Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Chapter 2

Total questions: 20

Worksheet time: 20mins

Name
Class
Date
1.

The EU’s GDPR is most equivalent to which U.S. federal law?

a)

The FTC Act

b)

HIPAA

c)

None

d)

GLBA

2.

Which of the following is not one of the nine principles of the APEC framework?

a)

Notice

b)

Integrity of personal information

c)

Security safeguards

d)

Right to rectification

3.

Marcia is the privacy program manager at a large company. She implemented a new privacy program one year ago and now, a year in, she is concerned that the program is not going well because not all employees have completed the required training. Marcia attends a meeting of company executives to ask for more funding for the program to support the training program. The CFO objects, reasoning that the privacy program is going just fine because the company did well on its last audit. The CEO isn’t sure, so she sends Marcia back to develop a report on how many privacy-related customer complaints they’ve had before she decides to allocate new funding. What most likely went wrong here?

a)

Marcia failed to secure proper executive sponsorship for her program in the first place.

b)

Marcia neglected to define specific metrics for the program at the beginning.

c)

The privacy program was not properly aligned with business strategy and objectives.

d)

Marcia does not have adequate procedures in place for monitoring internal compliance.

4.

Marcia is the privacy program manager at a large company. She implemented a new privacy program one year ago and now, a year in, she is concerned that the program is not going well because not all employees have completed the required training. Marcia attends a meeting of company executives to ask for more funding for the program to support the training program. The CFO objects, reasoning that the privacy program is going just fine because the company did well on its last audit. The CEO isn’t sure, so she sends Marcia back to develop a report on how many privacy-related customer complaints they’ve had before she decides to allocate new funding. A week later, Marcia returns with the report that the CEO requested, but the CFO still isn’t convinced that training is worth the cost. “I know not everyone has been through the training,” reasons the CFO, “but adding more training programs is prohibitively expensive. I just don’t think it’s worth it.” What metric might Marcia use to address the CFO’s concern?

a)

ROI

b)

Business resiliency

c)

Trend analysis

d)

Resource utilization

5.

Geoff is helping a small data analytics startup company based in the United States expand their business by offering analytics services for companies in the EU. Which of the following routes is Geoff most likely to recommend to allow data transfers from EU companies to the startup?

a)

U.S. Privacy Shield

b)

Standard contractual clauses

c)

Binding corporate rules

d)

APEC

6.

When defining a privacy program framework, it is important to map out how information moves around internally so that data can be tracked. Which term best describes this activity?

a)

Data classification

b)

Data flow mapping

c)

Data inventory

d)

Access control

7.

Aidan is a new privacy manager struggling to implement a privacy program at a beloved small-town retail shop called Middleburg Threads. Aidan has implemented an initial privacy program framework and completed the initial risk assessment. He found that privacy policies weren’t written down anywhere, the computers in the back office aren’t password protected, and perhaps most concerning of all, the company has outsourced online sales, including credit card processing, to another small local business. There doesn’t seem to be any sort of formal contract in place. Which of the following might be the best place for Aidan to start?

a)

. Implement information security controls.

b)

Immediately implement privacy awareness education for employees at the store.

c)

Develop a formal contract that includes the PCI DSS framework.

d)

Develop an incident response procedure because of the high risk.

8.

Annie is a CEO at a rapidly growing company. Currently, the company only does business in the United States, but Annie dreams of expanding across North America. Annie also wants customer privacy to be the hallmark of her company’s reputation, so she wants to do more to protect privacy than the minimum required for compliance. Annie is considering privacy program frameworks, and she is trying to choose between adopting a FIPPs-based approach and a PbD approach. How would you advise Annie and why?

a)

Select FIPPs because it is required by the U.S. Privacy Act

b)

Select PbD because it emphasizes respect for personal privacy beyond compliance.

c)

Select FIPPs because it offers the most robust personal privacy protections.

d)

Select PbD because it is required in Canada.

9.

Ahmad had just been hired to run the information privacy program at Accounting Unlimited, a large corporate bookkeeping and accounting firm. Ahmad starts by assessing the current privacy program. He is pleased to note that Accounting Unlimited employs robust privacy practices. Employees follow good processes and maintain privacy controls in most (but not all) areas. However, when he asks for the documentation on all the privacy procedures, he gets a patchwork of documents from different departments. Some of the documents are out of date and some are missing. How might Ahmad classify this privacy program’s maturity level?

a)

Ad hoc

b)

Repeatable

c)

Adequate

d)

Defined

10.

