Guaranteed Success in Information Privacy Technologist CIPT Exam Dumps [Q150-Q171]

Share

Guaranteed Success in Information Privacy Technologist CIPT Exam Dumps

IAPP CIPT Daily Practice Exam New 2026 Updated 258 Questions


Conclusion

Data privacy is an issue that affects many companies, and professionals in the industry are in high demand. It gets better for specialists if they have the CIPT certification from IAPP, which shows their skills in the industry. Candidates studying for the CIPT test should use the available courses and guides to ensure they pass the actual exam and get the desired certificate.


The Certified Information Privacy Technologist (CIPT) certification is a globally recognized credential that demonstrates a professional's knowledge and skills in the field of privacy and data protection. It is designed for technology professionals who work with personal data or who are responsible for ensuring compliance with privacy laws and regulations. The CIPT certification is issued by the International Association of Privacy Professionals (IAPP), the world's largest association of privacy professionals.


The CIPT certification exam covers the essential principles and practices of privacy and data protection, including privacy laws and regulations, data protection strategies, privacy by design, and data breach management. CIPT exam is designed to test a candidate's understanding of the key concepts and principles of privacy and data protection, as well as their ability to apply these principles to real-world scenarios. CIPT exam consists of 90 multiple-choice questions and must be completed within two hours.

 

NEW QUESTION # 150
In order to prevent others from identifying an individual within a data set, privacy engineers use a cryptographically-secure hashing algorithm. Use of hashes in this way illustrates the privacy tactic known as what?

  • A. Stripping.
  • B. Isolation.
  • C. Obfuscation.
  • D. Perturbation.

Answer: C


NEW QUESTION # 151
SCENARIO
Please use the following to answer the next question:
Chuck, a compliance auditor for a consulting firm focusing on healthcare clients, was required to travel to the client's office to perform an onsite review of the client's operations. He rented a car from Finley Motors upon arrival at the airport as so he could commute to and from the client's office. The car rental agreement was electronically signed by Chuck and included his name, address, driver's license, make/model of the car, billing rate, and additional details describing the rental transaction. On the second night, Chuck was caught by a red light camera not stopping at an intersection on his way to dinner. Chuck returned the car back to the car rental agency at the end week without mentioning the infraction and Finley Motors emailed a copy of the final receipt to the address on file.
Local law enforcement later reviewed the red light camera footage. As Finley Motors is the registered owner of the car, a notice was sent to them indicating the infraction and fine incurred. This notice included the license plate number, occurrence date and time, a photograph of the driver, and a web portal link to a video clip of the violation for further review. Finley Motors, however, was not responsible for the violation as they were not driving the car at the time and transferred the incident to AMP Payment Resources for further review. AMP Payment Resources identified Chuck as the driver based on the rental agreement he signed when picking up the car and then contacted Chuck directly through a written letter regarding the infraction to collect the fine.
After reviewing the incident through the AMP Payment Resources' web portal, Chuck paid the fine using his personal credit card. Two weeks later, Finley Motors sent Chuck an email promotion offering 10% off a future rental.
What is the most secure method Finley Motors should use to transmit Chuck's information to AMP Payment Resources?

  • A. Cloud file transfer services.
  • B. Transport Layer Security (TLS).
  • C. HyperText Transfer Protocol (HTTP).
  • D. Certificate Authority (CA).

Answer: B

Explanation:
TLS is a cryptographic protocol that provides secure communication over a network. It can help protect against eavesdropping and tampering by encrypting data in transit. Cloud file transfer services (option A) can also provide secure transmission of data but their security depends on the specific service used. Certificate Authority (CA) (option B) is not a method for transmitting data but rather a trusted third party that issues digital certificates used for authentication. HyperText Transfer Protocol (HTTP) (option C) is not a secure method for transmitting sensitive data as it does not provide encryption.


NEW QUESTION # 152
A credit card with the last few numbers visible is an example of what?

  • A. Sighting controls.
  • B. Synthetic data
  • C. Masking data
  • D. Partial encryption

Answer: C

Explanation:
Masking data involves obscuring certain parts of data to protect sensitive information while allowing some level of visibility. In the case of a credit card, masking typically involves showing only the last few digits while hiding the rest, which is a common practice to protect the full card number from unauthorized access.
This method helps in balancing the need for data utility with the requirement for data protection.


NEW QUESTION # 153
SCENARIO - Please use the following to answer the next question:
You have just been hired by Ancillary.com, a seller of accessories for everything under the sun. including waterproof stickers for pool floats and decorative bands and cases for sunglasses. The company sells cell phone cases, e-cigarette cases, wine spouts, hanging air fresheners for homes and automobiles, book ends, kitchen implements, visors and shields for computer screens, passport holders, gardening tools and lawn ornaments, and catalogs full of health and beauty products. The list seems endless. As the CEO likes to say, Ancillary offers, without doubt, the widest assortment of low-price consumer products from a single company anywhere.
Ancillary s operations are similarly diverse. The company originated with a team of sales consultants selling home and beauty products at small parties in the homes of customers, and this base business is still thriving.
However, the company now sells online through retail sites designated for industries and demographics, sites such as "My Cool Ride11 for automobile-related products or "Zoomer" for gear aimed toward young adults.
The company organization includes a plethora of divisions, units and outrigger operations, as Ancillary has been built along a decentered model rewarding individual initiative and flexibility, while also acquiring key assets. The retail sites seem to all function differently, and you wonder about their compliance with regulations and industry standards. Providing tech support to these sites is also a challenge, partly due to a variety of logins and authentication protocols.
You have been asked to lead three important new projects at Ancillary:
The first is the personal data management and security component of a multi-faceted initiative to unify the company s culture. For this project, you are considering using a series of third-party servers to provide company data and approved applications to employees.
The second project involves providing point of sales technology for the home sales force, allowing them to move beyond paper checks and manual credit card imprinting.
Finally, you are charged with developing privacy protections for a single web store housing all the company s product lines as well as products from affiliates. This new omnibus site will be known, aptly, as "Under the Sun." The Director of Marketing wants the site not only to sell Ancillary s products, but to link to additional products from other retailers through paid advertisements. You need to brief the executive team of security concerns posed by this approach.
Which should be used to allow the home sales force to accept payments using smartphones?

  • A. Radio Frequency Identification.
  • B. Field transfer protocol.
  • C. Cross-current translation.
  • D. Near-field communication.

Answer: D


NEW QUESTION # 154
Machine-learning based solutions present a privacy risk because?

  • A. Machine-learning solutions introduce more vulnerabilities than other software.
  • B. The decision-making process used by the solution is not documented.
  • C. Training data used during the training phase is compromised.
  • D. The solution may contain inherent bias from the developers.

Answer: C

Explanation:
Machine-learning solutions present a privacy risk primarily because the training data used during the training phase may contain sensitive information. If this data is compromised, it can lead to privacy breaches.
Machine-learning models can also inadvertently memorize and reproduce sensitive data from the training set.
Reference:IAPP CIPT Study Guide, "Privacy Risks in Machine Learning," which discusses the significance of ensuring the security and privacy of training data.


NEW QUESTION # 155
SCENARIO - Please use the following to answer the next question:
Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them.
SCENARIO - Please use the following to answer the next question:
Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them.
You also recall a recent visit to the Records Storage Section, often termed :The Dungeon" in the basement of the old hospital next to the modern facility, where you noticed a multitude of paper records. Some of these were in crates marked by years, medical condition or alphabetically by patient name, while others were in undifferentiated bundles on shelves and on the floor. The back shelves of the section housed data tapes and old hard drives that were often unlabeled but appeared to be years old. On your way out of the dungeon, you noticed just ahead of you a small man in a lab coat who you did not recognize. He carried a batch of folders under his arm, apparently records he had removed from storage.
Which regulation most likely applies to the data stored by Berry Country Regional Medical Center?

  • A. Personal Information Protection and Electronic Documents Act.
  • B. The Health Records Act 2001.
  • C. Health Insurance Portability and Accountability Act.
  • D. The European Union Directive 95/46/EC.

