CIPP-US IAPP Certified Information Privacy Professional/United States (CIPP/US) Free Practice Exam Questions (2025 Updated)
Prepare effectively for your IAPP CIPP-US Certified Information Privacy Professional/United States (CIPP/US) certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.
California’s SB 1386 was the first law of its type in the United States to do what?
How did the Fair and Accurate Credit Transactions Act (FACTA) amend the Fair Credit Reporting Act (FCRA)?
What is the purpose of a cure provision in a stale data privacy law?
Which of the following does Title VII of the Civil Rights Act prohibit an employer from asking a job applicant?
Your company, an online store selling digital keys to video games, has received a data access request from an individual. Specifically, the individual wants access to her recent purchase history, as she has misplaced the emails containing the digital keys to multiple game purchases she made last month.
From a security standpoint, what would the user have to do under CCPA in order to acceptably verify her identity?
When does the Telemarketing Sales Rule require an entity to share a do-not-call request across its organization?
Although an employer may have a strong incentive or legal obligation to monitor employees’ conduct or behavior, some excessive monitoring may be considered an intrusion on employees’ privacy? Which of the following is the strongest example of excessive monitoring by the employer?
A covered entity suffers a ransomware attack that affects the personal health information (PHI) of more than 500 individuals. According to Federal law under HIPAA, which of the following would the covered entity NOT have to report the breach to?
The FTC often negotiates consent decrees with companies found to be in violation of privacy principles. How does this benefit both parties involved?
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
What do the Civil Rights Act, Pregnancy Discrimination Act, Americans with Disabilities Act, Age Discrimination Act, and Equal Pay Act all have in common?
Which of the following is NOT a common challenge large organizations face when implementing data portability?
Which authority supervises and enforces laws regarding advertising to children via the Internet?
What is the most likely reason that states have adopted their own data breach notification laws?
Which of the following is most likely to provide privacy protection to private-sector employees in the United States?
All of the following are tasks in the “Discover” phase of building an information management program EXCEPT?
Which of the following became the first state to pass a law specifically regulating the collection of biometric data?
A California resident has created an account on your company's online food delivery platform and placed several orders in the past month Later she submits a data subject request to access her personal information under the California Privacy Rights Act.
Based on the CPRA. which of the following data elements would your company NOT have to provide to the requestor once her identity has been verified?
What was the original purpose of the Federal Trade Commission Act?
What role does the U.S. Constitution play in the area of workplace privacy?