ISO 27001/27701 - Integrated Information Security & Privacy Lead Implementer Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A multinational corporation, operating under GDPR and aiming for ISO 27001 and ISO 27701 certification, receives a valid data subject access request that includes a request for erasure of their personal data. The organization’s current data management practices involve several interconnected systems, including a primary CRM, a data warehouse for analytics, and various operational logs. The privacy team has identified that the data warehouse contains aggregated and anonymized data derived from the CRM, but also retains pseudonymized versions of the original data for historical analysis. Operational logs also contain personal identifiers for audit purposes. Which of the following integrated management system actions would most effectively address the data subject\'s right to erasure across all relevant data stores, ensuring demonstrable compliance with both ISO 27001 and ISO 27701 principles?

Implementing a centralized data catalog with automated data lineage tracking and a robust data disposal workflow that can purge pseudonymized and identified personal data from all identified repositories, including logs and derived datasets, based on a unique data subject identifier.
Updating the CRM system’s access control policies to restrict access to personal data for analytical purposes and relying on the anonymization process in the data warehouse to fulfill erasure requests for historical data.
Developing a new data retention policy that mandates the deletion of all personal data from operational logs after six months and instructing the data warehouse team to manually review and delete any remaining identifiable data during their quarterly maintenance cycle.
Enhancing the data subject access request portal to include a disclaimer stating that erasure requests cannot be fulfilled for data used in aggregated analytics or historical logging due to technical limitations.

About the ISO 27001/27701 - Integrated Information Security & Privacy Lead Implementer Certification

These free practice questions are designed to help you assess your readiness for the ISO 27001/27701 - Integrated Information Security & Privacy Lead Implementer exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.