exam questions

Exam CIPM All Questions

View all questions & answers for the CIPM exam

Exam CIPM topic 1 question 10 discussion

Actual exam question from IAPP's CIPM
Question #: 10
Topic #: 1
[All CIPM Questions]

An organization's privacy officer was just notified by the benefits manager that she accidentally sent out the retirement enrollment report of all employees to a wrong vendor.
Which of the following actions should the privacy officer take first?

  • A. Perform a risk of harm analysis.
  • B. Report the incident to law enforcement.
  • C. Contact the recipient to delete the email.
  • D. Send firm-wide email notification to employees.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
2 weeks, 4 days ago
Selected Answer: C
The privacy officer should first C. Contact the recipient to delete the email. Here's why: Immediate Mitigation: The priority is to minimize the potential damage. Contacting the vendor to request immediate deletion of the email is the most direct and immediate way to attempt to contain the breach. Time Sensitivity: Every moment that the data is in the wrong hands increases the risk. Contacting the recipient is the fastest action to take. Here's why the other options are not the first step: A. Perform a risk of harm analysis: A risk of harm analysis is a necessary step, but it comes after attempting to contain the breach.
upvoted 1 times
2 months, 2 weeks ago
Selected Answer: A
Risk analysis should be the first step and then containment of the information.
upvoted 2 times
7 months, 2 weeks ago
Selected Answer: C
Act immediately to mitigate and contain the breach. Then move onto other actions e.g. assessing the potential harm
upvoted 1 times
8 months, 1 week ago
It should be A to determine the harm first.
upvoted 2 times
9 months, 2 weeks ago
Selected Answer: C
The first priority in such situations is to mitigate any potential harm by containing the breach.
upvoted 1 times
1 year ago
Selected Answer: A
Risk Analysis
upvoted 2 times
1 year, 1 month ago
The answer is C: The privacy officer should work with the benefits manager to contain the breach promptly. This may involve contacting the vendor and requesting them to delete or secure the data immediately.
upvoted 4 times
1 year, 5 months ago
Selected Answer: C
I vote for c
upvoted 2 times
1 year, 6 months ago
C - data encryption is not clarified, the immediate action should be containment
upvoted 2 times
1 year, 7 months ago
Should be C, to secure operations and make sure no additional data is lost first
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago