Unique Top-selling CIPP-E Exams - New 2024 IAPP Pratice Exam [Q97-Q122]

Share

Unique Top-selling CIPP-E Exams - New 2024 IAPP Pratice Exam

Certified Information Privacy Professional Dumps CIPP-E Exam for Full Questions - Exam Study Guide


IAPP CIPP-E (Certified Information Privacy Professional/Europe) is a globally recognized certification program designed for professionals who deal with data privacy laws and regulations in the European Union (EU). Certified Information Privacy Professional/Europe (CIPP/E) certification program is offered by the International Association of Privacy Professionals (IAPP), which is the largest and most comprehensive global information privacy community. The CIPP-E exam is designed to test the knowledge and expertise of professionals who work in the field of privacy and data protection in the EU.


The CIPP/E certification exam covers the principles of the General Data Protection Regulation (GDPR), the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks, as well as other international data protection laws and frameworks. CIPP-E exam consists of 90 multiple-choice questions that must be completed within two and a half hours. Passing the exam requires a score of 300 out of 500 points. A CIPP/E certification is valid for two years, and re-certification is required every two years to maintain the credential.

 

NEW QUESTION # 97
Under the GDPR, where personal data is not obtained directly from the data subject, a controller is exempt from directly providing information about processing to the data subject if?

  • A. The data subject already has information regarding how his data will be used
  • B. The processing of the data subject's data is protected by appropriate technical measures
  • C. The provision of such information to the data subject would be too problematic
  • D. Third-party data would be disclosed by providing such information to the data subject

Answer: A

Explanation:
According to Article 14 of the GDPR, where personal data is not obtained directly from the data subject, the controller must provide the data subject with certain information about the processing, such as the identity of the controller, the purposes and legal basis of the processing, the categories of personal data concerned, the recipients or categories of recipients of the personal data, and the rights of the data subject12. However, there are some exceptions to this obligation, as specified in Article 14(5). One of them is when the provision of such information proves impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation is likely to render impossible or seriously impair the achievement of the objectives of that processing12. In such cases, the controller must take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available12. Reference: CIPP/E Certification - International Association of Privacy Professionals, Free CIPP/E Study Guide - International Association of Privacy Professionals, GDPR - EUR-Lex, Right to be Informed - General Data Protection Regulation (GDPR)


NEW QUESTION # 98
SCENARIO
Please use the following to answer the next question:
Due to rapidly expanding workforce, Company A has decided to outsource its payroll function to Company B. Company B is an established payroll service provider with a sizable client base and a solid reputation in the industry.
Company B's payroll solution for Company A relies on the collection of time and attendance data obtained via a biometric entry system installed in each of Company A's factories. Company B won't hold any biometric data itself, but the related data will be uploaded to Company B's UK servers and used to provide the payroll service. Company B's live systems will contain the following information for each of Company A's employees:
Name
Address
Date of Birth
Payroll number
National Insurance number
Sick pay entitlement
Maternity/paternity pay entitlement
Holiday entitlement
Pension and benefits contributions
Trade union contributions
Jenny is the compliance officer at Company A. She first considers whether Company A needs to carry out a data protection impact assessment in relation to the new time and attendance system, but isn't sure whether or not this is required.
Jenny does know, however, that under the GDPR there must be a formal written agreement requiring Company B to use the time and attendance data only for the purpose of providing the payroll service, and to apply appropriate technical and organizational security measures for safeguarding the data. Jenny suggests that Company B obtain advice from its data protection officer. The company doesn't have a DPO but agrees, in the interest of finalizing the contract, to sign up for the provisions in full. Company A enters into the contract.
Weeks later, while still under contract with Company A, Company B embarks upon a separate project meant to enhance the functionality of its payroll service, and engages Company C to help. Company C agrees to extract all personal data from Company B's live systems in order to create a new database for Company B.
This database will be stored in a test environment hosted on Company C's U.S. server. The two companies agree not to include any data processing provisions in their services agreement, as data is only being used for IT testing purposes.
Unfortunately, Company C's U.S. server is only protected by an outdated IT security system, and suffers a cyber security incident soon after Company C begins work on the project. As a result, data relating to Company A's employees is visible to anyone visiting Company C's website. Company A is unaware of this until Jenny receives a letter from the supervisory authority in connection with the investigation that ensues. As soon as Jenny is made aware of the breach, she notifies all affected employees.
Under the GDPR, which of Company B's actions would NOT be likely to trigger a potential enforcement action?

