内容を確かめてから購入したいという方のために、Tech4ExamはCIPP-A練習問題の無料サンプルを提供しています。IAPP Certified Information Privacy Professional/Asia (CIPP/A)向け92問の問題集の一部を実際にご覧いただけるので、品質に納得したうえでお選びいただけます。
IAPP CIPP-A 試験概要:
| 認定ベンダー: | IAPP(国際プライバシー専門家協会) |
|---|---|
| 試験名: | Certified Information Privacy Professional/Asia (CIPP/A) 試験 |
| 試験番号: | CIPP-A |
| 出題数: | 90問(採点対象75問+非採点対象15問) |
| 認定の有効期間: | 2年間(毎年の資格維持手続きが必要) |
| 合格点: | 300点(スケールドスコア、範囲100~500点) |
| 受験料: | 550米ドル(再受験:375米ドル) |
| 対応言語: | English |
| 関連資格: | CIPP/E CIPT CIPM CIPP/US CIPP/C |
| 試験時間: | 150 分 |
| 試験形式: | 多肢選択式, 事例設問形式 |
| 推奨トレーニング: | CIPP/A 知識体系ガイド IAPP公式 CIPP/A トレーニングプログラム |
| 受験申し込み: | Pearson VUE 試験予約サイト IAPP公式オンラインストア |
| サンプル問題: | DOWNLOAD DEMO |
| 受験方法: | Pearson VUE OnVueによるオンライン監督付き受験、または世界6,000か所以上に設置されたPearson VUE試験会場での受験 |
| 前提条件: | 正式な受験資格要件はなし。プライバシーに関する基礎知識およびアジア地域の関連法規の理解が推奨される |
| 公式シラバスのURL: | https://iapp.org/certify/cippa/ |
IAPP CIPP-A 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: 共通事項と地域別の制度的枠組み | 10~15% | - 国境を越えたデータ移転 - インシデント対応および漏洩時の通知義務 - APEC CBPR、PIPL、APPI、PIPA - コンプライアンスとガバナンス体制 |
| トピック 2: プライバシーの基礎知識 | 6~12% | - 現代のプライバシー原則
- 個人情報の定義
|
| トピック 3: シンガポールのプライバシー関連法規と実務 | 20~25% | - 主な義務事項
- 法執行体制と規制当局 |
| トピック 4: 香港のプライバシー関連法規と実務 | 20~25% | - 個人データ(プライバシー)条例(PDPO)第486章 - データ主体の権利 - データ保護原則 - 個人データ保護コミッショナー事務局 |
| トピック 5: インドのプライバシー関連法規と実務 | 20~25% | - データ取扱事業者の義務 - インドデータ保護委員会 - 2023年デジタル個人データ保護法(DPDP法) - 2000年情報技術法 |
CIPP-Aに挑戦する方へ – よくある質問まとめ
CIPP-A試験はIAPP Certified Information Privacy Professional/Asia (CIPP/A)の公式認定試験で、合格するとCertified Information Privacy Professional/Asia (CIPP/A)の認定を取得できます。この認定はスペシャリストレベルに位置づけられています。関連する認定には、CIPP/US、CIPP/E、CIPP/C、CIPM、CIPTなどがあります。Tech4Examでは、この試験の出題傾向に沿った92問の練習問題をご用意しています。
CIPP-A試験の出題数は90問(採点対象75問+非採点対象15問)、制限時間は150 分です。出題数に対して使える時間は限られるため、1問あたりにかけられるペースを意識しながら解き進める必要があります。難問に時間を使いすぎず、確実に答えられる問題から拾っていく時間配分が得点を安定させる鍵になります。Tech4Examのテストエンジンで制限時間つきの模擬試験を繰り返し、本番と同じリズムで解く感覚を身につけておくことをおすすめします。
CIPP-A試験の合格ラインは300点(スケールドスコア、範囲100~500点)、受験料は550米ドル(再受験:375米ドル)です。不合格になった場合、再受験には改めて全額の受験料が必要になるため、一度の受験で合格ラインをクリアできる準備が費用面でも重要です。Tech4Examの92問の練習問題で繰り返し自己採点を行い、安定して合格点を上回れることを確認してから本番に臨むと安心です。
受験条件は見直される場合があります。お申し込みの前に、IAPPの公式ページで最新の情報をご確認ください。
CIPP-A試験は、以下の公式窓口からお申し込みいただけます。
試験方式については、Pearson VUE OnVueによるオンライン監督付き受験、または世界6,000か所以上に設置されたPearson VUE試験会場での受験
IAPPが推奨する公式トレーニングには、以下のようなものがあります。
公式トレーニングで知識を体系的に学んだうえで、Tech4Examの92問の練習問題に取り組めば、理解度を試験形式で確かめながら弱点を補強できます。
はい、Tech4ExamではCIPP-A練習問題の無料サンプルをご用意しています。92問の問題集の一部を事前にご確認いただけるので、内容や品質に納得してからご購入いただけます。ご購入後は365日間の無料アップデートが付き、期間終了後も50%割引で更新を継続いただけるため、常に最新の出題内容に沿って学習できます。
