Stimulate the real exam
Our DCPLA study practice guide boosts the function to stimulate the real exam. The clients can use our software to stimulate the real exam to be familiar with the speed, environment and pressure of the real DCPLA exam and get a well preparation for the real exam. Under the virtual exam environment the clients can adjust their speeds to answer the DCPLA questions, train their actual combat abilities and be adjusted to the pressure of the real test. They can also have an understanding of their mastery degree of our DCPLA study practice guide. The clients can use our software to stimulate the real exam at any time and there are no limits for the times of stimulation.
Save time
Our DCPLA useful test guide materials present the most important information to the clients in the simplest way so our clients need little time and energy to learn our DCPLA useful test guide. The clients only need 20-30 hours to learn and prepare for the test. For those people who are busy in their jobs, learning or other things this is a good news because they needn't worry too much that they don't have enough time to prepare for the test and can leisurely do their main things and spare little time to learn our DCPLA study practice guide. So it is a great advantage of our DSCI Certified Privacy Lead Assessor DCPLA certification exam materials and a great convenience for the clients.
Our world is in the state of constant change and evolving. If you want to keep pace of the time and continually transform and challenge yourself you must attend one kind of DSCI certificate test to improve your practical ability and increase the quantity of your knowledge. Buying our DCPLA study practice guide can help you pass the test smoothly. Our DSCI Certified Privacy Lead Assessor DCPLA certification exam materials have gone through strict analysis and verification by senior experts and are ready to supplement new resources at any time. We try our best to present you the most useful and efficient information about the test and provide multiple functions and intuitive methods to help the clients learn efficiently. Learning our DCPLA useful test guide costs you little time and energy. The passing rate and hit rate are both high thus you will encounter few obstacles to pass the test. You can further understand our DCPLA study practice guide after you read the introduction as follow.
Free trials
Before the clients purchase our DCPLA study practice guide, they can have a free trial freely. The clients can log in our company's website and visit the pages of our products. The pages of our products lists many important information about our DSCI Certified Privacy Lead Assessor DCPLA certification exam materials and they include the price, version and updated time of our products, the exam name and code, the total amount of the questions and answers, the merits of our DCPLA useful test guide and the discounts. You can have a comprehensive understanding of our DCPLA useful test guide after you see this information. Then you can look at the free demos and try to answer them to see the value of our DSCI Certified Privacy Lead Assessor DCPLA certification exam materials and finally decide to buy them or not.
DSCI Certified Privacy Lead Assessor DCPLA certification Sample Questions:
1. Which of the following is the most effective way of ensuring the conformity to legal and regulations from the business functions, processes and relationships?
A) Providing a special section on regulatory and compliance requirements on internal portal, providing access to respective owner of functions, processes and relationships
B) Conducting classroom training and awareness sessions on regulatory and compliance requirements
C) Customised delivery of information on regulatory and compliance information to the functions, processes and relationships
D) Deploying desktop screens articulating information on regulations and responsibility of the organisation
2. Arrange the following techniques in decreasing order of the risk of re-identification:
I) Pseudonymization
II) De-identification
III) Anonymization
A) III, II, I
B) All have equal risk of re-identification
C) I, II
D) II, III, I
3. Which of the following wasn't prescribed as a privacy principle under the OECD Privacy Guidelines, 1980?
A) Openness
B) Data Minimization
C) Purpose Specification
D) Security Safeguard
4. Which of the following activities form part of an organization's Visibility over Personal Information (VPI) initiative, according to DSCI Privacy Framework (DPF)?
A) 'Data processing environment' analysis of industry peers
B) 'Data processing environment' analysis of the organization and associated third parties
C) 'Data processing environment' analysis of the country
D) 'Data processing environment' analysis of the organization only
5. FILL BLANK
RCI and PCM
In April 2011, the rules were issued under Section 43A of the IT Act by the Government of India and the
'body corporates' were required to comply with these rules. The Corporate legal team tried to understand and interpret the rules but struggled to understand its applicability esp. to client relationships and business functions. So, the company hired an IT Act legal expert to advise them on the Section 43A rules.
To start with, the company identified the PI dealt with by business functions as part of the earlier visibility exercise, but it wanted to reassure itself. Therefore, a specific exercise was conducted to revisit 'sensitive personal information' dealt by business functions. It was realized that the company collects lot of SPI of its employees and therefore 'reasonable security practices' need to be adhered to by the functions that deal with SPI. It was also ascertained that many of this SPI is being dealt by third parties, some of which are also located outside India. To meet the requirements of the rules, the company reviewed all the contracts and inserted a clause - 'the service provider shall implement reasonable security practices and procedures as per the IT (Amendment) Act, 2008'. Some of the large service providers were ISO 27001 certified and they claimed that they fulfill the requirements of 'reasonable security practices'. However, some SME service providers did not understand what would 'reasonable security practices' imply and requested the company to clarify, which referred them to Rule 8 of the Section 43A. Some small scale service providers expressed their unwillingness to get ISO certified, given the costs involved.
(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a definitive conclusion) Introduction and Background XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves more than
500 clients across industry verticals - BFSI, Retail, Government, Healthcare, Telecom among others in Americas, Europe, Asia-Pacific, Middle East and Africa. The company provides IT services including application development and maintenance, IT Infrastructure management, consulting, among others. It also offers IT products mainly for its BFSI customers.
The company is witnessing phenomenal growth in the BPM services over last few years including Finance and Accounting including credit card processing, Payroll processing, Customer support, Legal Process Outsourcing, among others and has rolled out platform based services. Most of the company's revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the company is looking to expand its operations in Europe. India, too has attracted company's attention given the phenomenal increase in domestic IT spend esp. by the government through various large scale IT projects. The company is also very aggressive in the cloud and mobility space, with a strong focus on delivery of cloud services. When it comes to expanding operations in Europe, company is facing difficulties in realizing the full potential of the market because of privacy related concerns of the clients arising from the stringent regulatory requirements based on EU General Data Protection Regulation (EU GDPR).
To get better access to this market, the company decided to invest in privacy, so that it is able to provide increased assurance to potential clients in the EU and this will also benefit its US operations because privacy concerns are also on rise in the US. It will also help company leverage outsourcing opportunities in the Healthcare sector in the US which would involve protection of sensitive medical records of the US citizens.
The company believes that privacy will also be a key differentiator in the cloud business going forward. In short, privacy was taken up as a strategic initiative in the company in early 2011.
Since XYZ had an internal consulting arm, it assigned the responsibility of designing and implementing an enterprise wide privacy program to the consulting arm. The consulting arm had very good expertise in information security consulting but had limited expertise in the privacy domain. The project was to be driven by CIO's office, in close consultation with the Corporate Information Security and Legal functions.
Did the company take sufficient steps to protect SPI dealt by its service providers and ensure that it complies with the regulatory requirements? Was referring to 'reasonable security practices' sufficient in the contracts or the company should have also considered some other measures for privacy protection as well? (250 to 500 words)
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: C | Question # 3 Answer: B | Question # 4 Answer: B | Question # 5 Answer: Only visible for members |