  • A. Their decision to operate without a data protection officer.
  • B. Their omission of data protection provisions in their contract with Company C.
  • C. Their engagement of Company C to improve their payroll service.
  • D. Their failure to provide sufficient security safeguards to Company A's data.

Answer: C


NEW QUESTION # 99
SCENARIO
Please use the following to answer the next question:
Zandelay Fashion ('Zandelay') is a successful international online clothing retailer that employs approximately
650 people at its headquarters based in Dublin, Ireland. Martin is their recently appointed data protection officer, who oversees the company's compliance with the General Data Protection Regulation (GDPR) and other privacy legislation.
The company offers both male and female clothing lines across all age demographics, including children. In doing so, the company processes large amounts of information about such customers, including preferences and sensitive financial information such as credit card and bank account numbers.
In an aggressive bid to build revenue growth, Jerry, the CEO, tells Martin that the company is launching a new mobile app and loyalty scheme that puts significant emphasis on profiling the company's customers by analyzing their purchases. Martin tells the CEO that: (a) the potential risks of such activities means that Zandelay needs to carry out a data protection impact assessment to assess this new venture and its privacy implications; and (b) where the results of this assessment indicate a high risk in the absence of appropriate protection measures, Zandelay may have to undertake a prior consultation with the Irish Data Protection Commissioner before implementing the app and loyalty scheme.
Jerry tells Martin that he is not happy about the prospect of having to directly engage with a supervisory authority and having to disclose details of Zandelay's business plan and associated processing activities.
What would MOST effectively assist Zandelay in conducting their data protection impact assessment?

  • A. Data breach documentation that data controllers are required to maintain.
  • B. Records of processing activities that data controllers are required to maintain.
  • C. Information about DPIAs found in Articles 38 through 40 of the GDPR.
  • D. Existing DPIA guides published by local supervisory authorities.

Answer: C


NEW QUESTION # 100
Please use the following to answer the next question:
Jane Stan's her new role as a Data Protection Officer (DPO) at a Malta-based company that allows anyone to buy and sell cryptocurrencies via its online platform. The company stores and processes the personal data of its customers in a dedicated data center located in Malta |EU).
People wishing to trade cryptocurrencies are required to open an online account on the platform. They then must successfully pass a KYC due diligence procedure aimed at preventing money laundering and ensuring compliance with applicable financial regulations.
The non-European customers are also required to waive all their GDPR rights by reading a disclaimer written in bold and belong a checkbox on a separate page in order to get their account approved on the platform.
The customers must likewise accept the terms of service of the platform. The terms of service also include a privacy policy section, saying, among other things, that if a Which of the following must be a component of the anti-money-laundering data-sharing practice of the platform?

  • A. The terms of service shall also enumerate all applicable anti-money laundering few.
  • B. Customers snail receive a clear and conspicuous notice about such data sharing before submitting their data during the registration process.
  • C. Customers shall have an opt-out feature to restrict data sharing with law enforcement agencies after the registration.
  • D. The terms of service shall include the address of the anti-money laundering agency and contacts of the investigators who may access me data.

Answer: D


NEW QUESTION # 101
What is the consequence if a processor makes an independent decision regarding the purposes and means of processing it carries out on behalf of a controller?

  • A. The controller will be liable to pay an administrative fine
  • B. The processor will be liable to pay compensation to affected data subjects
  • C. The controller will be required to demonstrate that the unauthorized processing negatively affected one or more of the parties involved
  • D. The processor will be considered to be a controller in respect of the processing concerned

Answer: B


NEW QUESTION # 102
What term BEST describes the European model for data protection?

  • A. Comprehensive
  • B. Self-regulatory
  • C. Sectoral
  • D. Market-based

Answer: A

Explanation:
Reference https://ec.europa.eu/info/sites/info/files/communication-european-strategy-data-19feb2020_en.pdf


NEW QUESTION # 103
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?

