Practice CDPSE Privacy Engineering questions with full explanations on every answer.
Start practicing
Privacy Engineering — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
A privacy engineer is configuring Azure Data Factory to ensure PII is masked during integration. Which feature should be configured to apply dynamic data masking on SQL targets?
2A practitioner is deploying a Google Cloud Storage bucket. To ensure that files containing PII are automatically redacted before being accessed by external users, which Cloud DLP action should be integrated?
3A privacy engineer is implementing differential privacy on a dataset using Google Cloud's Differential Privacy library. Which THREE configuration steps are critical for minimizing re-identification risk?
4In a Google Cloud environment, you need to implement a policy to automatically redact PII from documents uploaded to Cloud Storage. Which service should be integrated?
5When implementing Privacy by Design (PbD) in a new mobile application, which TWO of the following are considered proactive technical controls?
6In AWS Glue, a developer needs to ensure that sensitive columns are automatically identified and redacted during ETL jobs. Which component is best suited for this?
7A privacy engineer is configuring Azure SQL Database to ensure that sensitive columns containing PII are hidden from non-privileged users. Which feature should be implemented to achieve dynamic data masking?
8A privacy engineer is configuring a new AWS S3 bucket to store sensitive customer data. Which configuration ensures the highest level of privacy by design through encryption at rest using customer-managed keys?
9A privacy engineer is using Terraform to enforce encryption at rest for S3 buckets. Which resource attribute should be set to 'aws:kms'?
10Which technique is most effective for minimizing PII in a non-production database environment while maintaining referential integrity?
11In the context of Privacy by Design, what is the primary role of an 'Access Control Matrix' in a microservices architecture?
12Which of the following is an example of a Privacy-Enhancing Technology (PET) that focuses on data minimization?
13When implementing differential privacy in a data analytics pipeline, what is the primary technical trade-off the engineer must balance?
14When using Homomorphic Encryption, what is the primary limitation for a privacy engineer to consider?
15You are designing a system for k-anonymity. If a dataset has an identifier that is unique to every row, what is the first step you must take before applying generalization?
16A company needs to share customer demographics with a third party. Which technique allows for statistical analysis without revealing individual identities?
17Which of the following is an example of an 'operational' technical control for privacy?
18A privacy engineer is auditing log data. Which action best aligns with data minimization requirements for logs?
19You are troubleshooting a Federated Learning model. Privacy leakage is occurring during model updates. Which parameter should you adjust to improve privacy?
20When implementing a 'Privacy Dashboard' for users, which feature is critical for fulfilling GDPR Article 15 (Right of Access) requests?
21An organization is using 'Bring Your Own Key' (BYOK) in their cloud environment. What is the primary privacy benefit?
22In a database, you need to replace social security numbers with a consistent, non-reversible value for analytics. What is the best approach?
23Which component in an API gateway is used to ensure PII is not sent to third-party endpoints?
24When designing a data retention policy, which technical configuration in S3 best automates the process?
25You are implementing 'Privacy-Preserving Record Linkage' between two databases. What is the most effective approach?
26Which of the following is an example of a physical privacy control?
27Which feature in an identity provider (IdP) supports privacy by limiting the scope of claims sent to a relying party?
28When designing a system with k-anonymity, which metric measures the impact of generalization on the utility of the data?
29Which principle is represented by ensuring a user's data is only available to the specific application service that needs it?
30An organization wants to monitor data access patterns for potential privacy violations. Which tool is best for detecting unusual access to PII tables?
31A system architect is using 'Zero Trust' network principles. How does this enhance privacy?
32To prevent 're-identification' of an anonymized dataset, what process should be applied if the dataset is merged with external public data?
33When implementing Secure Multi-Party Computation (SMPC), what is the primary benefit?
34What is the primary function of a 'Data Protection Impact Assessment' (DPIA) from an engineering perspective?
35In the context of 'Privacy-Preserving Machine Learning', what is the purpose of the 'Membership Inference Attack' simulation during testing?
36When configuring a Cloud Service Provider's (CSP) 'Storage Access' permissions, which configuration best supports the principle of data segregation?
37What does a 'Privacy-Enhancing Technology' (PET) primarily aim to achieve?
38When encrypting data for long-term storage, which configuration is most important for privacy?
39Which of the following is an effective way to implement 'Right to Erasure' in a distributed database system?
