CIPT Certified Information Privacy Technologist Practice Questions
Prepare for CIPT with more than an answer.
- Exam fee
- $550 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- The Privacy Technologist's Role in the Context of the Organization20%
- Data Collection, Use, Dissemination, and Destruction20%
- Privacy Risk Management20%
- Privacy-Enhancing Strategies, Techniques, and Technologies20%
- Privacy by Design20%
- 1
Which of the following entities would most likely be exempt from complying with the General Data Protection Regulation (GDPR)?
Show answer details
Correct answer: C
C
- 2
What is the main function of the Amnesic Incognito Live System or TAILS device?
Show answer details
Correct answer: A
- 3
You are a wine collector who uses the web to do research about your hobby. You navigate to a news site and an ad for wine pops up. What kind of advertising is this?
Show answer details
Correct answer: B
- 4
What is a main benefit of data aggregation?
Show answer details
Correct answer: C
C
- 5
A software development team is building a new application and wants to integrate privacy checks into their CI/CD pipeline. The goal is to automatically scan for potential privacy risks before code is deployed to production. Which of the following is an example of a practical, automated check that could be added to the pipeline to enforce privacy by design?
flowchart TD A[Developer Commits Code] --> B{CI/CD Pipeline Triggered} B --> C[Build & Unit Tests] C --> D{Automated Privacy Scan} D -- No Issues --> E[Deploy to Staging] D -- Issues Found --> F[Fail Build & Notify Dev] E --> G[Manual QA] G --> H[Deploy to Production]Show answer details
Correct answer: D
While scanning for hardcoded secrets is a good security practice, scanning for new data fields being logged is a direct privacy control. Excessive or inadvertent logging of personal data is a common source of privacy incidents. An automated rule to flag this change forces developers to consciously evaluate if the new data is necessary to log, thus supporting data minimization and purpose limitation. Manual reviews and checking library privacy policies are not typically automated pipeline steps.
- 6
Which of the following became a foundation for privacy principles and practices of countries and organizations across the globe?
Show answer details
Correct answer: D
- 7
Which of the following most embodies the principle of Data Protection by Default?
Show answer details
Correct answer: D
D
- 8
How can a hacker gain control of a smartphone to perform remote audio and video surveillance?
Show answer details
Correct answer: B
B
- 9
Which is NOT a suitable action to apply to data when the retention period ends?
Show answer details
Correct answer: C
C
- 10
Based on the initial assessment and review of the available data flows, which of the following would be the most important privacy risk you should investigate first?

Show answer details
Correct answer: C
C