  • A. The data protection officer must be located in the country where the data controller has its main establishment.
  • B. The group of undertakings must obtain approval from a supervisory authority.
  • C. The data protection officer must be easily accessible from each establishment where the undertakings are located.
  • D. The group of undertakings must be comprised of organizations of similar sizes and functions.

Answer: C


NEW QUESTION # 104
You are the new Data Protection Officer for your company and have to determine whether the company has implemented appropriate technical and organizational measures as required by Article 32 of the GDPR. Which of the following would be the most important to consider when trying to determine this?

  • A. How the public perceives what constitutes adequate security measures
  • B. Which security measures are endorsed by a majority of experts.
  • C. How security measures might evolve in the future
  • D. Which kinds of security measures your company has employed in the past

Answer: A


NEW QUESTION # 105
In addition to the European Commission, who can adopt standard contractual clauses, assuming that all required conditions are met?

  • A. The European Data Protection Supervisor.
  • B. Approved data controllers.
  • C. National data protection authorities.
  • D. The Council of the European Union.

Answer: B


NEW QUESTION # 106
What is the key difference between the European Council and the Council of the European Union?

  • A. The European Council focuses primarily on issues involving human rights.
  • B. The Council of the European Union has a degree of legislative power.
  • C. The European Council is comprised of the heads of each EU member state.
  • D. The Council of the European Union is helmed by a president.

Answer: C

Explanation:
Section: (none)
Explanation
The European Council and the Council of the European Union are two different EU institutions that have similar names but distinct roles and memberships. The European Council is the body of leaders (heads of state or government) of the 27 EU member states that defines the EU's general political direction and priorities1. The European Council does not adopt EU legislation, but rather sets the agenda and gives guidance to the other EU institutions1. The Council of the European Union, informally known as the Council, is composed of national ministers from each EU member state, grouped by policy area1. The Council is one of the two legislative bodies of the EU, along with the European Parliament, and negotiates and adopts EU laws, coordinates member states' policies, and develops the EU's common foreign and security policy1. The key difference between the two institutions is that the European Council is comprised of the heads of each EU member state, while the Council of the European Union is comprised of the ministers of each EU member state12. Reference: European Council | Council of the European Union, What is the difference between EU Council, Council of the European Union, and Council of Europe?


NEW QUESTION # 107
Which aspect of the GDPR will likely have the most impact on the consistent implementation of data protection laws throughout the European Union?

  • A. That it essentially functions as a one-stop shop mechanism
  • B. That it makes notification of large-scale data breaches mandatory
  • C. That it takes the form of a Regulation as opposed to a Directive
  • D. That it makes appointment of a data protection officer mandatory

Answer: C

Explanation:
One of the main differences between a Regulation and a Directive in the EU law is that a Regulation is directly applicable and binding in all EU member states, without the need for national implementing measures, while a Directive sets out the objectives and principles that the member states must achieve, but leaves them the choice of form and methods to transpose it into their national laws. Therefore, by taking the form of a Regulation, the GDPR aims to harmonize and unify the data protection rules across the EU, and to ensure a consistent implementation and enforcement of the data protection laws throughout the EU. The other aspects of the GDPR listed in the question, such as the one-stop shop mechanism, the mandatory notification of large-scale data breaches, and the mandatory appointment of a data protection officer, are also important features of the GDPR, but they do not have the same impact on the consistency of the data protection laws as the form of a Regulation.


NEW QUESTION # 108
Which change was introduced by the 2009 amendments to the e-Privacy Directive 2002/58/EC?

  • A. A voluntary notification for personal data breaches applicable to all data controllers.
  • B. A mandatory notification for personal data breaches applicable to electronic communication providers.
  • C. A voluntary notification for personal data breaches applicable to electronic communication providers.
  • D. A mandatory notification for personal data breaches applicable to all data controllers.

Answer: B


NEW QUESTION # 109
Under what circumstances might the "soft opt-in" rule apply in relation to direct marketing?

