IAPP

Certified Information Privacy Professional/US (CIPP/US) (CIPP-US) practice questions

US privacy law and information management knowledge for the IAPP CIPP/US exam, with a worked explanation on every practice question.

New to CIPP-US? Read the how to pass Certified Information Privacy Professional/US (CIPP/US) study guide for a domain breakdown, a study plan, and exam-day tips.

Revising? The CIPP-US cheat sheet puts the domain weightings, key facts, and easy-to-confuse traps on one printable page.

90
Questions
150 min
Time allowed
300 / 500
Pass mark
$550
Exam cost (USD)
286
Practice questions

Exam domains and weighting

The CIPP-US blueprint is split across 5 domains. See the official exam guide for the authoritative breakdown.

CIPP-US exam domain weighting - each domain's share of the exam. Full breakdown with links below.
CIPP-US domains by share of the exam
DomainWeight
Introduction to the U.S. Privacy Environment24%
Limits on Private-Sector Collection and Use of Data31%
Government and Court Access to Private-Sector Information12%
Workplace Privacy10%
State Privacy Laws23%

Free sample questions

No account needed. Every question has a worked explanation, just like the full bank.

Free sampleGovernment and Court Access to Private-Sector Informationhard

An FBI agent serves a provider with a National Security Letter and includes a nondisclosure requirement barring the provider from telling anyone, including the affected customer, that it received the NSL. The provider's counsel wants to know how the USA FREEDOM Act altered the legal posture of that nondisclosure requirement. Which statement is correct?

  • AThe provider may seek judicial review of the nondisclosure requirement, and the government must periodically reassess whether continued secrecy remains justified. Correct
  • BThe nondisclosure requirement is now permanent once imposed, and the provider has no statutory mechanism to seek its removal at any later time.
  • CThe nondisclosure requirement was abolished entirely, so providers receiving NSLs may now freely publish the specific contents of any NSL they receive.
  • DThe provider may disclose the NSL only after first obtaining written authorisation from the Foreign Intelligence Surveillance Court for each individual customer affected.
USA FREEDOM added judicial review and periodic reassessment for National Security Letter nondisclosure requirements rather than abolishing them. The USA FREEDOM Act left NSL authority intact but reformed the gag provisions, giving recipients access to judicial review and obliging the government to reassess and terminate nondisclosure when secrecy is no longer needed.

Why A is correct: Correct: USA FREEDOM established judicial-review procedures for NSL gag orders and reciprocal notice requiring the government to revisit whether nondisclosure is still warranted.

Why B is wrong: Tempting because NSL gag orders were historically open-ended, but USA FREEDOM created review and termination mechanisms, so the gag is not permanent and unchallengeable.

Why C is wrong: Tempting because reforms increased transparency, but USA FREEDOM did not abolish NSL gags; it added procedures and reciprocal-notice rules rather than removing them.

Why D is wrong: Tempting because the FISC oversees national security matters, but NSL nondisclosure review runs through ordinary judicial-review procedures, not per-customer FISC authorisation.

Free sampleIntroduction to the U.S. Privacy Environmentmedium

A technology company has not violated any specific privacy statute, yet the Federal Trade Commission opens an enforcement action alleging the company misrepresented its data-sharing practices to consumers. On what legal source does the FTC most directly rely to bring this action?

  • AThe common law tort of intrusion upon seclusion, which the FTC enforces on behalf of consumers in federal court.
  • BIts statutory authority under Section 5 of the FTC Act to challenge unfair or deceptive acts or practices. Correct
  • CA constitutional right to fair dealing implied by the Due Process Clause of the Fourteenth Amendment.
  • DA self-regulatory code of conduct that the company adopted and the FTC enforces as binding federal regulation.
Identify Section 5 of the FTC Act as the statutory basis for FTC enforcement against deceptive privacy representations. The FTC's general enforcement power comes from Section 5 of the FTC Act, which bars unfair or deceptive acts or practices, allowing action against misrepresentations even absent a sector-specific privacy statute.

Why A is wrong: Tempting because intrusion is a privacy wrong, but it is a private tort claim brought by individuals, not a statutory power the FTC invokes for enforcement.

Why B is correct: Correct: Section 5 of the FTC Act prohibits unfair or deceptive acts or practices, letting the FTC act on a misrepresentation even where no specific privacy statute applies.

Why C is wrong: Tempting because due process sounds protective, but it limits government conduct toward individuals and is not the source of FTC authority over deceptive business practices.

Why D is wrong: Tempting because broken promises in a code can support a case, but the code is not itself the legal source, and the FTC's authority flows from the FTC Act.

Free sampleState Privacy Lawshard

A bank that does business in several states uses a fully automated model to approve or deny consumer credit-line increases with no human involvement. Counsel is mapping which state comprehensive privacy laws give the consumer a right to opt out of this kind of profiling. Under the leading state comprehensive privacy model, what is the threshold that determines whether the consumer has an opt-out right over this automated decision?

  • AWhether the automated model processes any personal data at all, since all automated processing triggers the profiling opt-out.
  • BWhether the consumer has previously exercised a separate right to delete their personal data held by the bank.
  • CWhether the profiling is carried out in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. Correct
  • DWhether the bank has annual revenue above a fixed dollar figure set by each state's profiling provision.
Recognise that state comprehensive privacy laws tie the profiling opt-out to automated decisions producing legal or similarly significant effects on the consumer. Under the Virginia, Colorado, and Connecticut comprehensive privacy models, the consumer's right to opt out of profiling is limited to profiling in furtherance of decisions that produce legal or similarly significant effects, such as credit, housing, or employment outcomes, rather than to all automated processing.

Why A is wrong: It is tempting to assume any automated processing triggers the right, but the opt-out is tied to significant-effect profiling, not to processing generally, so this overstates the scope.

Why B is wrong: Deletion and profiling opt-out are independent rights, so making one a precondition of the other confuses two distinct consumer entitlements under these statutes.

Why C is correct: State comprehensive laws such as the Colorado, Connecticut, and Virginia models grant an opt-out of profiling specifically when it is in furtherance of decisions producing legal or similarly significant effects, which a credit-line decision is.

Why D is wrong: Revenue thresholds appear in the applicability sections of some privacy laws, but the profiling opt-out is defined by the nature of the decision and its effect, not by a revenue figure inside the profiling provision.

Frequently asked questions

How many questions are on the CIPP-US exam?
The Certified Information Privacy Professional/US (CIPP/US) (CIPP-US) exam has 90 questions and runs for 150 minutes. The format is multiple choice, online proctored or pearson vue test centre.
What score do I need to pass CIPP-US?
The pass mark is 300 / 500. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
How much does the CIPP-US exam cost?
The exam costs 550 USD to sit. Practising on Examworthy is free to start, with a worked explanation on every question.
How does Examworthy help me prepare for CIPP-US?
Every practice question carries a worked explanation and a per-distractor rationale, mapped to the official blueprint domains. You learn why each answer is right or wrong, not just the letter.
Is Examworthy affiliated with IAPP?
No. Examworthy is not affiliated with or endorsed by IAPP. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.

Related certifications

More certifications you can practise on Examworthy, related to Certified Information Privacy Professional/US (CIPP/US).

Browse all certifications

Examworthy is not affiliated with or endorsed by IAPP. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CIPP-US and related marks belong to their respective owners.