IAPP CIPP-CN Certification Sample Questions

CIPP-CN Dumps, CIPP-CN PDF, CIPP-CN VCE, IAPP Certified Information Privacy Professional/China VCE, IAPP Information Privacy Professional/China PDFThe purpose of this Sample Question Set is to provide you with information about the IAPP Certified Information Privacy Professional/China (CIPP-CN) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CIPP-CN certification test. To get familiar with real exam environment, we suggest you try our Sample IAPP Information Privacy Professional/China Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual IAPP Certified Information Privacy Professional/China (CIPP-CN) certification exam.

These sample questions are simple and basic questions that represent likeness to the real IAPP Certified Information Privacy Professional/China exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium IAPP CIPP-CN Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

IAPP CIPP-CN Sample Questions:

01. Testing shows that a handler's automated pricing engine consistently quotes different terms to individuals grouped by characteristics unrelated to risk. What does the Personal Information Protection Law require the handler to do?
a)
Retrain the model on anonymized data so that the grouping characteristics are no longer present
b) Correct the system, because unreasonably differential treatment in transaction terms is prohibited whatever the model produced
c) Disclose the pricing logic in its privacy notice, after which the differential terms may continue to be applied
d) Offer affected individuals an explanation on request, which discharges the obligation in relation to the pricing

02. An employer opens an internal investigation into suspected procurement irregularities and begins gathering information about several employees. What does the Personal Information Protection Law require of that handling?
a)
Nothing beyond the employer's ordinary employment rights, since an investigation into misconduct is an internal management matter
b) Notification to the department performing personal information protection duties, and to the employees concerned, that an investigation has been opened
c) The consent of each employee under investigation before any information about them is gathered or examined
d) A ground for the handling, collection confined to the matters under investigation, and access restricted to those conducting it

03. What does the Personal Information Protection Law require of a department that performs personal information protection duties in relation to complaints?
a)
It must publicize the channel for complaints and reports, and deal with those it receives promptly
b) It must refer every complaint to the handler concerned, and require it to resolve the matter directly with the complainant, reporting the outcome
c) It must open and complete a formal investigation into each complaint it receives, whatever its subject matter or merit
d) It must publish the details of each complaint on its website once the matter has been concluded

04. On what footing may image-collection or personal-identity-recognition equipment be installed in a public place in China?
a)
Wherever the operator of the venue considers it commercially useful, provided a notice is displayed at the entrance
b) Only with the separate consent of every individual who enters the venue, whether as a customer, a visitor or a member of staff
c) Only where necessary for maintaining public security, with prominent signage, and the images used only for that purpose
d) Wherever the equipment has been registered with the public security organs before it is brought into service

05. Which additional regulatory step applies to an algorithmic recommendation or generative service that has public opinion attributes or social mobilization capability?
a)
A security assessment and filing of the service with the authorities
b) Approval of each recommendation rule change by the department performing personal information protection duties
c) Certification of the underlying model and its training data by an accredited professional institution
d) Appointment of an independent supervisory body composed mainly of members from outside the business

06. A user of a note-taking application declines the microphone permission, which the application uses only for an optional voice-input feature. What must the operator do?
a)
Collect the audio through an alternative sensor so that the feature can operate without the declined permission
b) Prompt the user at every launch until the permission is granted, so that the choice remains available to them
c) Continue to provide the rest of the application, withholding only the optional feature
d) Disable the application until the user grants the permission, since partial operation cannot be supported reliably

07. What default position do China's automotive data rules take on personal information generated by a vehicle?
a)
Not to collect it unless the function requires it, and to process it in the vehicle rather than transmit it
b) To collect only with the driver's separate consent, after which any transmission and use is permitted
c) To treat all vehicle-generated data as important data subject to the Data Security Law rather than to these rules
d) To collect and transmit whatever the vehicle generates, and to apply retention limits once the data reaches the manufacturer

08. How does the Personal Information Protection Law classify the personal information of minors below the age it specifies?
a)
As information belonging to the guardian, who exercises the rights over it in their own name
b) As sensitive personal information, so the whole of the enhanced regime applies to handling it
c) As ordinary personal information, with the guardian's consent operating as the only additional requirement imposed
d) As information that may not be handled at all except by educational institutions and healthcare providers

09. Users of a generative service enter prompts that frequently contain personal information about themselves and others. What does the framework require of the provider?
a)
To retain every prompt indefinitely, so that the provider can respond to any later regulatory inquiry about the output
b) To obtain separate consent from every third party mentioned in a prompt, and from the user, before the prompt is processed, stored or logged
c) To treat prompts as the user's own content, over which the provider has no personal information obligations at all
d) To protect the input information and usage records, collect no more than the service needs, and not unlawfully retain identifying input or disclose it

10. A retailer adopts a policy of rejecting every applicant with any criminal record, for all positions, although no legislation requires a check for any of them. How should that policy be assessed?
a)
It is lawful where each applicant gives separate consent, in writing, to the criminal record check
b) It is lawful for customer-facing roles and unlawful only for positions with no contact with the public
c) It is unlawful, because collecting the records has no statutory authorization and the blanket exclusion is unrelated to any role's requirements
d) It is lawful, provided the policy is published in the recruitment materials so that applicants know the standard before applying

Answers:

Question: 01
Answer: b
Question: 02
Answer: d
Question: 03
Answer: a
Question: 04
Answer: c
Question: 05
Answer: a
Question: 06
Answer: c
Question: 07
Answer: a
Question: 08
Answer: b
Question: 09
Answer: d
Question: 10
Answer: c

Note: For any error in IAPP Certified Information Privacy Professional/China (CIPP-CN) certification exam sample questions, please update us by writing an email on feedback@certfun.com.

Rating: 4.7 / 5 (118 votes)