IAPP CIPT Exam Prep
Certified Information Privacy Technologist (CIPT) (Page 11 )

Updated On: 12-Sep-2026

Revocation and reissuing of compromised credentials is impossible for which of the following authentication techniques?

  1. Biometric data.
  2. Picture passwords.
  3. Personal identification number.
  4. Radio frequency identification.

Answer(s): A

Explanation:

Answer(s): A – Biometric data
Why biometric authentication cannot be revoked or re-issued: Biometric identifiers (e.g., fingerprints, iris patterns, facial geometry) are intrinsic to the user and are captured as immutable physical traits. Once a biometric template is compromised, the underlying biological characteristic cannot be “changed” without fundamentally altering the individual. Unlike secrets or tokens, a biometric value cannot be reset, re-issued, or replaced with a new secret; the only mitigation is to enroll a different modality or to switch to a different authentication method altogether. Consequently, the revocation of a compromised biometric credential is effectively impossible, forcing a complete re-enrollment and often a change of the underlying device or sensor.
Why the other options are not impossible:
Picture passwords (B) – The image or pattern used as a password is a memorized secret that can be replaced with a new picture or pattern at any time; revocation is simply a matter of changing the stored template. Personal identification number (PIN) (C) – PINs are secret numeric codes stored in a system; if compromised, the user can immediately set a new PIN, restoring security without affecting other credentials. Radio-frequency identification (RFID) (D) – RFID tags or cards carry adjustable credentials (e.g., keys, certificates).
When a tag is compromised, it can be de-provisioned and a new tag provisioned with fresh cryptographic material, effectively revoking the old credential.
Because only biometric authentication fundamentally ties the credential to an unchangeable physiological attribute, it is the sole technique among the choices for which revocation and re-issuance of compromised credentials is impossible.


Reference:

1. NIST Special Publication 800-63-3 – Digital Identity Guidelines https://csrc.nist.gov/publications/detail/sp/800-63-3/final
2. ISO/IEC 19794-5 – Information technology – Biometric interoperability – Data interchange format – Part 5: Fingerprint images (provides specifications for biometric data handling and security considerations) https://www.iso.org/standard/73090.html



What is the main function of the Amnesic Incognito Live System or TAILS device?

  1. It allows the user to run a self-contained computer from a USB device.
  2. It accesses systems with a credential that leaves no discernable tracks.
  3. It encrypts data stored on any computer on a network.
  4. It causes a system to suspend its security protocols.

Answer(s): A

Explanation:

Correct Answer: A – “It allows the user to run a self-contained computer from a USB device.”
Why A is correct
TAILS (The Amnesic Incognito Live System) is a live operating system that boots directly from removable media (USB stick, DVD, etc.). It loads entirely into RAM, leaving no persistent state on the host machine, thereby fulfilling the “amnesic” requirement. The entire OS, its applications, and bundled security tools (Tor, encryption utilities, sandboxed browsers, etc.) are packaged within that single, self-contained image, enabling the user to run a complete computer environment without installing anything on the target system.
Why B is less suitable
While TAILS does erase traces of activity, its primary design is not to “access systems with a credential that leaves no discernable tracks.” Option B implies a focus on credential-based remote access with stealthy authentication, which describes more specialized tools (e.g., credential-stealing or covert remote admin utilities) rather than the whole purpose of TAILS.
Why C is less suitable
TAILS does not encrypt data stored on any computer on a network; it provides on-disk encryption only for the data it creates on the volatile storage of the live session. Network-wide encryption is outside the scope of its core functionality and is therefore inaccurate.
Why D is less suitable
TAILS does not “cause a system to suspend its security protocols”; rather, it deliberately isolates all activity within a hardened, read-only environment that intentionally enhances security by preventing any modifications to the host OS.


Reference:

Tails Documentation – Overview: https://tails.boum.org/about/index.en.html Tails Documentation – Security Features: https://tails.boum.org/doc/about/



Which is NOT a drawback to using a biometric recognition system?

  1. It can require more maintenance and support.
  2. It can be more expensive than other systems
  3. It has limited compatibility across systems.
  4. It is difficult for people to use.

Answer(s): D

Explanation:

Justification

A: More maintenance and support – Biometric sensors degrade over time, require regular cleaning, calibration, and updates to the underlying algorithms, leading to added operational overhead. This is a recognized disadvantage. B. Higher cost – Compared with traditional token- or password-based solutions, biometric systems involve expensive hardware (readers, enrollment stations) and ongoing software licensing for sophisticated matching engines, making cost a genuine drawback. C. Limited cross-system compatibility – Proprietary biometric standards and differing sensor vendors often restrict interoperability; integrating a solution with existing access-control infrastructure can be challenging. D. Difficulty of use – This is not an inherent drawback of biometric recognition. Modern systems incorporate intuitive enrollment UI, quick one-touch verification, and optional fallback methods (e.g., PIN), making them generally easy to use for most users.
While usability can vary, the difficulty is not a systematic, universal disadvantage compared with the concrete issues listed in A-C.
Therefore, option D is the only statement that does not represent a genuine, universal drawback to biometric recognition, making it the correct answer.


