Free DSCI DCPLA Actual Exam Questions
Dumps Box (DumpsBox) offers up-to-date practice exam questions for DCPLA certification exam which are developed and validated by DSCI subject domain experts certified in DSCI DCPLA . These practice questions are update regularly as we keep an eye on any recent changes in DCPLA syllabus, and when there is update our team quickly adjusts the questions. This commitment to providing the best quality exam prep material to certification aspirants is what makes DumpsBox.com the best certification exam prep website. On top of that, our strong, yet strictly moderated, community based feedback keeps the content clean and current. Each question has helpful community discussion that provides it extra perspective and introduces helpful resources for better exam preparation. This also saves students from other outdated practice questions or illicit exam dumps that can have adverse affects on career. Browse through our DSCI DCPLA exam questions and pass your exam on first try.
privacy:
I) Data minimization
II) Intrusion prevention system
III) Data scrambling
IV) Data loss prevention
V) Data portability
VI) Data obfuscation
VII) Data encryption
VIII) Data mirroring
In the landmark case _______________ the Honourable Supreme Court of India reaffirmed the status of Right to Privacy as a Fundamental Right under Part III of the constitution.
protection of PI or SPDI of Individuals?
The entire assessment process, from commencement to submission of final report to DSCI must be
completed within 2 weeks.
It’s mandatory for the assessee to provide the pre-requisites to the assessor organization before
commencement of the first phase of assessment.
Organization, conduct external assessment leading to DSCI Privacy certification?
with the assessment outcome.
[Scenario Based Questions]
FILL BLANK
PIS
The company has a well-defined and effectively implemented security policy. As in case of access
control, the security controls vary in different client relationships based on the client requirements
but certain basic or hygiene security practices / controls are implemented organization wide. The
consultants have advised the information security function to realign the company’s security policy,
risk assessment, data classification, etc to include privacy aspects. But the consultants are struggling
to make information security function understand what exact changes need to be made and the
security function itself is unable to figure it out.
(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a
definitive conclusion)
Introduction and Background
XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE
and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves
more than 500 clients across industry verticals — BFSI, Retail, Government, Healthcare, Telecom
among others in Americas, Europe, Asia-Pacific, Middle East and Afric
a. The company provides IT services including application development and maintenance, IT
Infrastructure management, consulting, among others. It also offers IT products mainly for its BFSI
customers.
The company is witnessing phenomenal growth in the BPM services over last few years including
Finance and Accounting including credit card processing, Payroll processing, Customer support, Legal
Process Outsourcing, among others and has rolled out platform based services. Most of the
company’s revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the
company is looking to expand its operations in Europe. India, too has attracted company’s attention
given the phenomenal increase in domestic IT spend esp. by the government through various large
scale IT projects. The company is also very aggressive in the cloud and mobility space, with a strong
focus on delivery of cloud services. When it comes to expanding operations in Europe, company is
facing difficulties in realizing the full potential of the market because of privacy related concerns of
the clients arising from the stringent regulatory requirements based on EU General Data Protection
Regulation (EU GDPR).
To get better access to this market, the company decided to invest in privacy, so that it is able to
provide increased assurance to potential clients in the EU and this will also benefit its US operations
because privacy concerns are also on rise in the US. It will also help company leverage outsourcing
opportunities in the Healthcare sector in the US which would involve protection of sensitive medical
records of the US citizens. The company believes that privacy will also be a key differentiator in the
cloud business going forward. In short, privacy was taken up as a strategic initiative in the company
in early 2011.
Since XYZ had an internal consulting arm, it assigned the responsibility of designing and
implementing an enterprise wide privacy program to the consulting arm. The consulting arm had
very good expertise in information security consulting but had limited expertise in the privacy
domain. The project was to be driven by CIO's office, in close consultation with the Corporate
Information Security and Legal functions.