  • A. When an individual has not consented to the marketing.
  • B. Where an individual is given the ability to unsubscribe from marketing emails sent to him.
  • C. Where an individual's details have been obtained from a bought-in marketing list.
  • D. When an individual's details are obtained from their inquiries about buying a product.

Answer: B


NEW QUESTION # 110
What type of data lies beyond the scope of the General Data Protection Regulation?

  • A. Anonymized
  • B. Pseudonymized
  • C. Encrypted
  • D. Masked

Answer: A

Explanation:
The General Data Protection Regulation (GDPR) is a data protection law that applies to the processing of personal data of individuals in the European Union (EU) and the European Economic Area (EEA). Personal data is any information relating to an identified or identifiable natural person, such as name, address, email, phone number, etc12. The GDPR does not apply to personal data that is anonymized, meaning that it cannot be linked back to a specific individual12. Anonymization can be achieved by removing or masking any identifying information from the data, such as using pseudonyms, aggregating or generalizing the data, or applying statistical methods12.
Therefore, the type of data that lies beyond the scope of the GDPR is anonymized data.
Reference:
https://commission.europa.eu/law/law-topic/data-protection/reform/what-personal-data_en#:~:text=Different%20pieces%20of%20information%2C%20which,the%20scope%20of%20the%20GDPR. B. ANONYMIZED Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data. Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the GDPR. Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.


NEW QUESTION # 111
The GDPR specifies fines that may be levied against data controllers for certain infringements. Which of the following infringements would be subject to the less severe administrative fine of up to 10 million euros (or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year)?

  • A. Failure to provide the means for a data subject to rectify inaccuracies in personal data.
  • B. Failure to process personal information in a manner compatible with its original purpose.
  • C. Failure to implement technical and organizational measures to ensure data protection is enshrined by design and default.
  • D. Failure to demonstrate that consent was given by the data subject to the processing of their personal data where it is used as the basis for processing.

Answer: C

Explanation:
According to Article 83 of the GDPR, the less severe administrative fines of up to 10 million euros or 2% of the annual worldwide turnover apply to infringements of the articles governing controllers and processors, certification bodies, and monitoring bodies. These include Articles 8, 11, 25-39, 42, and 43. Among the answer choices, only option B falls under this category, as Article 25 requires controllers to implement data protection by design and by default. Option A is related to Article 7, which governs the conditions for consent. Option C is related to Article 5, which sets out the principles for processing personal data. Option D is related to Article 16, which grants the right to rectification to data subjects. These articles are subject to the more severe administrative fines of up to 20 million euros or 4% of the annual worldwide turnover. Reference:
GDPR Article 83
GDPR Article 25
GDPR Article 7
GDPR Article 5
GDPR Article 16


NEW QUESTION # 112
Read the following steps:
* Discover which employees are accessing cloud services and from which devices and apps
* Lock down the data in those apps and devices
* Monitor and analyze the apps and devices for compliance
* Manage application life cycles
* Monitor data sharing
An organization should perform these steps to do which of the following?

  • A. Maintain a secure Bring Your Own Device (BYOD) program.
  • B. Ensure cloud vendors are complying with internal data use policies.
  • C. Pursue a GDPR-compliant Privacy by Design process.
  • D. Institute a GDPR-compliant employee monitoring process.

Answer: A

Explanation:
Explanation/Reference: https://www.itproportal.com/features/heading-off-the-spectre-of-gdpr-compliance-with-secure-byod/


NEW QUESTION # 113
A Spanish electricity customer calls her local supplier with Questions: about the company's upcoming merger. Specifically, the customer wants to know the recipients to whom her personal data will be disclosed once the merger is final. According to Article 13 of the GDPR, what must the company do before providing the customer with the requested information?

  • A. Verify that the purpose of the request from the customer is in line with the GDPR.
  • B. Verify that the request is applicable to the data collected before the GDPR entered into force.
  • C. Verify that the identity of the customer can be proven by other means.
  • D. Verify that the personal data has not already been sent to the customer.