Tech4Examには返金保証があります。ご購入後60日以内に対応する試験を受験して不合格だった場合、全額返金をお申し込みいただけます。ただし、購入後3日以内の受験による不合格、ダウンロード後に実際の試験を受験しなかった場合、無料資料や有効期限切れのご注文は対象外となり、受験者の氏名はお支払い者の氏名と一致している必要があります。お申し込みの際は、受験票のコピーと公式のScore ReportのPDFを試験後2日以内にご提出ください。提出後7日以内に手続きが完了します。返金の代わりに、同等の試験資料2点を無料でお受け取りいただき、お手持ちの製品の更新サービスをそのまま継続する選択も可能です。納品は即時ダウンロード方式で、お支払い完了後1分以内にメールでお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールするパソコンの台数に制限はありません。
CIPP-A試験の出題範囲は5の領域に分かれています。主な領域として、「シンガポールのプライバシー関連法規と実務(20~25%)」、「共通事項と地域別の制度的枠組み(10~15%)」、「インドのプライバシー関連法規と実務(20~25%)」などが挙げられます。各領域の詳しい内訳については、このページ上部に掲載している試験シラバスをご確認ください。
IAPP Certified Information Privacy Professional/Asia (CIPP/A) 認定 CIPP-A 試験問題:
問題 #1
How is the transparency of the complaint process treated in both Hong Kong and Singapore?
A. The Hong Kong and Singapore commissioners are obliged to start investigations when receiving a complaint and inform the respondent of the personal details of the complainant.
B. Investigations into complaints in Hong Kong and Singapore are open to the public.
C. A complainant must alert all individuals potentially affected by the complaint.
D. The Hong Kong and Singapore Commissioner may require the complainants to identify themselves before carrying out any investigation into the complaint.
問題 #2
SCENARIO - Please use the following to answer the next QUESTION:
Zoe is the new Compliance Manager for the Star Hotel Group, which has five hotels across Hong Kong and Chin a. On her first day, she does an inspection of the largest property, StarOne. She starts with the hotel reception desk. Zoe sees the front desk assistant logging in to a database as he is checking in a guest. The hotel manager, Bernard, tells her that all guest data, including passport numbers, credit card numbers, home address, mobile number and other information associated with a guest's stay is held in a database. Bernard tells her not to worry about the security of the database because it is operated for Star Hotels by a local service provider called HackProof, who therefore are responsible for all the guest data.
Zoe notices what looks like a CCTV camera in the corner of the reception area. Bernard says they record all activity in the lobby. In fact, last Tuesday he had received a data access request from a lawyer requesting a copy of footage of all lobby activity for the preceding month. The lawyer's covering letter said that his client has never visited the hotel herself, but is investigating whether her husband has been doing so without her knowledge.