Can you please guide the information security function to realign company’s security initiatives to
include privacy protection, keeping in mind that the client security requirements would vary across
relationships? (250 to 500 words)
[Scenario Based Questions]
FILL BLANK
IUA and PAT
The company has a very mature enterprise level access control policy to restrict access to
information. There is a single sign-on platform available to access company resources such as email,
intranet, servers, etc. However, the access policy in client relationships varies depending on the
client requirements. In fact, in many cases clients provide access ids to the employees of the
company and manage them. Some clients also put technical controls to limit access to information
such data masking tool, encryption, and anonymizing data, among others. Some clients also record
the data collection process to monitor if the employee of the company does not collect more data
than is required. Taking cue from the best practices implemented by the clients, the company,
through the consultants, thought of realigning its access control policy to include control on data
collection and data usage by the business functions and associated third parties. As a first step, the
consultants advised the company to start monitoring the PI collection, usage and access by business
functions without their knowledge. The IT function was given the responsibility to do the monitoring,
as majority of the information was handled electronically. The analysis showed that many times,
more information than necessary was collected by the some functions, however, no instances of
misuse could be identified. After few days of this exercise, a complaint was registered by a female
company employee in the HR function against a male employee in IT support function. The female
employee accused the male employee of accessing her photographs stored on a shared drive and
posting it on a social networking site.
(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a
definitive conclusion)
Introduction and Background
XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE
and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves
more than 500 clients across industry verticals — BFSI, Retail, Government, Healthcare, Telecom
among others in Americas, Europe, Asia-Pacific, Middle East and Afric
a. The company provides IT services including application development and maintenance, IT
Infrastructure management, consulting, among others. It also offers IT products mainly for its BFSI
customers.
The company is witnessing phenomenal growth in the BPM services over last few years including
Finance and Accounting including credit card processing, Payroll processing, Customer support, Legal
Process Outsourcing, among others and has rolled out platform based services. Most of the
company’s revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the
company is looking to expand its operations in Europe. India, too has attracted company’s attention
given the phenomenal increase in domestic IT spend esp. by the government through various large
scale IT projects. The company is also very aggressive in the cloud and mobility space, with a strong
focus on delivery of cloud services. When it comes to expanding operations in Europe, company is
facing difficulties in realizing the full potential of the market because of privacy related concerns of
the clients arising from the stringent regulatory requirements based on EU General Data Protection
Regulation (EU GDPR).
To get better access to this market, the company decided to invest in privacy, so that it is able to
provide increased assurance to potential clients in the EU and this will also benefit its US operations
because privacy concerns are also on rise in the US. It will also help company leverage outsourcing
opportunities in the Healthcare sector in the US which would involve protection of sensitive medical
records of the US citizens. The company believes that privacy will also be a key differentiator in the
cloud business going forward. In short, privacy was taken up as a strategic initiative in the company
in early 2011.
Since XYZ had an internal consulting arm, it assigned the responsibility of designing and
implementing an enterprise wide privacy program to the consulting arm. The consulting arm had
very good expertise in information security consulting but had limited expertise in the privacy
domain. The project was to be driven by CIO's office, in close consultation with the Corporate
Information Security and Legal functions.
What should the company do to limit data collection and usage and at the same time ensure that
such kinds of incidents don’t reoccur? (250 to 500 words)
[Scenario Based Questions]
FILL BLANK
VPI
As a starting point, the consultants undertook a visibility exercise to understand the type of personal
information (PI) being dealt with within the organization and also by third parties and the scope was
to cover all the client relationships (IT services and BPM both) and functions. They met with the
client relationship and business function owners to collect this dat
a. The consultants did a mapping exercise to identify PI and associated attributes including whether
company directly collects the PI, how it is accessed, transmitted, stored and what are the applicable
regulatory and contractual requirements. Given the enormous scale of the exercise (enterprise
wide), the consultant classified the PI as financial information, health related information, personally
identifiable information, etc. and collected the rest of the attributes against this classification. When
understanding the underlying technology environment, the consultants restricted themselves only to
the technology environment that was under company’s ownership and premises and did not
continue the exercise for client side environment. This was done because relationship owners
seemed reluctant to share such client specific details. Only in 2 relationships, were the relationship
heads proactive to introduce the consultants to the clients and get the requisite information. The
analysis of the environment in these 2 relationships revealed that even though lots of restrictions
were imposed at the company side, the same restrictions were not available at the client side.
