New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

DSCI DCPLA DSCI Certified Privacy Lead Assessor Exam Practice Test

Page: 1 / 7
Total 70 questions

DSCI Certified Privacy Lead Assessor Questions and Answers

Question 1

Certification once granted, will be valid for period of _______ years subject to surveillance assessments.

Options:

A.

4

B.

5

C.

3

D.

1

Question 2

A newly appointed Data Protection officer is reviewing the organization’s existing privacy policy. Which of the following would be the most critical factor for the review process?

Options:

A.

Awareness of the business units about the privacy policy

B.

Changes in the legal/regulatory regime

C.

Privacy policies of industry peers

D.

Foreseeable challenges in the effective implementation of the policy

Question 3

What are the two phases of DSCI Privacy Third Party Assessment?

Options:

A.

Initial and Detailed

B.

Primary and Secondary

C.

Initial and Final

D.

None of the above

Question 4

Which of the following is not an objective of POR?

Options:

A.

Create an inventory of business processes, enterprise and operational functions, client relationships that deal with personal information

B.

Identify all the activities, functions and operations that can be attributed to the privacy initiatives of an organization

C.

Evaluate the role of corporate function in legal compliance management, its relations with IT, and security functions. Evaluate the role of legal function in compliance matters

D.

Establish a privacy function to address the activities, functions and operations that are required to manage the privacy initiatives

Question 5

Classify the following scenario as major or minor non-conformity.

“The organization has a very mature information security policy. Lately, the organization has realized the need to focus on protection of PI. A formal PI identification exercise was done for this purpose and a mapping of PI and security controls was done. The organization has also put in place data masking technology in certain functions where the SPI was accessed by employees of a third party. However, the organization is yet to include PI specifically in its risk assessment exercise, incident management, testing, data classification and security architecture programs.”

Options:

A.

Major

B.

Minor

C.

Both Major & Minor

D.

None of the above

Question 6

With respect to privacy implementation, organizations should strive for which of the following:

Options:

A.

Meaningful compliance

B.

Demonstrable accountability

C.

Checklist based exercise

D.

None of the above

Question 7

What is a Data Controller?

Options:

A.

Entity that collects personal data

B.

Entity that stores personal data

C.

Entity that determines the purpose and means for data processing

D.

Entity that shares personal data with third parties

Question 8

“Data which cannot be attributed to a particular data subject without use of additional information.” Which of the following best describes the above statement?

Options:

A.

Anonymized Data

B.

Metadata

C.

Pseudonymized Data

D.

None of the above

Question 9

Which of the following activities form part of an organization’s Visibility over Personal Information (VPI) initiative, according to DSCI Privacy Framework (DPF®)?

Options:

A.

‘Data processing environment’ analysis of industry peers

B.

‘Data processing environment’ analysis of the country

C.

‘Data processing environment’ analysis of the organization and associated third parties

D.

‘Data processing environment' analysis of the organization only

Question 10

Which of the following parameters should ideally be addressed by a privacy program of an organization? (Choose all that apply.)

Options:

A.

Privacy incident response plan and grievance handling

B.

Environmental security concerns

C.

Training and data classification

D.

Intellectual Property (IP) protection

Page: 1 / 7
Total 70 questions