FIP Sample Questions & Answers
Privacy law and regulation carries the most weight, followed by building and running a privacy program, engineering privacy into technology, AI governance foundations, and the leadership experience expected of a senior privacy professional.
Launch the full FIP simulator →Showing 6 of 12 free samples.
- Question 1Advanced
Privacy Technology and Engineering (CIPT Focus) · Privacy by Design and Privacy-Enhancing Technologies
A software engineer is architecting a new healthcare application that uses Differential Privacy to share aggregate patient statistics with researchers. To implement this correctly, the engineer needs to determine the 'privacy budget' (epsilon). Which of the following statements accurately describes the trade-off involved in setting the epsilon value?
graph LR A[Raw Data] --> B{Privacy Mechanism} B -->|Add Noise| C[Output] style B fill:#f9f,stroke:#333,stroke-width:2px subgraph Tradeoff D[Low Epsilon] --> E[High Privacy / Low Utility] F[High Epsilon] --> G[Low Privacy / High Utility] endShow answer & explanation
Correct answer: A
In differential privacy, 'epsilon' (ε) quantifies the privacy loss. A smaller epsilon means stricter privacy (less information leakage), which is achieved by adding more random noise to the data. This increased noise reduces the utility (accuracy) of the dataset for the researchers. Conversely, a higher epsilon adds less noise (better utility) but offers weaker privacy guarantees.
- Question 2Intermediate
AI Governance (AIGP Pathway) · AI-specific regulations (EU AI Act, NIST AI RMF)
According to the EU AI Act, an AI system intended to be used for real-time remote biometric identification in publicly accessible spaces for law enforcement is generally classified as which risk level?
Show answer & explanation
Correct answer: C
Under the EU AI Act, 'real-time' remote biometric identification in publicly accessible spaces for law enforcement purposes is classified as an Unacceptable Risk and is prohibited in principle (Article 5). There are very narrow exceptions (e.g., searching for missing children, preventing imminent terrorist threats) which require judicial authorization, but the baseline classification is prohibited/unacceptable.
- Question 3Intermediate
Professional Experience and Leadership · Privacy Leadership and Applied Knowledge
You are the CPO of a company that has just acquired a smaller startup. During due diligence, you discovered the startup has no formal data retention policy and has been storing customer PII indefinitely. What is your immediate priority as a leader to integrate this acquisition into your privacy program?
Show answer & explanation
Correct answer: B
As a leader, you cannot make arbitrary decisions (like deleting data older than 2 years) without understanding the data. The first step in post-acquisition integration is to understand what you have acquired. A data inventory/mapping exercise is necessary to determine what data exists, why it is held, and what legal or business requirements dictate its retention. Only then can a compliant retention schedule be enforced.
- Question 4Intermediate
Privacy Law and Regulation (CIPP Foundation) · Privacy Legislation and Regulation
A US-based e-commerce company is updating its privacy policy to comply with the California Privacy Rights Act (CPRA). The company shares customer browsing history with third-party advertising networks to facilitate targeted ads. Under CPRA, how must this activity be presented to the consumer?
Show answer & explanation
Correct answer: A
The CPRA expanded the CCPA's opt-out rights to explicitly include 'sharing' of personal information for cross-context behavioral advertising, regardless of whether monetary consideration is exchanged. The required link on the homepage must now read 'Do Not Sell or Share My Personal Information' (or the company must honor valid opt-out preference signals like GPC).
- Question 5Beginner
Privacy Technology and Engineering (CIPT Focus) · Privacy by Design and Privacy-Enhancing Technologies
When implementing a Privacy by Design (PbD) framework during the software development lifecycle (SDLC), at which phase is it MOST effective to conduct the initial privacy threshold assessment?
Show answer & explanation
Correct answer: C
Privacy by Design principles dictate that privacy should be proactive, not reactive. Conducting the assessment in the Requirements or Design phase allows privacy controls to be architected into the system before code is written, which is more cost-effective and robust than attempting to patch issues during Testing or Deployment.
- Question 6IntermediateSelect 2
Privacy Program Management (CIPM Focus) · Privacy Program Operations
Which TWO of the following are primary components of a comprehensive Vendor Privacy Risk Management program? (Select TWO)
Show answer & explanation
Correct answers: A, D
Pre-contract due diligence is essential to assess the vendor's security and privacy posture before sharing data. Contractual clauses (like GDPR Art 28 terms) bind the vendor to specific legal obligations. These two elements—assessment and contracting—are the pillars of vendor risk management.
Pre-contract due diligence is essential to assess the vendor's security and privacy posture before sharing data. Contractual clauses (like GDPR Art 28 terms) bind the vendor to specific legal obligations. These two elements—assessment and contracting—are the pillars of vendor risk management.
Ready for the real thing?
The full FIP simulator has every exam-style question, timed mode, and instant scoring.