CIPPUS Exam Prep Free practice test →

Free CIPPUS Practice Questions

10 free, exam-style Certified Information Privacy Professional/United States (CIPPUS) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CIPPUS practice test to study every exam domain.

These 10 free CIPPUS questions are organized by exam domain, so you can see how each part of the Certified Information Privacy Professional/United States blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Introduction to the U.S. Privacy Environment

Question 1

Scenario: A company implements a new data collection system. What governance step is required to assess privacy impacts before deployment?

  1. Conduct a privacy impact assessment
  2. Launch immediately to test with users
  3. Wait for customer complaints
  4. Increase data storage capacity
Show answer & explanation

Correct answer: A - Conduct a privacy impact assessment

Question 2

Scenario: U.S. company transfers EU customer data to U.S. servers using Data Privacy Framework. What is required for compliance?

  1. Self-certification and adherence to DPF principles
  2. No certification needed for U.S. companies
  3. Only encryption is required
  4. GDPR does not apply to U.S. companies
Show answer & explanation

Correct answer: A - Self-certification and adherence to DPF principles

Question 3

Scenario: Organization discovers a large data breach affecting 5,000 customers. What is the notification timeline requirement?

  1. Without unreasonable delay, maximum 60 days
  2. Within 24 hours
  3. Within 1 year
  4. No notification required if data encrypted
Show answer & explanation

Correct answer: A - Without unreasonable delay, maximum 60 days

Question 4

Scenario: A company designs a new mobile app. What Privacy by Design principle requires implementing preventive privacy measures?

  1. Proactive not reactive
  2. Privacy as default setting
  3. End-to-end security
  4. Visibility and transparency
Show answer & explanation

Correct answer: A - Proactive not reactive

Domain 2: Limits on Private-Sector Collection and Use of Data

Question 5

Scenario: An app targeted at children collects geolocation data without verifiable parental consent. What law is violated? The app is for users aged 8-12 and shares data with advertisers.

  1. COPPA
  2. TCPA
  3. HIPAA
  4. FERPA
Show answer & explanation

Correct answer: A - COPPA

Question 6

Scenario: A business associate discovers a breach of protected health information. What must they do regarding the covered entity?

  1. Notify covered entity without unreasonable delay
  2. Wait 60 days before notifying
  3. No notification required
  4. Only notify if over 500 records
Show answer & explanation

Correct answer: A - Notify covered entity without unreasonable delay

Question 7

Scenario: A bank shares customer account details with its marketing affiliate without providing opt-out notice. What law applies?

  1. GLBA Privacy Rule violation
  2. HIPAA Security Rule
  3. FCRA disclosure requirement
  4. No violation if same company
Show answer & explanation

Correct answer: A - GLBA Privacy Rule violation

Question 8

Scenario: A marketer uses web-scraped data from public profiles to send targeted text messages without consent. What requirement applies?

  1. TCPA requirement for prior express written consent
  2. CAN-SPAM opt-out only
  3. Free speech under First Amendment overrides privacy
  4. Public data exemption applies
Show answer & explanation

Correct answer: A - TCPA requirement for prior express written consent

Domain 4: Workplace Privacy

Question 9

Scenario: Employer uses AI-driven tool to screen job applicants' resumes in New York City. What is required under NYC AEDT Law?

  1. Bias audit required annually
  2. No requirements for resume screening
  3. Only consent needed
  4. AI tools are prohibited
Show answer & explanation

Correct answer: A - Bias audit required annually

Question 10

Scenario: Company monitors employee emails on company server for business purposes. What does ECPA allow?

  1. Allowed under business purpose exception
  2. Prohibited without individual consent
  3. Only criminal monitoring allowed
  4. Requires court order
Show answer & explanation

Correct answer: A - Allowed under business purpose exception

The rest of the CIPPUS blueprint

The CIPPUS exam also covers these domains. Drill them in the full free practice test:

Ready for the real thing?

Practice hundreds more CIPPUS questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing