Easter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

DSCI certified Privacy Professional (DCPP) Question and Answers

DSCI certified Privacy Professional (DCPP)

Last Update May 20, 2024
Total Questions : 122

We are offering FREE DCPP-01 DSCI exam questions. All you do is to just go and sign up. Give your details, prepare DCPP-01 free exam questions and then go for complete pool of DSCI certified Privacy Professional (DCPP) test questions that will help you more.

DCPP-01 pdf

DCPP-01 PDF

$35  $99.99
DCPP-01 Engine

DCPP-01 Testing Engine

$42  $119.99
DCPP-01 PDF + Engine

DCPP-01 PDF + Testing Engine

$56  $159.99
Questions 1

From the following list, identify the technology aspects that are specially designed for upholding the privacy:

i. Data minimization

ii. Intrusion prevention system

iii. Data scrambling

iv. Data loss prevention

v. Data portability

vi. Data obfuscation

vii. Data encryption

viii. Data mirroring

Please select the correct set of aspects from below options:

Options:

A.  

Only i., iii., vii. and viii

B.  

Only i., ii., iii., vii. and viii

C.  

Only i., ii., vi. and vii

D.  

Only ii., v., vi., vii. and viii

Discussion 0
Questions 2

Which of the following instruments can be used for a legal data transfer when a company in the EU wishes to transfer data to Asian countries?

Options:

A.  

Framework for the Privacy Shield

B.  

Standard Contractual Clauses

C.  

Data processors must be certified by ISO 27001 under customized contracts

D.  

Binding Corporate Rules

Discussion 0
Questions 3

According to the EU-US Safe Harbour Framework, which of the following is not required when transferring personal information from EU member nations to the US?

Options:

A.  

Contracts with EU data exporters should include standard contractual clauses

B.  

Safe harbor principles must be followed

C.  

The self-certification process with the Federal Trade Commission

D.  

Privacy information publicly disclosed

Discussion 0
Questions 4

As a newly-appointed privacy officer of an IT company gearing up for DSCI’s privacy certification, you are trying to understand what data elements are involved in each of the business process, function and if these data elements can be classified as sensitive personal information. What is being accomplished with this effort?

Options:

A.  

Organization to get “Visibility” over its exposure to sensitive personal information

B.  

It is a part of the annual exercise per the organization’s privacy policy/ processes

C.  

Information security controls for confidential information being reviewed

D.  

Gathering inputs to restructure privacy function

Discussion 0
Questions 5

What does PHI stand for, as per HIPAA/ HITECH?

Options:

A.  

Personal heuristic information

B.  

Public health information

C.  

Protected health information

D.  

Personal health information

Discussion 0
Questions 6

Which one of the following is considered as the first step of evolution in the formation of today’s concept of privacy?

Options:

A.  

Fundamental civil liberty

B.  

Universal declaration of human rights

C.  

Right to be left alone

D.  

Binding corporate rules

Discussion 0
Questions 7

Which of the following laid foundation for the development of OECD privacy principles for the promotion of free international trade and trans border data flows?

Options:

A.  

Fair information Privacy Practices of US, 1974

B.  

EU Data Protection Directive

C.  

Safe Harbor Framework

D.  

WTO’s Free Trade Agreement

Discussion 0
Questions 8

In India, who among the following would be the authorized legal entities to monitor and intercept communication of individuals?

Options:

A.  

“Intermediaries” as defined under the IT (Amendment) Act, 2008

B.  

Telecom Service Providers

C.  

Intelligence and Law Enforcement Agencies

D.  

Directorate of Revenue Intelligence (DRI)

Discussion 0
Questions 9

Which type of data qualify as Sensitive Personal Data or Information under Section 43A of IT (Amendment) Act, 2008?

Options:

A.  

Sexual orientation

B.  

Political affiliation

C.  

Religion and caste

D.  

Call Data Records (CDRs)

Discussion 0
Questions 10

Which of the following is not a driver for increased privacy-related concerns and subsequent regulatory responses from various governments around the world?

Options:

A.  

Outsourcing and trans-border data flows in globalized world

B.  

