CIPT Exam QuestionsBrowse all questions from this exam

CIPT Exam - Question 74


SCENARIO -

Please use the following to answer next question:

EnsureClaim is developing a mobile app platform for managing data used for assessing car accident insurance claims. Individuals use the app to take pictures at the crash site, eliminating the need for a built-in vehicle camera. EnsureClaim uses a third-party hosting provider to store data collected by the app. EnsureClaim customer service employees also receive and review app data before sharing with insurance claim adjusters.

The app collects the following information:

✑ First and last name

✑ Date of birth (DOB)

✑ Mailing address

✑ Email address

✑ Car VIN number

✑ Car model

✑ License plate

✑ Insurance card number

✑ Photo

✑ Vehicle diagnostics

✑ Geolocation

What would be the best way to supervise the third-party systems the EnsureClaim App will share data with?

Show Answer
Correct Answer: B

Conducting a security and privacy review before onboarding new vendors that collect personal data from the app ensures that adequate protections are in place before any data is shared. This proactive approach allows EnsureClaim to identify and address potential security and privacy issues in advance, thereby mitigating risks and ensuring compliance with data protection regulations.

Discussion

1 comment
Sign in to comment
StantsOption: B
Jan 27, 2024

The best way to supervise the third-party systems that the EnsureClaim App will share data with is Option B: Conduct a security and privacy review before onboarding new vendors that collect personal data from the app. This approach ensures that any third-party systems have adequate security and privacy measures in place before any data is shared with them. It allows for potential issues to be identified and addressed before any personal data is put at risk. While all the options listed are important aspects of data management and security, conducting a security and privacy review before onboarding new vendors provides a proactive approach to data protection. So, the answer is Option