CIPT Exam Prep Free practice test →

Free CIPT Practice Questions

10 free, exam-style Certified Information Privacy Technologist (CIPT) (CIPT) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CIPT practice test to study every exam domain.

Question 1

A fintech startup processes EU customer financial data using servers in Singapore. The startup has no DPO, no data processing agreements with its cloud provider, and its privacy notice is a single sentence stating 'We respect your privacy.' Which of the following is the MOST critical compliance gap?

  1. The privacy notice fails to include the required disclosures under GDPR Articles 13 and 14
  2. The absence of a data processing agreement violates GDPR Article 28 controller-processor obligations
  3. The international transfer to Singapore lacks an adequate safeguard mechanism under Chapter V
  4. The organization has not designated a Data Protection Officer as required under Article 37
Show answer & explanation

Correct answer: B - The absence of a data processing agreement violates GDPR Article 28 controller-processor obligations

Question 2

A cookie consent interface shows 'Accept All' requiring one click, while 'Reject All' requires navigating through three separate pages of toggle switches. A regulator would MOST likely find this:

  1. Compliant, because users are provided with a functional mechanism to refuse consent
  2. Non-compliant, because the asymmetry undermines freely given consent under GDPR standards
  3. Compliant, provided each toggle switch is clearly labeled with its specific processing purpose
  4. Non-compliant, but only if the data controller is established within an EU member state
Show answer & explanation

Correct answer: B - Non-compliant, because the asymmetry undermines freely given consent under GDPR standards

Question 3

A predictive policing algorithm focuses resources on neighborhoods that have historically had more arrests. Increased police presence leads to more arrests in those areas, which further trains the algorithm to target those neighborhoods. This illustrates:

  1. Historical training data bias from unrepresentative sampling during initial data collection
  2. Proxy discrimination where a neutral variable correlates with a protected characteristic
  3. A feedback loop where biased model outputs reinforce and amplify the original data skew
  4. Disparate impact resulting from the use of facially neutral selection criteria in deployment
Show answer & explanation

Correct answer: C - A feedback loop where biased model outputs reinforce and amplify the original data skew

Question 4

An AI chatbot trained on customer support tickets begins reproducing actual customer names, email addresses, and order details in its responses to unrelated users. This is BEST described as:

  1. An attribute inference attack where the model deduces sensitive traits from non-sensitive inputs
  2. A model inversion attack that reconstructs training data through targeted query exploitation
  3. Training data memorization where the model retains and outputs verbatim personal data samples
  4. A membership inference attack that reveals whether specific records were used in training
Show answer & explanation

Correct answer: C - Training data memorization where the model retains and outputs verbatim personal data samples

Question 5

In a k-anonymous dataset with k=3, all three individuals in one equivalence class have 'diabetes' as their medical condition. An attacker who identifies this group can determine:

  1. Nothing meaningful, because k-anonymity guarantees full protection of sensitive attributes
  2. Only that the individuals share certain quasi-identifier values like age range or ZIP code
  3. The exact identity of each individual by cross-referencing against external data sources
  4. That every person in that equivalence class has diabetes, despite not knowing which is which
Show answer & explanation

Correct answer: D - That every person in that equivalence class has diabetes, despite not knowing which is which

Question 6

A cloud provider needs to run analytics on a hospital's encrypted patient data without ever decrypting it or seeing the plaintext. Which technology BEST enables this?

  1. Homomorphic encryption, which allows computation on ciphertext that produces encrypted results
  2. Symmetric encryption with a shared key managed through a hardware security module
  3. Trusted execution environments that isolate processing inside secure hardware enclaves
  4. Format-preserving encryption that maintains data structure while obscuring the content
Show answer & explanation

Correct answer: A - Homomorphic encryption, which allows computation on ciphertext that produces encrypted results

Question 7

A data subject submits a deletion request, but the organization also has a legal obligation to retain certain financial records containing that individual's data. The organization should:

  1. Delete all of the individual's data immediately to fully comply with the erasure request
  2. Retain only the specific data required by law and delete all remaining data for that individual
  3. Deny the entire deletion request and cite the legal retention obligation as justification
  4. Suspend all processing of the individual's data and escalate the conflict to the supervisory authority
Show answer & explanation

Correct answer: B - Retain only the specific data required by law and delete all remaining data for that individual

Question 8

An IoT manufacturer releases a smart doorbell with no privacy notice, no way to view or delete recordings, encryption only during cloud upload but not for local storage, and default video sharing with the manufacturer's partners. How many of the seven Privacy by Design foundational principles are violated?

  1. Two: privacy as the default setting and end-to-end security throughout the lifecycle
  2. Three: proactive not reactive, privacy as the default, and visibility and transparency
  3. Five: default settings, embedded design, full lifecycle security, transparency, and user respect
  4. All seven: every foundational principle is implicated by at least one of the identified failures
Show answer & explanation

Correct answer: C - Five: default settings, embedded design, full lifecycle security, transparency, and user respect

Question 9

A company's marketing team wants to enable detailed user tracking by default to maximize ad revenue, while the privacy team argues for minimal tracking by default. Under Privacy by Design, which position is correct?

  1. Marketing, because controllers may set defaults based on legitimate business interest balancing
  2. Privacy, because maximum privacy must be the default and both goals should be pursued together
  3. Neither, because the appropriate default should be determined through a formal DPIA process
  4. Both, because a compromise at a moderate level of tracking satisfies proportionality requirements
Show answer & explanation

Correct answer: B - Privacy, because maximum privacy must be the default and both goals should be pursued together

Question 10

A small company with 50 employees processes employee health data for occupational health purposes. Does the GDPR Record of Processing Activities (RoPA) exemption for organizations under 250 employees apply?

  1. Yes, because the employee count falls below the 250-employee threshold set by Article 30(5)
  2. Yes, because occupational health processing is considered occasional and not systematic in nature
  3. No, because the processing of special category health data triggers an exception to the exemption
  4. No, because every organization regardless of size must maintain a complete RoPA under Article 30
Show answer & explanation

Correct answer: C - No, because the processing of special category health data triggers an exception to the exemption

What's on the CIPT exam

The Certified Information Privacy Technologist (CIPT) (CIPT) exam is organized into 5 knowledge domains. These free practice questions are drawn from across them so you can see where you're strong and where to study:

  1. Foundational Principles of Privacy in Technology
  2. The Privacy Technologist's Role in the Context of the Organization
  3. Privacy Risks, Threats, and Violations
  4. Privacy-Enhancing Strategies and Techniques
  5. Privacy Engineering and Privacy by Design in the Development Lifecycle

Ready for the real thing?

Practice hundreds more CIPT questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing