Download EXIN Privacy and Data Protection Foundation.PDPF.SelfTestEngine.2018-12-02.17q.vcex

Vendor: Exin
Exam Code: PDPF
Exam Name: EXIN Privacy and Data Protection Foundation
Date: Dec 02, 2018
File Size: 13 KB

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

Demo Questions

Question 1
According to the GDPR, for which situations should a Data Protection impact Assessment (DPIA) be conducted?
  1. For all projects that include technologies or processes that require data protection
  2. For all sets of similar processing operations with comparable risks
  3. For any situation where technologies and processes will be subject to a risk assessment
  4. For technologies and processes that are likely to result in a high risk to the rights of data subjects
Correct answer: A
Question 2
While paying with a credit card, the card is skimmed (i.e. the data on the magnetic strip is stolen). The magnetic strip contains the account number, expiration date, cardholder’s name and address, PIN number and more. 
What kind of a data breach is this?
  1. Material
  2. Non-material
  3. Verbal
Correct answer: B
Question 3
Someone regularly receives offers from a store where he purchased something five years ago. He wants the company to stop sending offers and to wipe his personal data. 
Which aspect of the rights of a data subject in the General Data Protection Regulation (GDPR) requires the company to comply?
  1. The right to erasure
  2. The right to rectification
  3. The right to restriction of processing
  4. The right to withdraw consent
Correct answer: D
Question 4
Important technical requirements set out in the General Data Protection Regulation (GDPR) are about data quality. One is the obligation to ensure appropriate security, including protection against unauthorized or unlawful processing. 
What is another important technical requirement?
  1. To ascertain that personal data collection is adequate, relevant and limited to what is necessary in relation to the purposes
  2. To control that data collected for specified, explicit and legitimate purposes is not further processed for other purposes
  3. To keep personal data accurate and up to date, ensuring that inaccurate data are erased or rectified without delay
  4. To make sure that personal data is processed lawfully, fairly and in transparent manner in relation to the data subject
Correct answer: A
Question 5
According to the GDPR, what is a mandatory topic in a DPIA report?
  1. Systematic description of the fiduciary duties to ensure compliance to all relevant laws and regulations
  2. An assessment of the necessity and proportionality of the processing operations in relation to the purposes
  3. The documentation of the risks to the rights and freedoms of the data protection officer
  4. The measures envisaged to address the privacy compliance frameworks risks
Correct answer: B
Question 6
What is the role of the one assigned the responsibility to govern the purposes and means of processing personal data within an organization, according to the GDPR?
  1. Controller
  2. Data Protection Officer
  3. Data Subject
  4. Processor
Correct answer: A
Question 7
The GDPR states that records of processing activities must be kept by the controller. To whom must the controller make these records available, if requested?
  1. The data processor
  2. The Data Protection Officer
  3. The European Commission
  4. The supervisory authority
Correct answer: D
Question 8
Which situation is considered a data breach according to the GDPR?
  1. A processor deletes personal data after his contract with the controller expired.
  2. A processor leaves his computer unattended, where colleagues may be able to access it.
  3. After a disk crash a processor restores personal data from a recent back-up.
  4. After processing a processor deletes personal data on instruction of the controller.
Correct answer: B
Question 9
A controller is processing personal data based on consent of the data subjects. There are no other legitimate grounds. While processing, the controller discovers that a data subject whose consent for the processing had been received, has died since. 
What, according to the GDPR, will be the consequences for the controller with regard to the processing?
  1. The controller can proceed with the processing as intended.
  2. The controller can proceed, but only for the purposes for which consent has been given.
  3. The controller must act as if the data subject has withdrawn consent and erase his/her data.
  4. The controller needs to find the heir in order to require consent for the processing.
Correct answer: A
Question 10
According to the GDPR, what is the main reason to consider data protection in the initial design phase?
  1. It ensures efficiency in project phases
  2. It ensures privacy by default
  3. It reduces the risk of fraud
  4. It reduces the risk of liability
Correct answer: B

Use VCE Exam Simulator to open VCE files


Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!