Answer: C

Explanation:
According to Article 13 of the GDPR, the controller (in this case, the electricity supplier) has the obligation to provide the data subject (in this case, the customer) with information about the processing of their personal data, including the recipients or categories of recipients of the personal data, if any. However, before providing such information, the controller must verify the identity of the data subject, to ensure that the information is not disclosed to unauthorized persons. This verification can be done by other means than the personal data already collected, such as asking for additional information, sending a verification code, or using a secure online portal. The other options (A, B, and C) are not relevant for this verification, as they do not relate to the identity of the data subject, but to the scope, purpose, and history of the processing. Reference:
Article 13 of the GDPR
The right to be informed (transparency) (Article 13 & 14 GDPR)
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)


NEW QUESTION # 114
SCENARIO
Please use the following to answer the next question:
Joe started the Gummy Bear Company in 2000 from his home in Vermont, USA.
Today, it is a multi-billion-dollar candy company operating in every continent. All of the company's IT servers are located in Vermont. This year Joe hires his son Ben to join the company and head up Project Big, which is a major marketing strategy to triple gross revenue in just 5 years. Ben graduated with a PhD in computer software from a top university. Ben decided to join his father's company, but is also secretly working on launching a new global online dating website company called Ben Knows Best.
Ben is aware that the Gummy Bear Company has millions of customers and believes that many of them might also be interested in finding their perfect match. For Project Big, Ben redesigns the company's online web portal and requires customers in the European Union and elsewhere to provide additional personal information in order to remain a customer. Project Ben begins collecting data about customers' philosophical beliefs, political opinions and marital status.
If a customer identifies as single, Ben then copies all of that customer's personal data onto a separate database for Ben Knows Best. Ben believes that he is not doing anything wrong, because he explicitly asks each customer to give their consent by requiring them to check a box before accepting their information. As Project Big is an important project, the company also hires a first year college student named Sam, who is studying computer science to help Ben out.
Ben calls out and Sam comes across the Ben Knows Best database. Sam is planning on going to Ireland over Spring Beak with 10 of his friends, so he copies all of the customer information of people that reside in Ireland so that he and his friends can contact people when they are in Ireland.
Joe also hires his best friend's daughter, Alice, who just graduated from law school in the U.S., to be the company's new General Counsel. Alice has heard about the GDPR, so she does some research on it. Alice approaches Joe and informs him that she has drafted up Binding Corporate Rules for everyone in the company to follow, as it is important for the company to have in place a legal mechanism to transfer data internally from the company's operations in the European Union to the U.S.
Joe believes that Alice is doing a great job, and informs her that she will also be in-charge of handling a major lawsuit that has been brought against the company in federal court in the U.S. To prepare for the lawsuit, Alice instructs the company's IT department to make copies of the computer hard drives from the entire global sales team, including the European Union, and send everything to her so that she can review everyone's information. Alice believes that Joe will be happy that she did the first level review, as it will save the company a lot of money that would otherwise be paid to its outside law firm.
As a result of Sam's actions, the Gummy Bear Company potentially violated Articles 33 and 34 of the GDPR and will be required to do what?

  • A. Analyze and evaluate the liability for customers in Ireland.
  • B. Analyze and evaluate all of its breach notification obligations.
  • C. Notify its Data Protection Authority about the data breach.
  • D. Notify all of its customers that reside in the European Union.

Answer: C


NEW QUESTION # 115
ISO 31700 has set forth requirements relating to consumer products and services. In particular, this international standard focuses on the implementation of which of the following?

  • A. Automated systems for identifying EU data subjects' personal data.
  • B. Privacy notices for companies providing services to consumers.
  • C. Comprehensive ethical Al software.
  • D. Privacy by design.

Answer: D

Explanation:
ISO 31700 is an international standard that provides high-level requirements and recommendations for organizations that use privacy by design (PbD) in the development, maintenance and operation of consumer goods and services. PbD is a concept that aims to integrate privacy into products, services and systems by default, following seven main principles: proactive not reactive, privacy as the default, privacy embedded into design, full functionality, end-to-end security, visibility and transparency, and respect for user privacy. PbD is also a legal requirement under many prominent privacy regulations across the world, such as the GDPR. ISO 31700 is based on a consumer-centric approach, where the consumer's privacy rights and preferences are placed at the center of product development and operation.


