What privacy risk is NOT mitigated by the use of encrypted computation to target and serve online
ads?
D
When analyzing user data, how is differential privacy applied?
A
Between November 30th and December 2nd, 2013, cybercriminals successfully infected the credit
card payment systems and bypassed security controls of a United States-based retailer with malware
that exfiltrated 40 million credit card numbers. Six months prior, the retailer had malware detection
software installed to prevent against such an attack.
Which of the following would best explain why the retailers consumer data was still exfiltrated?
B
Which of the following is the least effective privacy preserving practice in the Systems Development
Life Cycle (SDLC)?
C
Which of the following functionalities can meet some of the General Data Protection Regulation’s
(GDPR’s) Data Portability requirements for a social networking app designed for users in the EU?
C
A company configures their information system to have the following capabilities:
Allow for selective disclosure of attributes to certain parties, but not to others.
Permit the sharing of attribute references instead of attribute values - such as I am over 21 instead
of birthday date.
Allow for information to be altered or deleted as needed.
These capabilities help to achieve which privacy engineering objective?
C
When should code audits be concluded?
D
Not updating software for a system that processes human resources data with the latest security
patches may create what?
B
SCENARIO
Please use the following to answer the next question:
Light Blue Health (LBH) is a healthcare technology company developing a new web and mobile
application that collects personal health information from electronic patient health records. The
application will use machine learning to recommend potential medical treatments and medications
based on information collected from anonymized electronic health records. Patient users may also
share health data collected from other mobile apps with the LBH app.
The application requires consent from the patient before importing electronic health records into the
application and sharing it with their authorized physicians or healthcare provider. The patient can
then review and share the recommended treatments with their physicians securely through the app.
The patient user may also share location data and upload photos in the app. The patient user may
also share location data and upload photos in the app for a healthcare provider to review along with
the health record. The patient may also delegate access to the app.
LBHs privacy team meets with the Application development and Security teams, as well as key
business stakeholders on a periodic basis. LBH also implements Privacy by Design (PbD) into the
application development process.
The Privacy Team is conducting a Privacy Impact Assessment (PIA) to evaluate privacy risks during
development of the application. The team must assess whether the application is collecting
descriptive, demographic or any other user related data from the electronic health records that are
not needed for the purposes of the application. The team is also reviewing whether the application
may collect additional personal data for purposes for which the user did not provide consent.
What is the best way to minimize the risk of an exposure violation through the use of the app?
D
SCENARIO
Please use the following to answer the next question:
Light Blue Health (LBH) is a healthcare technology company developing a new web and mobile
application that collects personal health information from electronic patient health records. The
application will use machine learning to recommend potential medical treatments and medications
based on information collected from anonymized electronic health records. Patient users may also
share health data collected from other mobile apps with the LBH app.
The application requires consent from the patient before importing electronic health records into the
application and sharing it with their authorized physicians or healthcare provider. The patient can
then review and share the recommended treatments with their physicians securely through the app.
The patient user may also share location data and upload photos in the app. The patient user may
also share location data and upload photos in the app for a healthcare provider to review along with
the health record. The patient may also delegate access to the app.
LBHs privacy team meets with the Application development and Security teams, as well as key
business stakeholders on a periodic basis. LBH also implements Privacy by Design (PbD) into the
application development process.
The Privacy Team is conducting a Privacy Impact Assessment (PIA) to evaluate privacy risks during
development of the application. The team must assess whether the application is collecting
descriptive, demographic or any other user related data from the electronic health records that are
not needed for the purposes of the application. The team is also reviewing whether the application
may collect additional personal data for purposes for which the user did not provide consent.
Regarding the app, which action is an example of a decisional interference violation?
D
SCENARIO
Please use the following to answer the next question:
Light Blue Health (LBH) is a healthcare technology company developing a new web and mobile
application that collects personal health information from electronic patient health records. The
application will use machine learning to recommend potential medical treatments and medications
based on information collected from anonymized electronic health records. Patient users may also
share health data collected from other mobile apps with the LBH app.
The application requires consent from the patient before importing electronic health records into the
application and sharing it with their authorized physicians or healthcare provider. The patient can
then review and share the recommended treatments with their physicians securely through the app.
The patient user may also share location data and upload photos in the app. The patient user may
also share location data and upload photos in the app for a healthcare provider to review along with
the health record. The patient may also delegate access to the app.
LBHs privacy team meets with the Application development and Security teams, as well as key
business stakeholders on a periodic basis. LBH also implements Privacy by Design (PbD) into the
application development process.
The Privacy Team is conducting a Privacy Impact Assessment (PIA) to evaluate privacy risks during
development of the application. The team must assess whether the application is collecting
descriptive, demographic or any other user related data from the electronic health records that are
not needed for the purposes of the application. The team is also reviewing whether the application
may collect additional personal data for purposes for which the user did not provide consent.
The Privacy Team is conducting a Privacy Impact Assessment (PIA) for the new Light Blue Health
application currently in development. Which of the following best describes a risk that is likely to
result in a privacy breach?
A
SCENARIO
Please use the following to answer the next question:
Light Blue Health (LBH) is a healthcare technology company developing a new web and mobile
application that collects personal health information from electronic patient health records. The
application will use machine learning to recommend potential medical treatments and medications
based on information collected from anonymized electronic health records. Patient users may also
share health data collected from other mobile apps with the LBH app.
The application requires consent from the patient before importing electronic health records into the
application and sharing it with their authorized physicians or healthcare provider. The patient can
then review and share the recommended treatments with their physicians securely through the app.
The patient user may also share location data and upload photos in the app. The patient user may
also share location data and upload photos in the app for a healthcare provider to review along with
the health record. The patient may also delegate access to the app.
LBHs privacy team meets with the Application development and Security teams, as well as key
business stakeholders on a periodic basis. LBH also implements Privacy by Design (PbD) into the
application development process.
The Privacy Team is conducting a Privacy Impact Assessment (PIA) to evaluate privacy risks during
development of the application. The team must assess whether the application is collecting
descriptive, demographic or any other user related data from the electronic health records that are
not needed for the purposes of the application. The team is also reviewing whether the application
may collect additional personal data for purposes for which the user did not provide consent.
What is the best way to ensure that the application only collects personal data that is needed to fulfill
its primary purpose of providing potential medical and healthcare recommendations?
C
Which of the following would be the best method of ensuring that Information Technology projects
follow Privacy by Design (PbD) principles?
D
What Privacy by Design (PbD) element should include a de-identification or deletion plan?
C
A privacy engineer reviews a newly developed on-line registration page on a companys website. The
purpose of the page is to enable corporate customers to submit a returns / refund request for
physical goods. The page displays the following data capture fields: company name, account
reference, company address, contact name, email address, contact phone number, product name,
quantity, issue description and company bank account details.
After her review, the privacy engineer recommends setting certain capture fields as non-
mandatory. Setting which of the following fields as non-mandatory would be the best example of
the principle of data minimization?
B