Many business functions were also availing services from third party service providers. Though these
functions were aware of the type of PI dealt by third parties, they were not aware of the technology
environment at the third parties. In one odd case, personal information of a company employee was
accidentally leaked by the employee of the third party through the social networking site. The
consultants relied on whatever information was provided by the functions w.r.t. third parties. After
finishing the data collection, the consultant used the information to create information flow maps
highlighting the flow of information across systems deployed at the company premises. This work
helped them have a high level view of PI dealt by the company. The data collection exercise has been
conducted only once by the consultants. The visibility exercise empowered the management to have
a company-wide view of PI and how it flows across the organization. This information was coupled
with the security controls / practices deployed at the relationship or function level to derive the risk
posture of the PI.
(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a
definitive conclusion)
Introduction and Background
XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE
and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves
more than 500 clients across industry verticals — BFSI, Retail, Government, Healthcare, Telecom
among others in Americas, Europe, Asia-Pacific, Middle East and Africa. The company provides IT
services including application development and maintenance, IT Infrastructure management,
consulting, among others. It also offers IT products mainly for its BFSI customers.
The company is witnessing phenomenal growth in the BPM services over last few years including
Finance and Accounting including credit card processing, Payroll processing, Customer support, Legal
Process Outsourcing, among others and has rolled out platform based services. Most of the
company’s revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the
company is looking to expand its operations in Europe. India, too has attracted company’s attention
given the phenomenal increase in domestic IT spend esp. by the government through various large
scale IT projects.
The company is also very aggressive in the cloud and mobility space, with a strong focus on delivery
of cloud services. When it comes to expanding operations in Europe, company is facing difficulties in
realizing the full potential of the market because of privacy related concerns of the clients arising
from the stringent regulatory requirements based on EU General Data Protection Regulation (EU
GDPR).
To get better access to this market, the company decided to invest in privacy, so that it is able to
provide increased assurance to potential clients in the EU and this will also benefit its US operations
because privacy concerns are also on rise in the US. It will also help company leverage outsourcing
opportunities in the Healthcare sector in the US which would involve protection of sensitive medical
records of the US citizens. The company believes that privacy will also be a key differentiator in the
cloud business going forward. In short, privacy was taken up as a strategic initiative in the company
in early 2011.
Since XYZ had an internal consulting arm, it assigned the responsibility of designing and
implementing an enterprise wide privacy program to the consulting arm. The consulting arm had
very good expertise in information security consulting but had limited expertise in the privacy
domain. The project was to be driven by CIO's office, in close consultation with the Corporate
Information Security and Legal functions.
Was the visibility exercise adequately carried out? What gaps did you notice? (250 to 500 words)
[Scenario Based Questions]
FILL BLANK
MIM
The company has a well-defined and tested Information security monitoring and incident
management process in place. The process has been in place since last 10 years and has matured
significantly over a period of time. There is a Security Operations Centre (SOC) to detect security
incidents based on well-defined business rules.
The security incident management is based on ISO 27001 and defines incident types, alert levels,
roles and responsibilities, escalation matrix, among others. The consultants advised company to
realign the existing monitoring and incident management to cater to privacy requirements. The
company consultants sought help of external privacy expert in this regard.
(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a
definitive conclusion)
Introduction and Background
XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE
and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves
more than 500 clients across industry verticals — BFSI, Retail, Government, Healthcare, Telecom
among others in Americas, Europe, Asia-Pacific, Middle East and Afric
a. The company provides IT services including application development and maintenance, IT
Infrastructure management, consulting, among others. It also offers IT products mainly for its BFSI
customers.
The company is witnessing phenomenal growth in the BPM services over last few years including
Finance and Accounting including credit card processing, Payroll processing, Customer support, Legal
Process Outsourcing, among others and has rolled out platform based services. Most of the
company’s revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the
company is looking to expand its operations in Europe. India, too has attracted company’s attention
given the phenomenal increase in domestic IT spend esp. by the government through various large
scale IT projects. The company is also very aggressive in the cloud and mobility space, with a strong
focus on delivery of cloud services. When it comes to expanding operations in Europe, company is
facing difficulties in realizing the full potential of the market because of privacy related concerns of
the clients arising from the stringent regulatory requirements based on EU General Data Protection
Regulation (EU GDPR).
To get better access to this market, the company decided to invest in privacy, so that it is able to
provide increased assurance to potential clients in the EU and this will also benefit its US operations
because privacy concerns are also on rise in the US. It will also help company leverage outsourcing
opportunities in the Healthcare sector in the US which would involve protection of sensitive medical
records of the US citizens. The company believes that privacy will also be a key differentiator in the
cloud business going forward. In short, privacy was taken up as a strategic initiative in the company
in early 2011.