NEW QUESTION # 116
Which of the following Convention 108+ principles, as amended in 2018, is NOT consistent with a principle found in the GDPR?

  • A. The requirement to demonstrate compliance to a supervisory authority.
  • B. The obligation of companies to declare data breaches.
  • C. The necessity of the bulk collection of personal data by the government.

Answer: A


NEW QUESTION # 117
As per the GDPR, which legal basis would be the most appropriate for an online shop that wishes to process personal data for the purpose of fraud prevention?

  • A. Consent
  • B. Legitimate interest
  • C. Protection of the interests of the data subjects.
  • D. Performance of a contact

Answer: B


NEW QUESTION # 118
A company in France suffers a robbery over the weekend owing to a faulty alarm system. When it is determined that the break-in involves the loss of a substantial amount of data, the company decides on a CCTV system to monitor for future incidents. Company technicians install cameras in the entrance of the building, hallways and offices. Footage is recorded continuously, and is monitored by the home office in the United States. What is the most realistic step the company could take to address their security concerns and comply with the personal data processing principles set out in Article 5 of the GDPR?

  • A. Restrict camera placement to building entrances only.
  • B. Retain captured footage for no more than 30 days.
  • C. Seek informed consent from company employees.
  • D. Have cameras recording during work hours only.

Answer: C


NEW QUESTION # 119
Company X has entrusted the processing of their payroll data to Provider
Y. Provider Y stores this encrypted data on its server. The IT department of Provider Y finds out that someone managed to hack into the system and take a copy of the data from its server. In this scenario, whom does Provider Y have the obligation to notify?

  • A. The public
  • B. Law enforcement
  • C. The supervisory authority
  • D. Company X

Answer: B


NEW QUESTION # 120
What is the MAIN reason GDPR Article 4(22) establishes the concept of the "concerned supervisory authority"?

  • A. To ensure the GDPR covers controllers that do not have an establishment in the EU but have a representative in a member state.
  • B. To encourage the consistency of local data processing activity.
  • C. To give corporations a choice about who their supervisory authority will be.
  • D. To ensure that the interests of individuals residing outside the lead authority's jurisdiction are represented.

Answer: B


NEW QUESTION # 121
An organisation receives a request multiple times from a data subject seeking to exercise his rights with respect to his own personal dat a. Under what condition can the organisation charge the data subject for processing the request?

  • A. Only where the organisation can show that it is reasonable to do so because more than one request was made.
  • B. Only if the organisation can demonstrate that the request is clearly excessive or misguided.
  • C. Only where the administrative costs of taking the action requested exceeds a certain threshold.
  • D. Only to the extent this is allowed under the restrictions on data subjects' rights introduced under Art 23 of GDPR.

Answer: B

Explanation:
1. A request may be manifestly unfounded or excessive if it has no clear purpose, is clearly frivolous or vexatious, is made repeatedly by the same data subject, or goes beyond what is reasonably necessary to fulfil the data subject's request2. In such cases, the organisation can either charge a reasonable fee or refuse to act on the request, but it must be able to justify its decision and inform the data subject of the reasons and their right to lodge a complaint with a supervisory authority or a judicial remedy1. The other options are not correct, as they either do not reflect the conditions for charging a fee under the GDPR, or are not relevant to the question. Reference: Right of access | ICO, Charge for a Data Subject Request GDPR - GDPR Wiki


NEW QUESTION # 122
......


The CIPP/E certification program was developed by the International Association of Privacy Professionals (IAPP), the largest privacy association in the world. The IAPP is a not-for-profit organization that promotes and advances the privacy profession globally. The IAPP CIPP/E certification program provides an essential and comprehensive understanding of the EU's data protection laws, and it is recognized as the gold standard certification for privacy professionals in Europe.

 

Best way to practice test for IAPP CIPP-E: https://www.examcost.com/CIPP-E-practice-exam.html

CIPP-E Dump Ready - Exam Questions and Answers: https://drive.google.com/open?id=1P5JQ9_xnOJ46oo2tHx8eHTHMQbXSa9tB