exam questions

Exam CIPM All Questions

View all questions & answers for the CIPM exam

Exam CIPM topic 1 question 81 discussion

Actual exam question from IAPP's CIPM
Question #: 81
Topic #: 1
[All CIPM Questions]

SCENARIO -
Please use the following to answer the next question:
Paul Daniels, with years of experience as a CEO, is worried about his son Carlton's successful venture, Gadgo. A technological innovator in the communication industry that quickly became profitable, Gadgo has moved beyond its startup phase. While it has retained its vibrant energy, Paul fears that under Carlton's direction, the company may not be taking its risks or obligations as seriously as it needs to. Paul has hired you, a Privacy Consultant, to assess the company and report to both father and son. "Carlton won't listen to me," Paul says, "but he may pay attention to an expert."
Gadgo's workplace is a clubhouse for innovation, with games, toys, snacks. espresso machines, giant fish tanks and even an iguana who regards you with little interest. Carlton, too, seems bored as he describes to you the company's procedures and technologies for data protection. It's a loose assemblage of controls, lacking consistency and with plenty of weaknesses. "This is a technology company," Carlton says. "We create. We innovate. I don't want unnecessary measures that will only slow people down and clutter their thoughts."
The meeting lasts until early evening. Upon leaving, you walk through the office it looks as if a strong windstorm has recently blown through, with papers scattered across desks and tables and even the floor. A "cleaning crew" of one teenager is emptying the trash bins. A few computers have been left on for the night, others are missing. Carlton takes note of your attention to this: "Most of my people take their laptops home with them, or use their own tablets or phones. I want them to use whatever helps them to think and be ready day or night for that great insight. It may only come once!"
What would be the best kind of audit to recommend for Gadgo?

  • A. A supplier audit.
  • B. An internal audit.
  • C. A third-party audit.
  • D. A self-certification.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
9385ae2
2 weeks, 2 days ago
Selected Answer: C
C. need an independent third party to complete this.
upvoted 1 times
...
Vinz_
1 month ago
Selected Answer: C
First party audits usually support self certifications and there is no clue in the described scenario that an internal audit team exists. Third party audits are independent and provide a level of expert recommendations.
upvoted 1 times
...
Privacy2024
1 month, 1 week ago
Selected Answer: B
Also let me add this. The IAPP CIPM framework emphasizes the importance of conducting internal assessments to evaluate privacy and security risks, especially when a company has gaps in its data protection practices. Given that the scenario describes Gadgo as a company with inconsistent controls, lax data protection measures, and informal privacy practices, an internal audit provides the best foundation for addressing those issues.
upvoted 1 times
9385ae2
3 weeks, 2 days ago
Disagree. Should be C. Who has the expertise, internally, to the audit. Surely they don't have the right person/people on staff to complete an internal audit.
upvoted 1 times
...
...
Privacy2024
1 month, 1 week ago
Selected Answer: B
It's B. Here's why: Given the state of the company's privacy and security measures, an internal audit is the best way to assess current practices, identify gaps, and help develop stronger controls and procedures. This audit will also assist in educating the leadership (including both Paul and Carlton) on the necessary steps to protect the company's data. Given that the company appears to be missing fundamental privacy and security structures, an internal audit would be an appropriate first step before seeking external guidance or compliance certifications.
upvoted 1 times
...
Adyyogi
5 months, 3 weeks ago
Selected Answer: C
third party audit will be most likely accepted by anyone as objective
upvoted 3 times
...
bilgecell
9 months ago
In this scenario, an external audit may be a good option to persuade the management body and get objective feedback.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago