FIP Practice Questions
Prepare for FIP with more than an answer.
- Level
- Fellow / Advanced Designation
- Valid for
- Lifetime (as long as underlying IAPP certifications remain in good standing)
Domains covered on the exam 5
- Privacy Law and Regulation (CIPP Foundation)30%
- Privacy Program Management (CIPM Focus)25%
- Privacy Technology and Engineering (CIPT Focus)20%
- AI Governance (AIGP Pathway)10%
- Professional Experience and Leadership15%
- 1
True or False: Under the GDPR, a Data Protection Officer (DPO) can be penalized or dismissed by the controller for performing their duties, such as reporting a compliance issue to the Data Protection Authority (DPA).
Show answer details
Correct answer: B
GDPR Article 38(3) explicitly protects the DPO from being dismissed or penalized by the controller or processor for performing their tasks. The DPO must act independently and report to the highest management level.
- 2
A global company uses a centralized HR system. When handling Data Subject Access Requests (DSARs) from employees in different jurisdictions, what is the best practice approach for a unified process?
Show answer details
Correct answer: B
While a unified intake is efficient, applying the strictest standard globally (Option A) can be legally risky or overly burdensome (e.g., providing GDPR rights to US employees where no such right exists might create unintended contractual obligations). The best practice is to centralize the intake but tailor the fulfillment logic (timelines, exemptions, redactions) to the specific laws applicable to the requester.
- 3
Case Study:
TechHealth Corp is a wearable device manufacturer based in California. They are launching a new smart ring that tracks heart rate, sleep, and blood oxygen levels. The device syncs to a mobile app.
The marketing team wants to sell aggregated user health trends to insurance companies. The engineering team has implemented 'k-anonymity' with k=5 for the dataset.
However, a privacy researcher recently published a paper showing that k-anonymity is vulnerable to 'homogeneity attacks' and 'background knowledge attacks' for high-dimensional datasets like this.
As the Privacy Engineer for this project, which advanced privacy-enhancing technology (PET) should you recommend to replace or augment k-anonymity to provide mathematically provable privacy guarantees while still allowing aggregate trend analysis?
Show answer details
Correct answer: A
Differential Privacy (DP) is the current gold standard for aggregate data analysis. Unlike k-anonymity, which relies on hiding individuals in a crowd (and fails if the crowd is homogeneous or if external data is linked), DP adds mathematical noise to the output of queries. It provides a provable guarantee that the output of an analysis is essentially the same whether any single individual is in the dataset or not, thus protecting against re-identification attacks including background knowledge attacks.
- 4
A multinational pharmaceutical company headquartered in France is planning to centralize its HR data processing in a new cloud instance hosted in the United States. The data includes sensitive health information of employees from France, Germany, and Italy. As the Chief Privacy Officer, you are conducting a Transfer Impact Assessment (TIA). Which of the following factors is MOST critical to evaluate to ensure the transfer withstands scrutiny under the 'Schrems II' requirements regarding US surveillance laws?
Show answer details
Correct answer: D
Under the CJEU's Schrems II ruling and subsequent EDPB recommendations, the core issue is whether the laws in the third country (specifically US surveillance laws like FISA 702 and EO 12333) impinge on the effectiveness of the transfer tool (like SCCs). The TIA must assess if the importer is a 'communications service provider' subject to these laws and if technical supplementary measures (like encryption where the keys are held in the EU) can effectively prevent access.
- 5
You are the Privacy Manager for a global retail chain. Marketing wants to launch a new loyalty program that tracks user location in real-time via a mobile app to offer in-store coupons. This involves profiling under GDPR. According to Article 22 and EDPB guidelines, which of the following conditions MUST be met to lawfully proceed with this automated decision-making activity?
Show answer details
Correct answer: A
GDPR Article 22 prohibits automated decision-making (ADM) that produces legal or similarly significant effects unless one of three exceptions applies: it is necessary for entering into or performance of a contract, authorized by law, or based on the data subject's explicit consent. For a marketing loyalty program, explicit consent is the most likely valid basis.
- 6
An organization is designing a privacy metrics dashboard for the Board of Directors. The goal is to move beyond 'vanity metrics' (e.g., number of people trained) to 'outcome-based metrics' that demonstrate risk reduction. Which of the following metrics best satisfies this requirement?
Show answer details
Correct answer: D
This is an outcome-based metric (Key Risk Indicator or KRI) that measures the effectiveness of the 'Privacy by Design' process. It directly correlates to the reduction of compliance risk (unassessed apps entering production). The other options are activity metrics (completion rates) or operational efficiency metrics (time to close), rather than risk outcome metrics.
