Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CIPM All Questions

View all questions & answers for the CIPM exam

Exam CIPM topic 1 question 84 discussion

Actual exam question from IAPP's CIPM
Question #: 84
Topic #: 1
[All CIPM Questions]

SCENARIO -
Please use the following to answer the next question:
Ben works in the IT department of IgNight, Inc., a company that designs lighting solutions for its clients. Although IgNight's customer base consists primarily of offices in the US, some individuals have been so impressed by the unique aesthetic and energy-saving design of the light fixtures that they have requested IgNight's installations in their homes across the globe.
One Sunday morning, while using his work laptop to purchase tickets for an upcoming music festival, Ben happens to notice some unusual user activity on company files. From a cursory review, all the data still appears to be where it is meant to be but he can't shake off the feeling that something is not right. He knows that it is a possibility that this could be a colleague performing unscheduled maintenance, but he recalls an email from his company's security team reminding employees to be on alert for attacks from a known group of malicious actors specifically targeting the industry.
Ben is a diligent employee and wants to make sure that he protects the company but he does not want to bother his hard-working colleagues on the weekend. He is going to discuss the matter with this manager first thing in the morning but wants to be prepared so he can demonstrate his knowledge in this area and plead his case for a promotion.
To determine the steps to follow, what would be the most appropriate internal guide for Ben to review?

  • A. Incident Response Plan.
  • B. Code of Business Conduct.
  • C. IT Systems and Operations Handbook.
  • D. Business Continuity and Disaster Recovery Plan.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
1 year, 2 months ago
Selected Answer: A
Should be A
upvoted 2 times
...
Ssourav
1 year, 3 months ago
Selected Answer: A
The most appropriate internal guide for Ben to review in order to determine the steps to follow after noticing unusual activity on company files would be: A. Incident Response Plan.
upvoted 2 times
...
DracoL
1 year, 3 months ago
Selected Answer: A
I agree with A. This case is obviously under the Response Phase (Protect) and under the CIPM material, one of the section of response phase is Incident Response Plan.
upvoted 2 times
...
Adyyogi
1 year, 3 months ago
Selected Answer: A
A_ because in the incident Mng Plan should be included steps to follow in these situations. Now..."Codes of conduct are not obligatory but rather potential tools that can be used to promote compliance. Article 40 GDPR elaborates upon a pre-existing provision under the Directive 95/46/EC (Data Protection Directive – DPD), specifically Article 27(1)..." CoC relates more to B2B relationship than "employee to employer "..
upvoted 3 times
...
creativesyde
1 year, 3 months ago
This should be A
upvoted 2 times
...
Alex951
1 year, 5 months ago
Thisshould definitely be incident response plan
upvoted 2 times
...
bilgecell
1 year, 6 months ago
I selected incident response plan but correct answer is code of conduct. I haven't seen code of conduct sample but there is an explanation at GDPR. You can glance at https://gdprhub.eu/Article_40_GDPR . It seems a standard includes all data privacy life cycle.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...