40You are auditing a system for 'Data Minimization'. Which discovery finding would be a primary concern?
41Which THREE features are essential when implementing a robust 'Consent Management Platform' (CMP)?
42Which TWO of the following are key privacy engineering objectives when designing a system that processes sensitive health data?
43Which TWO techniques should be used to protect PII in non-production environments to ensure the data remains non-identifiable?
44Which THREE privacy-enhancing technologies are commonly used to facilitate data analysis on distributed datasets without centralizing the raw PII?
45Which TWO actions should be taken when decommissioning an old server containing PII?
46Which THREE factors are critical for balancing privacy and utility when using k-anonymity?
47Which TWO technical controls are effective for limiting the scope of PII access in a cloud-based SQL environment?
48Which TWO methods are effective for preventing 'Inference Attacks' in a data analytics platform?
49Which TWO of the following are privacy-by-design principles relevant to software development?
50Which TWO of the following are key privacy controls in an AWS environment?
51Which THREE attributes are typically included in a 'Privacy Metadata' schema to support automated data governance?
52Which TWO of the following are effective ways to protect logs that contain PII?
53Which THREE technical approaches assist in 'Right to Portability' implementation?
54Which TWO actions help improve privacy in a containerized environment (e.g., Kubernetes)?
55Which THREE privacy engineering activities are performed during the 'Maintenance' phase of the system lifecycle?
56A privacy engineer is implementing differential privacy in a data analytics pipeline. To ensure the privacy budget remains intact over multiple queries, which technique should be applied?
57You are configuring AWS Macie to identify PII in an S3 bucket. Which setting must be enabled to ensure that specific sensitive data patterns are detected across all files regardless of their object tags?
58When pseudonymizing a database using SHA-256 hashing, what is the most critical requirement to prevent re-identification via brute-force or dictionary attacks?
59A web application stores user logs in a cleartext format. To implement 'Privacy by Design', which technical control is the most appropriate first step to minimize data exposure?
60You are integrating a homomorphic encryption library into a cloud-based financial system. What is the primary trade-off you must communicate to stakeholders regarding the implementation of Fully Homomorphic Encryption (FHE)?
61Which feature in Microsoft Purview Information Protection should be used to automatically identify and classify documents containing credit card numbers as they are created?
62In a federated learning architecture, how is the model trained without exposing the underlying local datasets?
63An organization uses a 'Privacy-preserving Synthetic Data' generator. What is the primary purpose of this tool in a development environment?
64When configuring 'Dynamic Data Masking' in SQL Server, which permission is required for a user to see the unmasked data?
65A privacy engineer is implementing 'Tokenization' for credit card processing. Where should the 'vault' be situated to ensure the highest level of privacy?
66Which of the following is the most effective technical control for implementing the 'Right to be Forgotten' in a distributed microservices environment?
67When using 'k-anonymity' to protect a dataset, what does the parameter 'k' represent?
68To ensure that data access logs cannot be tampered with by an administrator with high privileges, which technical control should be implemented?
69What is the primary privacy advantage of using 'On-Device Processing' for machine learning inference?
70You are configuring an API gateway to implement 'Data Minimization' via response filtering. How is this typically achieved for JSON payloads?
71A privacy engineer is reviewing a 'consent management platform' (CMP). Which configuration is necessary to ensure compliance with a user's choice to 'opt-out' of data sharing?
72Which THREE of the following are considered standard 'Privacy-Enhancing Technologies' (PETs) used for data protection in analytics?
73When designing a privacy-preserving data pipeline, which TWO strategies help achieve 'Data Minimization'?
74Which THREE techniques are commonly used to achieve 'Pseudonymization' for PII in data sets?
75Which TWO actions should be taken when performing a 'Privacy Impact Assessment' (PIA) on a new software tool?
76Which THREE considerations are critical when implementing 'Anonymization' to ensure it meets the standard of being 'irreversible'?
77Which THREE types of data are considered 'sensitive' and require heightened privacy controls?
78Which TWO features in a cloud IAM configuration help enforce 'Least Privilege' as a privacy control?
The Privacy Engineering domain covers the key concepts tested in this area of the CDPSE exam blueprint published by ISACA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CDPSE domains — no account required.
The Courseiva CDPSE question bank contains 78 questions in the Privacy Engineering domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Privacy Engineering domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included