Answer: C


NEW QUESTION # 156
To comply with the Sarbanes-Oxley Act (SOX), public companies in the United States are required to annually report on the effectiveness of the auditing controls of their financial reporting systems. These controls must be implemented to prevent unauthorized use, disclosure, modification, and damage or loss of financial data.
Why do these controls ensure both the privacy and security of data?

  • A. Disclosure of data is an aspect of privacy; unauthorized use, modification, and damage or loss of data are aspects of security.
  • B. Unauthorized use of data is an aspect of privacy; disclosure, modification, and damage or loss of data are aspects of security.
  • C. Modification of data is an aspect of privacy; unauthorized use, disclosure, and damage or loss of data are aspects of security.
  • D. Damage or loss of data are aspects of privacy; disclosure, unauthorized use, and modification of data are aspects of privacy.

Answer: A


NEW QUESTION # 157
Granting data subjects the right to have data corrected, amended, or deleted describes?

  • A. A security safeguard.
  • B. Accountability.
  • C. Individual participation.
  • D. Use limitation.

Answer: A


NEW QUESTION # 158
A privacy engineer reviews a newly developed on-line registration page on a company's website. The purpose of the page is to enable corporate customers to submit a returns / refund request for physical goods. The page displays the following data capture fields: company name, account reference, company address, contact name, email address, contact phone number, product name, quantity, issue description and company bank account details.
After her review, the privacy engineer recommends setting certain capture fields as "non-mandatory". Setting which of the following fields as "non-mandatory" would be the best example of the principle of data minimization?

  • A. The company address and name.
  • B. The company bank account detail field.
  • C. The contact phone number field.
  • D. The contact name and email address.

Answer: B

Explanation:
The principle of data minimization dictates that only the minimum necessary personal data should be collected for a given purpose. In the context of an online registration page for returns or refunds, setting the company bank account detail field as non-mandatory best exemplifies data minimization. This is because, typically, bank account details are highly sensitive and not immediately necessary for processing a return or refund request. Instead, these details could be collected later in the process when the refund is being processed. Collecting only essential information up front reduces the risk of data exposure and aligns with privacy best practices, as outlined in frameworks such as GDPR and supported by IAPP guidance on data minimization.


NEW QUESTION # 159
SCENARIO
You have just been hired by Ancillary.com, a seller of accessories for everything under the sun, including waterproof stickers for pool floats and decorative bands and cases for sunglasses. The company sells cell phone cases, e-cigarette cases, wine spouts, hanging air fresheners for homes and automobiles, book ends, kitchen implements, visors and shields for computer screens, passport holders, gardening tools and lawn ornaments, and catalogs full of health and beauty products. The list seems endless. As the CEO likes to say, Ancillary offers, without doubt, the widest assortment of low-price consumer products from a single company anywhere.
Ancillary's operations are similarly diverse. The company originated with a team of sales consultants selling home and beauty products at small parties in the homes of customers, and this base business is still thriving. However, the company now sells online through retail sites designated for industries and demographics, sites such as "My Cool Ride" for automobile-related products or "Zoomer" for gear aimed toward young adults. The company organization includes a plethora of divisions, units and outrigger operations, as Ancillary has been built along a decentered model rewarding individual initiative and flexibility, while also acquiring key assets. The retail sites seem to all function differently, and you wonder about their compliance with regulations and industry standards. Providing tech support to these sites is also a challenge, partly due to a variety of logins and authentication protocols.
You have been asked to lead three important new projects at Ancillary:
The first is the personal data management and security component of a multi-faceted initiative to unify the company's culture. For this project, you are considering using a series of third- party servers to provide company data and approved applications to employees.
The second project involves providing point of sales technology for the home sales force, allowing them to move beyond paper checks and manual credit card imprinting.
Finally, you are charged with developing privacy protections for a single web store housing all the company's product lines as well as products from affiliates. This new omnibus site will be known, aptly, as "Under the Sun." The Director of Marketing wants the site not only to sell Ancillary's products, but to link to additional products from other retailers through paid advertisements. You need to brief the executive team of security concerns posed by this approach.
If you are asked to advise on privacy concerns regarding paid advertisements, which is the most important aspect to cover?