Increasing economic value of personal information

C.  

Rising demand of data privacy professionals

D.  

Phenomenal rise in use of social networking sites, where a lot of personal information is shared with others

Discussion 0
Questions 11

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

For exporting EU branch employees’ data to Asian Countries for processing, which of the following instruments could be used for legal data transfer?

Options:

A.  

Customized contracts mandating ISO 27001 certification by the data processor

B.  

Standard Contractual Clauses

C.  

Binding Corporate Rules

D.  

Safe Harbor

Discussion 0
Questions 12

A ministry under government of India plans to collect citizens’ information related to their education, medical condition, economic status, caste and religion. As per the privacy requirements mentioned under Sec 43A of IT (Amendment) Act, 2008, the citizens’ ‘Consent’ would be mandatory for which of the following elements before their collection?

Options:

A.  

Educational records

B.  

Medical condition

C.  

Caste and religion

D.  

Sec 43A may not be applicable

Discussion 0
Questions 13

With reference to APEC privacy framework, when personal information is to be transferred to another person or organization, whether domestically or internationally, “the ______________ should obtain the consent of the individual and exercise due diligence and take reasonable steps to ensure that the recipient person or organization will protect the information consistently with APEC information privacy principles”.

Options:

A.  

Personal Information Owner

B.  

Personal Information Controller

C.  

Personal Information Processor

D.  

Personal Information Auditor

Discussion 0
Questions 14

Which of the following statements are true about the privacy statement of an organization?

Options:

A.  

Content of the online privacy statement of an organization will depend upon the applicable laws, and may need to address requirements across geographical boundaries and legal jurisdictions

B.  

As per privacy laws generally it is mandatory to mention the phone contact details of the owner of organization in the online privacy statement where customers can reach out in case of a grievance or incident

C.  

Online privacy statement is an instrument to demonstrate to stakeholders how the organization gathers, uses, discloses, and manages personal data

D.  

India’s Information Technology (Amendment) Act, 2008 does not require that privacy policy be published on the website

Discussion 0
Questions 15

XYZ & Co., an Indian hospital specialized in dealing with cancer treatment has organized a free health checkup camp for women in a specific district, after seeking due permission from competent authorities. During the camp the hospital staffs will be feeding the medical records of these women into the computer connected to hospital network system. Does the said hospital need to notify its privacy policy to the women attending the camp and seek their consent regarding the collection and processing of such information?

Options:

A.  

No, since it is a free checkup camp for their welfare

B.  

Yes, in the any language as per the wishes of said hospital

C.  

No, since the law does not require the same in this case

D.  

Yes, in the language such women would understand

Discussion 0
Questions 16

XYZ is a successful startup that acquired a respectable size & scale of operations in last 3 years, handling business process services for small & medium scale enterprises, largely in US & Europe. They are at the stage of closing a deal with a new banking client and working out the details of privacy related obligations in contract. Ensuring effective enforcement of which of the below listed privacy principles is client’s accountability, even after outsourcing its loan approval process to XYZ?

I. Notice

II. Choice and Consent

III. Collection Limitation

IV. Use Limitation

V. Access and Correction

VI. Security

VII. Disclosure to third Party

Please select the correct set of principles from below listed options:

Options:

A.  

None of the above, since they are outsourcing the work to XYZ who will carry the liability going forward

B.  

All except V and VI

C.  

All except III

D.  

All of the above listed privacy principles

Discussion 0
Questions 17

According to the EU, which of the following steps is not relevant when transferring data from an EU member to a third country that does not meet EU standards?

Options:

A.  

Obtaining approval by the Data Protection Authority or informing it

B.  

Aligning data protection legislation across geographies

C.  

Sizing up the security measures employed by the importing organization to account for the sensitivity of the data being transferred

D.  

A model contract is signed

Discussion 0
Questions 18

When sharing personal information (of the data subject) with third parties for processing, which of the following privacy principles includes informed consent?

Options:

A.  

Disclosure of information

B.  

Collection limitation

C.  

Accountability

D.  

Purpose limitation

Discussion 0