Reference:

International Organization for Standardization. ISO/IEC 30107-3:2018 – Presentation Attack Detection – Part 3: Requirements and Test Methods. https://www.iso.org/standard/75357.html National Institute of Standards and Technology. Biometric Systems: Guidelines for Design and Evaluation. https://csrc.nist.gov/publications/detail/sp/800-76-2/rev-1/final (accessed 2025)



What is a main benefit of data aggregation?

  1. It is a good way to perform analysis without needing a statistician.
  2. It applies two or more layers of protection to a single data record.
  3. It allows one to draw valid conclusions from small data samples.
  4. It is a good way to achieve de-identification and unlinkabilty.

Answer(s): D

Explanation:

Why option D is the correct main benefit of data aggregation
De-identification & unlinkability – Aggregating records combines data from multiple sources or partitions so that patterns are observable only at the group level; individual identities are removed, making it difficult to re-identify participants. This satisfies privacy-preserving analytics requirements such as GDPR “pseudonymisation” or HIPAA “de-identified” status. Statistical robustness – Aggregated datasets increase sample size, reducing sampling bias and improving the reliability of derived insights without the need for specialized statistical expertise in each isolated dataset.
Resource efficiency – By processing and analyzing grouped data in blocks, organizations can optimize compute resources while still satisfying analytical use-cases like trend analysis, reporting, and privacy-enhancing statistical modeling.
Why the other choices are less suitable
Option A – “Analysis without needing a statistician” is misleading; aggregated data often still requires statistical methods to interpret trends, uncertainty, or significance correctly. Option B – “Two or more layers of protection on a single record” describes stacking protective mechanisms (e.g., encryption + access control) rather than the core purpose of aggregation, which is to generalize data across many records. Option C – “Draw valid conclusions from small data samples” is the opposite of aggregation’s strength; aggregation expands the effective sample size, reducing reliance on small-sample conclusions.


Reference:

CIPP Exam Study Guide – International Association of Privacy Professionals (IAPP) : https://iapp.org/resources/privacy-certification/cipp-study-guide/ NIST Special Publication 800-122 – Guide to Protecting the Confidentiality of Personally Identifiable Information : https://doi.org/10.6028/NIST.SP.800-122



Under the Family Educational Rights and Privacy Act (FERPA), releasing personally identifiable information from a student's educational record requires written permission from the parent or eligible student in order for information to be?

  1. Released to a prospective employer.
  2. Released to schools to which a student is transferring.
  3. Released to specific individuals for audit or evaluation purposes.
  4. Released in response to a judicial order or lawfully ordered subpoena.

Answer(s): A

Explanation:

Technical justification
FERPA’s baseline rule is that education records containing personally identifiable information (PII) may not be disclosed without the prior written consent of the parent or, when applicable, the eligible student. Permissible disclosures without consent are narrowly defined (e.g., to school officials with a legitimate educational interest, to institutions where the student is transferring, or in response to a lawful subpoena/judicial order). These exceptions are explicitly enumerated in the statute and the U.S. Department of Education’s FERPA regulations. Option A – prospective employer : Disclosure of a student’s education records to a prospective employer is not covered by any of the statutory exceptions. Consequently, the school must obtain a written release from the parent or eligible student before any PII can be shared with that employer. Option B – schools to which a student is transferring : FERPA expressly permits the transfer of records to a receiving school without prior written consent, provided the disclosure is for “legitimate educational purposes.” Therefore, written permission is not required . Option C – specific individuals for audit or evaluation : Audits and evaluations may be conducted by designated entities without prior written consent if the purpose is authorized under the “research or audit” exception, and the recipient must adhere to FERPA’s confidentiality requirements. Hence, written permission is not mandatory in this scenario. Option D – judicial order or subpoena : A school may disclose records in response to a court order or subpoena without written consent, provided the school makes a reasonable attempt to notify the parent or student of the order. Consequently, written permission is not required .
Conclusion The only circumstance among the choices that requires prior written permission from the parent or eligible student is when the records are to be released to a prospective employer.


Reference:

U.S. Department of Education, FERPA (Family Educational Rights and Privacy Act) – “Student Records: What’re the Rules?” https://www2.ed.gov/policy/gen/guid/fpco/ferpa-index.html U.S. Department of Education, “FERPA and the Release of Student Information to Employers” (official guidance) https://www2.ed.gov/policy/gen/guid/fpco/ferpa-employers.html



Viewing page 11 of 66
Viewing questions 51 - 55 out of 325 questions


Post your Comments and Discuss IAPP CIPT exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!