  • A. Latent keys that trigger malware when an advertisement is selected.
  • B. Sensitive information from Structured Query Language (SQL) commands that may be exposed.
  • C. Unseen web beacons that combine information on multiple users.
  • D. Personal information collected by cookies linked to the advertising network.

Answer: D


NEW QUESTION # 160
Which of the following findings during a code review is most likely to suggest a privacy vulnerability?

  • A. Conditional logic based on device language settings.
  • B. Extensive use of inheritance in class structures.
  • C. Comments in the code referencing internal documentation.
  • D. Hardcoded test users with real email addresses.

Answer: D

Explanation:
CIPT emphasizes that using real personal data in development or test environments is a direct privacy risk because:
* Test environments often lack the same security controls
* Personal data becomes exposed unnecessarily
* Violates data minimization and purpose limitation
* Increases risk of accidental disclosure or breach
Hardcoded test users with real email addresses is a red flag, indicating:
* Personal data improperly stored in source code
* Limited ability to delete or manage the data
* Exposure to developers, contractors, or repositories
* Increased breach and compliance risk
This aligns with:
* CIPT principles for secure development
* Privacy-by-design rules prohibiting real data in dev/test
* ISO/IEC 29134 PIA risk detection
* NIST SP 800-53 control failures (MP, SC, AC families)
Why other options are not privacy vulnerabilities:
* A: Inheritance structure is an engineering practice, not a privacy risk.
* C: Language settings are benign preference data.
* D: Comments are not a privacy vulnerability (unless they contain sensitive data).


NEW QUESTION # 161
Many modern vehicles incorporate technologies that increase the convenience of drivers, but collect information about driver behavior in order to Implement this. What should vehicle manufacturers prioritize to ensure enhanced privacy protection for drivers?

  • A. Obtain affirmative consent for processing of sensitive data about the driver.
  • B. Share the sensitive data collected about driver behavior with the driver.
  • C. Derive implicit consent for the processing of sensitive data by the continued use of the vehicle.
  • D. Provide easy to read, in-vehicle instructions about how to use the technology.

Answer: A

Explanation:
vehicle manufacturers should prioritize obtaining affirmative consent for processing sensitive data about drivers in order to ensure enhanced privacy protection. Affirmative consent involves obtaining explicit agreement from individuals before collecting or processing their personal data.


NEW QUESTION # 162
Which of the following is an example of the privacy risks associated with the Internet of Things (loT)?

  • A. A water district fines an individual after a meter reading reveals excess water use during drought conditions.
  • B. A website stores a cookie on a user's hard drive so the website can recognize the user on subsequent visits.
  • C. An insurance company raises a person's rates based on driving habits gathered from a connected car.
  • D. A group of hackers infiltrate a power grid and cause a major blackout.

Answer: C

Explanation:
The Internet of Things (IoT) introduces various privacy risks due to the interconnected nature of devices and the large amount of personal data they collect and transmit. Here's a detailed explanation:
* Data Collection and Usage: IoT devices collect extensive data about individuals' behaviors and habits.
For instance, connected cars can gather data on driving patterns, locations, speeds, and other personal details.
* Privacy Implications: When this data is accessed or shared without proper consent or transparency, it can lead to privacy violations. An insurance company using driving data from a connected car to adjust a person's rates exemplifies this risk, as it directly impacts the individual based on potentially sensitive data.
* Surveillance and Profiling: IoT devices can enable continuous surveillance and detailed profiling of individuals, leading to concerns about autonomy and control over personal information.
* Regulatory Considerations: Regulatory frameworks like GDPR emphasize the need for data minimization, purpose limitation, and informed consent, which can be challenging to implement effectively in IoT ecosystems.
Reference: The IAPP Information Privacy Technologist documentation discusses privacy risks associated with IoT, highlighting issues such as data collection, consent, and the potential for misuse of personal information.