Zoe and Bernard head up to the hotel spa. The spa is independently owned by a company called Relax Ltd. Bernard explains that Relax Ltd is a small company and, as they don't have their own database, they transfer data about the spa guests to StarOne staff so that they can upload the data into the HackProof system. Relax Ltd staff can then login and review their guest data as needed.
Zoe asks more about the HackProof system. Bernard tells her that the server for the Hong Kong hotels is in Hong Kong, but there is a server in Shenzhen that has a copy of all the Hong Kong hotel data and supports the properties in China. The data is in China for back up purposes and also is accessible by staff in the China hotels so they can better service guests who visit their hotels in both territories.
How should Bernard respond to the lawyer's request for the CCTV footage?
A. Provide a copy of the footage to the lawyer under the exemption for legal professional privilege.
B. Decline to turn over the footage as there is no basis for it to be disclosed under the exemption for prevention or detection of crime.
C. Decline to turn over the footage as it is not a valid data access request.
D. Provide a copy of the footage within 40 days as it is a data access request.
問題 #3
Which personal data element is NOT considered a special category of data under the General Data Protection Regulation (GDPR)?
A. Physical or mental health data.
B. Political opinions.
C. Financial information.
D. Race or ethnic origin.
問題 #4
In what way are Hong Kong citizens protected from direct marketing in ways that India and Singapore citizens are not?
A. Subscribers must have explicitly indicated that they did not object to their data being collected and used for marketing purposes.
B. Subscribers can opt out of the use of their data for marketing purposes after collection by withdrawing consent.
C. Data subjects are protected from the secondary use of personal data for marketing purposes.
D. Data subjects must be notified on a website if their data is being used for marketing purposes.
問題 #5
SCENARIO - Please use the following to answer the next QUESTION:
Zoe is the new Compliance Manager for the Star Hotel Group, which has five hotels across Hong Kong and Chin a. On her first day, she does an inspection of the largest property, StarOne. She starts with the hotel reception desk. Zoe sees the front desk assistant logging in to a database as he is checking in a guest. The hotel manager, Bernard, tells her that all guest data, including passport numbers, credit card numbers, home address, mobile number and other information associated with a guest's stay is held in a database. Bernard tells her not to worry about the security of the database because it is operated for Star Hotels by a local service provider called HackProof, who therefore are responsible for all the guest data.
Zoe notices what looks like a CCTV camera in the corner of the reception area. Bernard says they record all activity in the lobby. In fact, last Tuesday he had received a data access request from a lawyer requesting a copy of footage of all lobby activity for the preceding month. The lawyer's covering letter said that his client has never visited the hotel herself, but is investigating whether her husband has been doing so without her knowledge.
Zoe and Bernard head up to the hotel spa. The spa is independently owned by a company called Relax Ltd. Bernard explains that Relax Ltd is a small company and, as they don't have their own database, they transfer data about the spa guests to StarOne staff so that they can upload the data into the HackProof system. Relax Ltd staff can then login and review their guest data as needed.
Zoe asks more about the HackProof system. Bernard tells her that the server for the Hong Kong hotels is in Hong Kong, but there is a server in Shenzhen that has a copy of all the Hong Kong hotel data and supports the properties in China. The data is in China for back up purposes and also is accessible by staff in the China hotels so they can better service guests who visit their hotels in both territories.
HackProof reports to Zoe that a copy of the entire guest database has been exfiltrated by a hacker. What is Zoe's best course of action?
A. Zoe does not need to do anything as there is no mandatory breach notification requirement in Hong Kong.
B. Zoe must immediately notify all guests, the police and the Privacy Commissioner of the breach.
C. Zoe should consider if there is a real risk of harm to the guests and take appropriate action based on her assessment.
D. Zoe must report the breach to the Privacy Commissioner and make an action plan together with the Commissioner.
解説:
| 問題 #1 正解: D | 問題 #2 正解: B | 問題 #3 正解: A | 問題 #4 正解: A | 問題 #5 正解: C |

弊社は製品に自信を持っており、面倒な製品を提供していません。


-Yamashita

