TechNuggets Academy
CIPP/US

Free Certified Information Privacy Professional/United States Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$5505 exam domainsLevel Intermediate2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: Introduction to the U.S. Privacy Environment
A company's website states, "We never share your personal information with third parties." In reality, the company sells email addresses to a marketing affiliate in exchange for compensation. How would the FTC most likely characterize this practice under Section 5 of the FTC Act?
The FTC's deception authority applies when a company makes a material representation or omission that is likely to mislead a reasonable consumer. A false claim that data is never shared with third parties, when it in fact is sold, is a textbook material misrepresentation and is enforced as a deceptive practice, not an unfairness claim.
Question 2 of 12 · Domain 2: Limits on Private-sector Collection and Use of Data
A regional bank shares nonpublic personal information (NPI) about its customers with an unaffiliated marketing company so that company can promote its own products to the bank's customers. This sharing does not fall under any joint marketing or other GLBA exception. Under the GLBA Privacy Rule, which BEST describes the bank's obligation before sharing this NPI?
The GLBA Privacy Rule is opt-out based for sharing NPI with nonaffiliated third parties outside a recognized exception: the institution must give a clear and conspicuous notice describing the sharing and a reasonable opportunity/method for the customer to opt out before disclosure occurs.
Question 3 of 12 · Domain 3: Government and Court Access to Private-sector Information
A cloud email provider receives a law enforcement request seeking the contents of emails that have been in storage for more than 180 days, accompanied only by a subpoena and notice to the subscriber, consistent with the literal text of the Stored Communications Act (SCA). Which statement most accurately reflects current practice?
In United States v. Warshak (6th Cir. 2010), the court held that email content carries a reasonable expectation of privacy under the Fourth Amendment, so most major providers now require a warrant supported by probable cause for content regardless of the SCA's statutory 180-day distinction.
Question 4 of 12 · Domain 4: Workplace Privacy
An employer orders a consumer report on a job applicant and, based on its contents, decides not to hire the candidate. Under the FCRA, what must the employer do BEFORE making the final decision?
The FCRA requires a two-step adverse action process for employment: before taking adverse action based on a consumer report, the employer must give the applicant a pre-adverse action notice with a copy of the report and the 'Summary of Your Rights Under the FCRA,' along with a reasonable opportunity to dispute inaccuracies before the final decision is made.
Question 5 of 12 · Domain 5: State Privacy Laws
A California-based e-commerce company's website receives an incoming Global Privacy Control (GPC) signal from a visitor's browser. The company has not posted a 'Do Not Sell or Share My Personal Information' link on its homepage, believing the GPC signal alone satisfies its CCPA/CPRA opt-out obligations. Under the CPRA regulations, is this approach compliant?
Under 11 CCR §7025, businesses must treat a GPC signal as a valid consumer opt-out request for sale/sharing occurring through that browser, but this obligation does not replace the independent requirement to post a 'Do Not Sell or Share' link, since the business may also sell or share personal information through non-browser channels (e.g., offline sources, apps, or other online means not covered by the signal).
Question 6 of 12 · Domain 1: Introduction to the U.S. Privacy Environment
A mobile app developer headquartered in Texas suffers a data breach affecting app users who reside in California, New York, and Illinois. Which of the following BEST describes who has authority to pursue enforcement action against the developer?
U.S. privacy enforcement is multi-layered: the FTC enforces Section 5 against unfair/deceptive practices affecting consumers nationwide, while state attorneys general independently enforce their own state consumer protection/UDAP statutes (and applicable state privacy laws) against companies whose conduct harms their state's residents, regardless of where the company is headquartered.
Question 7 of 12 · Domain 2: Limits on Private-sector Collection and Use of Data
An employer decides not to hire an applicant based in part on a background check report obtained from a consumer reporting agency (CRA). Under the Fair Credit Reporting Act (FCRA), what must the employer do BEFORE finalizing this adverse employment decision?
FCRA requires a two-step adverse action process for employment decisions based on consumer reports: a pre-adverse action disclosure (copy of the report plus the FTC 'Summary of Your Rights Under the FCRA') given before the decision is final, followed by a reasonable waiting period so the applicant can dispute inaccuracies before a final adverse action notice is issued.
Question 8 of 12 · Domain 3: Government and Court Access to Private-sector Information
Which federal law governs law enforcement's real-time interception of the content of a live telephone call?
Title I of ECPA, commonly called the Wiretap Act, governs real-time interception of the content of wire, oral, and electronic communications and requires a heightened 'super-warrant' showing, including necessity and minimization.
Question 9 of 12 · Domain 4: Workplace Privacy
A company monitors employees' work email accounts on the corporate email system without individualized suspicion of wrongdoing. Which legal principle most directly permits this monitoring under federal law?
The Electronic Communications Privacy Act (ECPA) generally prohibits interception of electronic communications, but the business extension exception permits employers to monitor communications on company-provided systems in the ordinary course of business, particularly where employees have been notified of a monitoring policy that diminishes their expectation of privacy.
Question 10 of 12 · Domain 5: State Privacy Laws
A retailer experiences a data breach exposing unencrypted Social Security numbers of customers residing in California, Virginia, and Colorado. The breach resulted from the retailer's failure to implement and maintain reasonable security procedures. Under which state's law can affected consumers bring a private lawsuit directly against the retailer for statutory damages arising from this breach?
The CCPA contains a narrow private right of action (Cal. Civ. Code §1798.150) allowing consumers to sue for statutory damages when unencrypted, non-redacted personal information is breached as a result of a business's failure to implement reasonable security procedures. This is one of the few private rights of action among comprehensive state privacy statutes.
Question 11 of 12 · Domain 1: Introduction to the U.S. Privacy Environment
Which source of U.S. law provides an individual with a private right of action for the tort of "intrusion upon seclusion"?
Intrusion upon seclusion is one of the four privacy torts derived from William Prosser's classification and is recognized under state common law (and adopted by many states via the Restatement (Second) of Torts). It provides individuals a private right of action independent of any statute.
Question 12 of 12 · Domain 2: Limits on Private-sector Collection and Use of Data
An operator of a children's mobile app wants to collect only a child's email address to send occasional in-app notifications, and this information will not be disclosed to third parties or used for behavioral advertising. Under COPPA's limited exception for internal use of contact information, which verifiable parental consent method is specifically designed to satisfy this lower-risk scenario?
COPPA's FTC-approved 'email plus' method allows operators to use a parent's email address for verifiable parental consent when the information collected from the child is used only for internal purposes and not disclosed, provided the operator sends a delayed confirmatory notice to the parent (e.g., via a second email or letter) giving them the opportunity to revoke consent.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

CIPP/US exam — quick answers

How much does the CIPP/US exam cost?

The exam fee is approximately $550 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 5 domains: Introduction to the U.S. Privacy Environment (~20%), Limits on Private-sector Collection and Use of Data (~25%), Government and Court Access to Private-sector Information (~15%), Workplace Privacy (~20%), State Privacy Laws (~20%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Introduction to the U.S. Privacy Environment →Limits on Private-sector Collection and Use of Data →Government and Court Access to Private-sector Information →Workplace Privacy →State Privacy Laws →