer-Ad hoc
This PMM maturity level indicates procedures or processes exist; however, they are not
fully documented and do not cover all relevant aspects - Answer-Repeatable
This PMM maturity level indicates procedures or processes are fully documented and
implemented and cover all relevant aspects - Answer-Defined
This PMM maturity level indicates that reviews are conducted to assess the
effectiveness of the controls in place - Answer-Managed
This PMM maturity level indicates that regular review and feedback is used to ensure
continuous improvement towards optimization of the given process - Answer-Optimized
What are the seven foundational principles of PbD? - Answer-Proactive not Reactive-
Preventative not Remedial; Privacy as the Default Setting; Privacy Embedded into
Design; Full Functionality-Positive Sum not Zero-sum; End-to-End Security-Full Life
Cycle Protection; Visibility and Transparency; Respect for User Privacy
This ensures that privacy and security controls and aligned with an organization's
tolerance for risk and its compliance with regulations and commitment to building a
sustainable privacy-minded culture - Answer-PbD paradigm
One tool used to determine whether a PIA should be conducted is called what? -
Answer-Privacy Threshold Analysis (PTA)
These type of assessments further assist the privacy professional in the Protect phase -
Answer-PIA, risk assessments, security assessments
This is a policy-based approach to manage the flow of information through a life cycle
from creation to final disposition - Answer-DLM/ILM
Main drivers of DLM/ILM - Answer-1. Enterprise data growth 2. Growth in unstructured
data \n\n 3. Limitations in relational database management system performance \n\n 4.
Information access and security concerns\n5. Lack of effective methods for classifying
data \n6. Difficulty in assessing productivity of systems, applications and databases