NEW QUESTION # 163
Which of these activities is NOT generally part of the responsibilities of a privacy engineer within an organization?

  • A. Creating a culture of privacy by implementing safeguards into the development cycle.
  • B. Translating privacy requirements into the engineering lifecycle.
  • C. Reviewing design documents and acting as a privacy subject matter advisor for development teams.
  • D. Performing independent assessments to review and certify their organization's compliance with privacy laws.

Answer: D

Explanation:
CIPT defines the role of a privacy engineer as operational and technical, focused on:
* Embedding privacy into system design
* Translating legal/privacy requirements into code-level requirements
* Advising development teams
* Implementing privacy-by-design controls
* Supporting risk assessments (PIA, DPIA)
* Ensuring systems support user rights and data governance
They are not responsible for:
# Independent compliance certifications or audits.
Independent assessments must be performed by:
* Internal Audit
* Compliance departments
* External assessors
* Third-party auditors (e.g., SOC 2, ISO 27701 assessments)
This separation ensures objectivity and avoids conflicts of interest - a key governance principle taught in CIPT.
Why other options are part of privacy engineering responsibilities:
* A: Core function - translating requirements into technical design.
* B: Privacy culture is strengthened through engineering safeguards.
* C: Reviewing designs is a standard privacy engineer duty.


NEW QUESTION # 164
Which of the following is NOT a workplace surveillance best practice?

  • A. Check local privacy laws before putting surveillance in place.
  • B. Once surveillance data has been gathered, limit exposure of the content.
  • C. Ensure the minimal amount of surveillance is performed to meet the objective.
  • D. Ensure surveillance is discreet so employees do not alter their behavior.

Answer: D


NEW QUESTION # 165
What is the best way to protect privacy on a geographic information system?

  • A. Using a firewall.
  • B. Using a wireless encryption protocol.
  • C. Limiting the data provided to the system.
  • D. Scrambling location information.

Answer: C

Explanation:
Explanation/Reference: https://www.researchgate.net/
publication/2873114_Protecting_Personal_Privacy_in_Using_Geographic_Information_Systems


NEW QUESTION # 166
A healthcare provider would like to data mine information for research purposes however the Chief Privacy Officer is concerned medical data of individuals may be disclosed overcome the concern, which is the preferred technique for protecting such data while still allowing for analysis?

  • A. Access Control
  • B. Isolation
  • C. Encryption
  • D. Perturbation

Answer: D

Explanation:
perturbation would be a preferred technique for protecting medical data while still allowing for analysis. Perturbation involves adding noise or randomness to data in order to preserve privacy while still allowing for statistical analysis.


NEW QUESTION # 167
A valid argument against data minimization is that it?

  • A. Can limit business opportunities.
  • B. Decreases the speed of data transfers.
  • C. Can have an adverse effect on data quality.
  • D. Increases the chance that someone can be identified from data.

Answer: A

Explanation:
A valid argument against data minimization is that it can limit business opportunities23. Data minimization refers to limiting the collection, storage, and processing of personal information to only what is strictly necessary for business operations3. While this practice can help protect privacy and security, it can also restrict the potential uses and benefits of data for innovation, research, marketing, analytics etc.23. The other options are not valid arguments against data minimization, but rather arguments in favor of it23.
https://www.manageengine.com/data-security/what-is/data-minimization.html


NEW QUESTION # 168
SCENARIO
Wesley Energy has finally made its move, acquiring the venerable oil and gas exploration firm Lancelot from its long-time owner David Wilson. As a member of the transition team, you have come to realize that Wilson's quirky nature affected even Lancelot's data practices, which are maddeningly inconsistent. "The old man hired and fired IT people like he was changing his necktie," one of Wilson's seasoned lieutenants tells you, as you identify the traces of initiatives left half complete.
For instance, while some proprietary data and personal information on clients and employees is encrypted, other sensitive information, including health information from surveillance testing of employees for toxic exposures, remains unencrypted, particularly when included within longer records with less-sensitive dat a. You also find that data is scattered across applications, servers and facilities in a manner that at first glance seems almost random.
Among your preliminary findings of the condition of data at Lancelot are the following:
Cloud technology is supplied by vendors around the world, including firms that you have not heard of. You are told by a former Lancelot employee that these vendors operate with divergent security requirements and protocols.
The company's proprietary recovery process for shale oil is stored on servers among a variety of less-sensitive information that can be accessed not only by scientists, but by personnel of all types at most company locations.
DES is the strongest encryption algorithm currently used for any file.
Several company facilities lack physical security controls, beyond visitor check-in, which familiar vendors often bypass.
Fixing all of this will take work, but first you need to grasp the scope of the mess and formulate a plan of action to address it.
Which procedure should be employed to identify the types and locations of data held by Wesley Energy?