Jorge has finished implementing a NIST-based privacy framework for his employer. The executive team at Jorge’s company realize they cannot focus on every single activity in the large privacy program, so they want to pick out a few important privacy activities to monitor closely and improve. Which part of the NIST framework might help with this?

a)

NIST Core

b)

Privacy Maturity Model (PMM)

c)

Profiles

d)

Implementation tiers

11.

Melinda is an experienced pediatrician, and she has finally taken the leap to open her own clinic. She prides herself on her commitment to focusing only on her patients, so she wants to outsource some of her administrative functions, such as billing and scheduling. What does Melinda need to include in the contract when she hires a vendor for these functions?

a)

A data sharing agreement

b)

BCRs

c)

BAA

d)

Vendor evaluation

12.

Pierre is working on implementing a privacy program based on the NIST privacy framework. He is concerned with making sure that the program includes robust identity management. On which function of the NIST framework should Pierre focus?

a)

Protect

b)

Control

c)

Govern

d)

Identify

13.

Eduardo is a privacy program manager for Surfside Rentals, a small chain of stores in California that rent out surfing equipment. While Surfside Rentals has been in business for years, the company has recently decided to start offering a credit card program. Customers who sign up for the new credit card earn “juice points” that count toward free rentals for every dollar spent. Eduardo carefully monitors for any changes in privacy compliance requirements for the company. Given Surfside Rental’s recent business moves, which new type of jurisdictional category should Eduardo worry about?

a)

Personal jurisdiction

b)

Territorial jurisdiction

c)

Subject-matter jurisdiction

d)

Federal jurisdiction

14.

Dimitri cashed a paycheck at County Bank three months ago, but he doesn’t have an account there and hasn’t been back since. Under GLBA, County Bank should consider Dimitri as which of the following?

a)

Customer

b)

Consumer

c)

Visitor

d)

No relationship with the bank

15.

Jennifer is an IT manager and has spent the last five years implementing privacy controls on IT systems that she hopes will reduce privacy incidents over time. Which type of metric will be most helpful to Jennifer?

a)

ROI

b)

Business resiliency

c)

Resource utilization

d)

Trend analysis

16.

Which of the following would be the least useful as a privacy program metric?

a)

Number of PIAs completed

b)

Overall privacy program expenditures

c)

Quality of the incident response program

d)

Tabletop drills completed

17.

BlindDateDublin.com, an Irish dating website, was found responsible for repeatedly and purposely violating multiple provisions of the GDPR. The resulting privacy violations caused some people in the EU to lose their jobs and exposed others to social stigmas and other harms. What is the largest penalty BlindDateDublin.com might face?

a)

€30,000,000

b)

€20,000,000 or 4% of annual revenue, whatever is greater

c)

8% of annual revenue

d)

€10,000,000

18.

Which of the following is not a benefit of performing privacy impact assessments?

a)

Make risk-informed business decisions.

b)

Fulfill GDPR requirements.

c)

Calculate potential compliance costs.

d)

Evaluate the impact of privacy breaches after they occur.

19.

Nadya runs a small local bakery in Trenton, New Jersey. Her peanut butter cookies are so popular that she has received hundreds of requests to ship boxes of her cookies nationwide. Since Nadya does not have time to run her bakery and an online ordering process, she plans to contract with eSales, Inc., to manage a website, online orders, payments, and shipping. Nadya values the trust and loyalty of her customers and wants to be sure their privacy is protected. She has looked into eSales, Inc.’s privacy notices and asked them about their privacy practices in detail. From all she can tell, Nadya is satisfied with eSales, Inc.’s commitment to privacy, but she knows that eSales is growing rapidly and might be spreading itself pretty thin. What else could Nadya do to protect the privacy of her online customers?

a)

Ask eSales, Inc. to sign a data privacy agreement.

b)

Switch to a more stable vendor that will have time to pay adequate attention to the needs of small business.

c)

Hire a privacy program manager for the bakery charged with monitoring vendors, such as eSales, Inc.

d)

Nadya has already performed adequate due diligence and should be assured that eSales, Inc. will protect her customers’ privacy well.

20.

BizCorp has defined GLBA audit performance as a privacy program metric. Which of the following is most likely a secondary audience for this metric?

a)

CIO

b)

CFO

c)

Privacy program manager

d)

Investors