New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

DSCI DCPP-01 DSCI certified Privacy Professional (DCPP) Exam Practice Test

Page: 1 / 12
Total 122 questions

DSCI certified Privacy Professional (DCPP) Questions and Answers

Question 1

A growing economy has made it more important now than ever before for India to have comprehensive laws on __________.

Options:

A.

Right to Information

B.

Dispute resolution

C.

Privacy

D.

Right to Internet

Question 2

Health insurance firm based in the US uses BPM services provided by an Indian company. It was found that one of the employees of the Indian company exported customer data of the insurance company to another US-based insurance company. Under which of the below ground, the company and its executives in India were also subjected to legal action ?

Options:

A.

These actions were not avoided by using data loss prevention tools.

B.

No reasonable security practices were implemented to protect data.

C.

Employees of the company were allowed to view sensitive personal information.

D.

Background checks were not conducted on the individuals.

Question 3

BS 10012 is a British standard used to establish ___________.

Options:

A.

Personal information management system

B.

Privacy technology architecture

C.

Privacy reference architecture

D.

Privacy by design framework

Question 4

Among the following, which of the following is classified as the most important reason for enacting data protection/privacy laws around the world?

Options:

A.

Take legal action against the organizations and fine them for failing to protect privacy

B.

Protect the rights of individuals

C.

Ensure constitutional protection

D.

Maintain social harmony

Question 5

According to the IT (Amendment) Act, 2008, a corporate entity could be liable to pay compensation for negligence in implementing and maintaining reasonable security practices and procedures in order to protect Sensitive Personal Data or Information. What is the amount of penalty?

Options:

A.

Upper limit not defined

B.

Rs. 5,000,000

C.

Rs. 50,000,000

D.

Rs. 500,000,000

Question 6

Which of the following factor is least likely to be considered while implementing or augmenting data security solution for privacy protection:

Options:

A.

Security controls deployment at the database level

B.

Information security infrastructure up-gradation in the organization

C.

Classification of data type and its usage by various functions in the organization

D.

Training and awareness program for third party organizations

Question 7

‘Challenging Compliance’ as a privacy principle is covered in which of the following data protection/ privacy act?

Options:

A.

Federal Data Protection Act, Germany

B.

UK Data Protection Act

C.

PIPEDA

D.

Singapore Data Protection Act

Question 8

With reference to APEC privacy framework, when personal information is to be transferred to another person or organization, whether domestically or internationally, “the ______________ should obtain the consent of the individual and exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with APEC information privacy principles”.

Options:

A.

Personal Information Owner

B.

Personal Information Controller

C.

Personal Information Processor

D.

Personal Information Auditor

Question 9

After the rules were notified under section 43A of the IT (Amendment) Act, 2008, a clarification was issued by the government which exempted the service providers, which get access to/processes Sensitive Personal Data or information (SPDI) under contractual agreement with a legal entity located within or outside India. Which privacy principle provisions notified under Sec 43A were exempted for the service providers?

Options:

A.

Consent

B.

Privacy policy (which is published)

C.

Access and Correction

D.

Disclosure of information

Question 10

A US IT company has created a cloud based application for Canadian consumers only, with servers located in Vancouver, Canada. The application allows its users to publish their short stories, essays or e-books. The purpose of the application, i.e. literary work, is clearly stated in the terms and conditions which are mandatorily acknowledged by each user. With respect to this application, the company must ensure compliance with:

Options:

A.

PIPEDA

B.

US Consumer Privacy Bill of Rights

C.

EU Data Protection Directive

D.

None of the above

Question 11

Complete the sentence:

The Gramm-Leach-Bliley Act (GLBA) of US regulates the privacy practices adopted by financial institutions, requiring them to provide adequate security of the customer records. It lays various obligations on the financial institutions but allows such financial institutions to share the non-public information of customers (after properly notifying their consumers in a manner mentioned in the Act) with

Options:

A.

Its affiliates only after obtaining explicit consent from the consumers

B.

Its affiliates without need for obtaining explicit consent from the consumers for sharing their data

C.

Its affiliates after disclosure in initial and annual GLBA privacy notices

D.

Its affiliates after obtaining explicit permission of Federal Trade Commission

Question 12

Which of the following privacy principle deals with informed consent of the data subject before sharing the personal information (of the data subject) to third parties for processing?

Options:

A.

Collection limitation

B.

Purpose limitation

C.

Disclosure of information

D.

Accountability

Question 13

Company A collects and stores information from people X & Y on behalf of company B. Which of the following statements are true?

Options:

A.

A is the data controller since it collects data directly from X & Y

B.

B is the data controller while A is the sub processor as B has outsourced the data collection and processing to A

C.

B is the data controller that uses A as data processor to collect and process data of data subjects X and Y

D.

Both A & B are data controllers since both need to maintain highest principles of data protection

Question 14

Rising economic value of personal information has stressed the need for a comprehensive __________ legislation in India.

Options:

A.

Right to Internet

B.

Privacy

C.

Right to Information

D.

Dispute resolution

Question 15

Which one of the following is considered as the first step of evolution in the formation of today’s concept of privacy?

Options:

A.

Fundamental civil liberty

B.

Universal declaration of human rights

C.

Right to be left alone

D.

Binding corporate rules

Question 16

Which among the following can be classified as the most important purpose for enactment of data protection/ privacy regulations across the globe?

Options:

A.

Protect the constitution

B.

Penalize the organizations and impose fines for failure to protect privacy

C.

Ensure peace in the society

D.

Protect individual rights

Question 17

In India, who among the following would be the authorized legal entities to monitor and intercept communication of individuals?

Options:

A.

“Intermediaries” as defined under the IT (Amendment) Act, 2008

B.

Telecom Service Providers

C.

Intelligence and Law Enforcement Agencies

D.

Directorate of Revenue Intelligence (DRI)

Question 18

Which of the following doesn’t contribute, or contributes the least, to the growing data privacy challenges in today’s digital age?

Options:

A.

Social media

B.

Mass surveillance

C.

Use of secure wireless connections

D.

Increase in digitization of personal information

Page: 1 / 12
Total 122 questions