  • A. Data inventory.
  • B. Privacy audit.
  • C. Data classification.
  • D. Log collection

Answer: A

Explanation:
To identify the types and locations of data held by Wesley Energy, a data inventory should be employed. A data inventory involves creating a comprehensive record of all the data held by an organization, including information about its type and location.


NEW QUESTION # 169
SCENARIO
Tom looked forward to starting his new position with a U.S -based automobile leasing company (New Company), now operating in 32 states. New Company was recently formed through the merger of two prominent players, one from the eastern region (East Company) and one from the western region (West Company). Tom, a Certified Information Privacy Technologist (CIPT), is New Company's first Information Privacy and Security Officer. He met today with Dick from East Company, and Harry, from West Company.
Dick and Harry are veteran senior information privacy and security professionals at their respective companies, and continue to lead the east and west divisions of New Company. The purpose of the meeting was to conduct a SWOT (strengths/weaknesses/opportunities/threats) analysis for New Company. Their SWOT analysis conclusions are summarized below.
Dick was enthusiastic about an opportunity for the New Company to reduce costs and increase computing power and flexibility through cloud services. East Company had been contemplating moving to the cloud, but West Company already had a vendor that was providing it with software-as-a-service (SaaS). Dick was looking forward to extending this service to the eastern region. Harry noted that this was a threat as well, because West Company had to rely on the third party to protect its data.
Tom mentioned that neither of the legacy companies had sufficient data storage space to meet the projected growth of New Company, which he saw as a weakness. Tom stated that one of the team's first projects would be to construct a consolidated New Company data warehouse. Tom would personally lead this project and would be held accountable if information was modified during transmission to or during storage in the new data warehouse.
Tom, Dick and Harry agreed that employee network access could be considered both a strength and a weakness. East Company and West Company had strong performance records in this regard; both had robust network access controls that were working as designed. However, during a projected year-long transition period, New Company employees would need to be able to connect to a New Company network while retaining access to the East Company and West Company networks.
When employees are working remotely, they usually connect to a Wi-Fi network. What should Harry advise for maintaining company security in this situation?

  • A. Hiding wireless service set identifiers (SSID).
  • B. Retaining the password assigned by the network.
  • C. Using tokens sent through HTTP sites to verify user identity.
  • D. Employing Wired Equivalent Privacy (WEP) encryption.

Answer: A


NEW QUESTION # 170
A key principle of an effective privacy policy is that it should be?

  • A. Made general enough to maximize flexibility in its application.
  • B. Written in enough detail to cover the majority of likely scenarios.
  • C. Designed primarily by the organization's lawyers.
  • D. Presented with external parties as the intended audience.

Answer: D

Explanation:
A key principle of an effective privacy policy is that it should be presented with external parties as the intended audience1. This means that the privacy policy should be clear, easily understandable, and accessible to anyone who interacts with the organization or its services. The privacy policy should also inform external parties about how their personal data is collected, processed, stored, shared, and protected by the organization2. The other options are not principles of an effective privacy policy, but rather potential pitfalls or limitations.


NEW QUESTION # 171
......

Test Engine to Practice CIPT Test Questions: https://www.practicedump.com/CIPT_actualtests.html

Use Valid CIPT Exam - Actual Exam Question & Answer: https://drive.google.com/open?id=1exaWV-1X-BmDEXtjWFjOA-IGDBXvhNbR