New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPM Exam - Topic 2 Question 92 Discussion

Actual exam question for IAPP's CIPM exam
Question #: 92
Topic #: 2
[All CIPM Questions]

SCENARIO

Please use the following to answer the next QUESTIO N:

Liam is the newly appointed information technology (IT) compliance manager at Mesa, a USbased outdoor clothing brand with a global E-commerce presence. During his second week, he is contacted by the company's IT audit manager, who informs him that the auditing team will be conducting a review of Mesa's privacy compliance risk in a month.

A bit nervous about the audit, Liam asks his boss what his predecessor had completed related to privacy compliance before leaving the company. Liam is told that a consent management tool had been added to the website and they commissioned a privacy risk evaluation from a small consulting firm last year that determined that their risk exposure was relatively low given their current control environment. After reading the consultant's report, Liam realized that the scope of the assessment was limited to breach notification laws in the US and the Payment Card Industry's Data Security Standard (PCI DSS).

Not wanting to let down his new team, Liam kept his concerns about the report to himself and figured he could try to put some additional controls into place before the audit. Having some privacy compliance experience in his last role, Liam thought he might start by having discussions with the E-commerce and marketing teams.

The E-commerce Director informed him that they were still using the cookie consent tool forcibly placed on the home screen by the CIO, but could not understand the point since their office was not located in California or Europe. The marketing director touted his department's success with purchasing email lists and taking a shotgun approach to direct marketing. Both directors highlighted their tracking tools on the website to enhance customer experience while learning more about where else the customer had shopped. The more people Liam met with, the more it became apparent that privacy awareness and the general control environment at Mesa needed help.

With three weeks before the audit, Liam updated Mesa's Privacy Notice himself, which was taken and revised from a competitor's website. He also wrote policies and procedures outlining the roles and responsibilities for privacy within Mesa and distributed the document to all departments he knew of with access to personal information.

During this time. Liam also filled the backlog of data subject requests for deletion that had been sent to him by the customer service manager. Liam worked with application owners to remove these individual's information and order history from the customer relationship management (CRM) tool, the enterprise resource planning (ERP). the data warehouse and the email server.

At the audit kick-off meeting. Liam explained to his boss and her team that there may still be some room for improvement, but he thought the risk had been mitigated to an appropriate level based on the work he had done thus far.

After the audit had been completed, the audit manager and Liam met to discuss her team's findings, and much to his dismay. Liam was told that none of the work he had completed prior to the audit followed best practices for governance and risk mitigation. In fact, his actions only opened the company up to additional risk and scrutiny. Based on these findings. Liam worked with external counsel and an established privacy consultant to develop a remediation plan.

All of the key phases of an audit have occurred with Liam's involvement in the situation EXCEPT?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Brandon
16 days ago
Wait, he copied a competitor's privacy notice? That's risky!
upvoted 0 times
...
Remona
21 days ago
Totally agree, the cookie consent tool is a must!
upvoted 0 times
...
Maryln
26 days ago
Liam should have done more research on privacy laws.
upvoted 0 times
...
Rupert
1 month ago
Haha, Liam really dropped the ball on this one. I bet his boss is not happy with him. D) Follow-up is the way to go.
upvoted 0 times
...
William
1 month ago
This is a tricky one, but I'd go with C) Report. Liam was left out of that phase, and the question specifically asks which one he didn't participate in.
upvoted 0 times
...
Lillian
1 month ago
I'm leaning towards C) Report. Liam was present for the discussion of the audit findings, but it doesn't mention him being involved in the actual report.
upvoted 0 times
...
Loreta
2 months ago
Hmm, I think the answer is D) Follow-up since Liam didn't get a chance to implement the remediation plan before the audit findings were discussed.
upvoted 0 times
...
Hoa
2 months ago
I’m leaning towards "Prepare" because it seems like Liam jumped into action without a solid plan before the audit.
upvoted 0 times
...
Rebecka
2 months ago
I think it might be the "Follow-up" phase since he didn’t seem to implement any changes after the audit findings.
upvoted 0 times
...
Adelaide
2 months ago
Okay, I think I've got this. Based on the details provided, Liam has gone through the Prepare, Audit, and Report phases, but the Follow-up phase is still missing. I'll need to focus on identifying the specific steps involved in that final phase to answer this correctly.
upvoted 0 times
...
Belen
2 months ago
Hmm, this is a lot of information to process. I'm feeling a bit overwhelmed, to be honest. I think I'll start by re-reading the scenario carefully and making sure I understand the key details before I try to answer the question. That way, I'll be less likely to miss something important.
upvoted 0 times
...
Rebecka
2 months ago
This is a tricky one, but I think I've got a handle on it. Liam has clearly been involved in the Prepare, Audit, and Report phases, so the only one left is the Follow-up phase. I'll need to pay close attention to what that entails in order to answer this question.
upvoted 0 times
...
Talia
3 months ago
The question seems straightforward, but I'm not sure if I should choose B) Audit since Liam was involved in that phase.
upvoted 0 times
...
Vallie
3 months ago
I remember we discussed the audit phases in class, but I’m not entirely sure which one Liam might have skipped.
upvoted 0 times
...
Mari
3 months ago
I recall a practice question where we had to identify missing steps in an audit process. This feels similar, but I can't quite remember the exact details.
upvoted 0 times
...
Arlette
3 months ago
I think he skipped the preparation phase.
upvoted 0 times
...
Raelene
4 months ago
Okay, let me think this through. Based on the details provided, it seems like Liam has gone through the Prepare, Audit, and Report phases, but the Follow-up phase is still missing. I'll need to focus on identifying the key steps in that final phase to answer this correctly.
upvoted 0 times
...
Berry
4 months ago
I'm a bit confused about this question. It seems like there are a lot of details to keep track of, and I'm not sure exactly what the key phases of an audit are. I might need to re-read the scenario a few times to make sure I understand it fully.
upvoted 0 times
Bobbye
3 months ago
I get what you mean! There’s a lot going on in that scenario.
upvoted 0 times
...
...

Save Cancel