Since XYZ had an internal consulting arm, it assigned the responsibility of designing and
implementing an enterprise wide privacy program to the consulting arm. The consulting arm had
very good expertise in information security consulting but had limited expertise in the privacy
domain. The project was to be driven by CIO's office, in close consultation with the Corporate
Information Security and Legal functions.
If you were the privacy expert advising the company, what steps would you suggest to realign the
existing security monitoring and incident management to address privacy requirements especially
those specific to client relationships? (250 to 500 words)
[Scenario Based Questions]
FILL BLANK
RCI and PCM
Given its global operations, the company is exposed to multiple regulations (privacy related) across
the globe and needs to comply mostly through contracts for client relationships and directly for
business functions. The corporate legal team is responsible for managing the contracts and
understanding, interpreting and translating the legal requirements. There is no formal tracking of
regulations done. The knowledge about regulations mainly comes through interaction with the client
team. In most of the contracts, the clients have simply referred to the applicable legislations without
going any further in terms of their applicability and impact on the company. Since business
expansion is the priority, the contracts have been signed by the company without fully understanding
their applicability and impact. Incidentally, when the privacy initiatives were being rolled out, a
major data breach occurred at one of the healthcare clients located in the US. The US state data
protection legislation required the client to notify the data breach. During investigations, it emerged
that the data breach happened because of some vulnerability in the system owned by the client but
managed by the company and the breach actually happened 5 months back and came to notice now.
The system was used to maintain medical records of the patients. This vulnerability had been earlier
identified by a third party vulnerability assessment of the system and the closure of vulnerability was
assigned to the company. The company had made the requisite changes and informed the client. The
client, however, was of the view that the changes were actually not made by the company and they
therefore violated the terms of contract which stated that – “the company shall deploy appropriate
organizational and technology measures for protection of personal information in compliance with
the XX state data protection legislation.” The company could not produce necessary evidences to
prove that the configuration changes were actually made by it (including when these were made).
(Note: Candidates are requested to make and state assumptions wherever appropriate to reach a
definitive conclusion)
Introduction and Background
XYZ is a major India based IT and Business Process Management (BPM) service provider listed at BSE
and NSE. It has more than 1.5 lakh employees operating in 100 offices across 30 countries. It serves
more than 500 clients across industry verticals — BFSI, Retail, Government, Healthcare, Telecom
among others in Americas, Europe, Asia-Pacific, Middle East and Afric
a. The company provides IT services including application development and maintenance, IT
Infrastructure management, consulting, among others. It also offers IT products mainly for its BFSI
customers.
The company is witnessing phenomenal growth in the BPM services over last few years including
Finance and Accounting including credit card processing, Payroll processing, Customer support, Legal
Process Outsourcing, among others and has rolled out platform based services. Most of the
company’s revenue comes from the US from the BFSI sector. In order to diversify its portfolio, the
company is looking to expand its operations in Europe. India, too has attracted company’s attention
given the phenomenal increase in domestic IT spend esp. by the government through various large
scale IT projects. The company is also very aggressive in the cloud and mobility space, with a strong
focus on delivery of cloud services. When it comes to expanding operations in Europe, company is
facing difficulties in realizing the full potential of the market because of privacy related concerns of
the clients arising from the stringent regulatory requirements based on EU General Data Protection
Regulation (EU GDPR).
To get better access to this market, the company decided to invest in privacy, so that it is able to
provide increased assurance to potential clients in the EU and this will also benefit its US operations
because privacy concerns are also on rise in the US. It will also help company leverage outsourcing
opportunities in the Healthcare sector in the US which would involve protection of sensitive medical
records of the US citizens. The company believes that privacy will also be a key differentiator in the
cloud business going forward. In short, privacy was taken up as a strategic initiative in the company
in early 2011.
Since XYZ had an internal consulting arm, it assigned the responsibility of designing and
implementing an enterprise wide privacy program to the consulting arm. The consulting arm had
very good expertise in information security consulting but had limited expertise in the privacy
domain. The project was to be driven by CIO's office, in close consultation with the Corporate
Information Security and Legal functions.
Why do you think the company failed to defend itself against client accusations? (250 to 500 words)
“The network is unable to restrict unwanted external connections carrying sensitive information.”