Practice CDPSE Privacy Risk Management And Compliance questions with full explanations on every answer.
Start practicing
Privacy Risk Management And Compliance — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a DPIA (Data Protection Impact Assessment), a CDPSE identifies a high risk to data subjects due to the use of AI-driven profiling. What is the appropriate next step?
2A company wants to collect geolocation data from mobile users. Which privacy principle should be applied first?
3A CDPSE is auditing a legacy application that stores passwords in plain text. What is the most effective immediate mitigation strategy?
4An organization is evaluating a cloud service provider (CSP) for storing sensitive customer data. Under the GDPR, what is the most critical step the CDPSE must perform to manage third-party privacy risk?
5When mapping data flows to identify privacy risks, a practitioner discovers that personal data is being transferred to a non-affiliated third party. What is the immediate requirement?
6A company is implementing a new CCPA compliance tool. Which feature should be used to automate the 'Right to Opt-Out' request process for web visitors?
7A multinational company is transferring data between its US and EU subsidiaries. Which mechanism is most effective for ensuring cross-border data transfer compliance after the invalidation of previous frameworks?
8A CDPSE practitioner is conducting a Privacy Impact Assessment (PIA) for a new marketing application that uses behavioral tracking. Which action should be prioritized to ensure compliance with privacy-by-design principles?
9What is the primary purpose of a Data Privacy Impact Assessment (DPIA)?
10Which document should a CDPSE review to understand the organization's legal basis for processing employee personal data?
11When a third-party vendor reports a data breach, what is the first step the CDPSE should take?
12A company is preparing for a CCPA audit. Which internal process is most important to demonstrate compliance regarding the 'Right to Know'?
13Which technique should be used to protect personal data during software testing?
14A company is using an automated system to make credit decisions. What is the main privacy concern regarding the 'Right to Explanation'?
15An organization's privacy policy is updated to reflect a new vendor. What is the most important follow-up action?
16When conducting a privacy risk assessment, what is the significance of 'Data Lifecycle Management'?
17What does 'Privacy by Default' imply regarding system configuration?
18A CDPSE is reviewing a vendor's privacy controls. Which finding would be considered a major non-compliance risk?
19What is the first step in creating a data inventory for a privacy program?
20A company is implementing a Bring Your Own Device (BYOD) policy. What is the primary privacy challenge?
21When evaluating a third-party's security, what should the CDPSE focus on to ensure effective privacy risk management?
22How can a CDPSE ensure that personal data is only kept for as long as necessary?
23A company is considering the use of a data broker. Which privacy risk is most significant?
24During an audit, it is found that an application logs user session tokens including sensitive user IDs. What is the correct privacy recommendation?
25Which THREE elements are essential in a Data Protection Impact Assessment (DPIA) report?
26A CDPSE is advising on a website redesign. What is the most important privacy-related feature for a contact form?
27Which TWO actions should a CDPSE prioritize when assessing a vendor for privacy compliance?
28Which THREE documents are typically required for compliance with global privacy regulations?
29When managing privacy risks, which TWO approaches help in 'Data Minimization'?
30Which TWO factors must be considered when determining if a cross-border data transfer is lawful under GDPR?
31Which THREE steps are vital when responding to a Data Subject Access Request (DSAR)?
32Which TWO actions should a CDPSE take to demonstrate 'Privacy by Design' in a software project?
33Which THREE types of personal data are typically considered 'special category' or 'sensitive' data under privacy regulations?
34Which TWO security measures are most effective in protecting against unauthorized access to PII?
35Which THREE items should be included in a Privacy Policy that aligns with global transparency requirements?
36A CDPSE practitioner is conducting a Privacy Impact Assessment (PIA) for a new marketing application. During the data flow mapping phase, they identify that PII is being transferred to a cloud service provider located in a non-equivalent jurisdiction. Which action should the practitioner prioritize to ensure compliance with the GDPR?
37Your organization is preparing for a CCPA/CPRA audit. You are asked to verify the 'Right to Opt-Out of Sale or Sharing' implementation. Which technical requirement must be validated to ensure compliance with the Global Privacy Control (GPC) signal?
38A third-party vendor is providing an API integration for customer support. As a CDPSE, what is the first step you should take in the third-party privacy risk management lifecycle?
39During a Data Mapping exercise, the CDPSE discovers that a legacy database stores PII in cleartext. The system is scheduled for decommissioning in 18 months. What is the most appropriate privacy risk mitigation strategy?
40Which of the following is the most critical element to include in a Privacy Notice under GDPR to fulfill the 'Right to be Informed'?
41An organization is implementing a 'Privacy by Design' framework for a machine learning model used to predict customer churn. Which technique should be utilized to minimize privacy risk while maintaining model utility?
42A multinational company is evaluating a SaaS solution. As a CDPSE, you must ensure that the vendor's data retention policy aligns with your organization's internal privacy standards. Where should this requirement be formally documented?
43When establishing a Privacy Risk Assessment methodology, which TWO components are essential to ensure the assessment is repeatable and defensible?
44Which THREE activities should be included in an organization's privacy compliance monitoring program to identify potential regulatory non-compliance?
45In the event of a personal data breach, which TWO actions are required to satisfy the notification obligations under many modern privacy regulations (e.g., GDPR)?
The Privacy Risk Management And Compliance domain covers the key concepts tested in this area of the CDPSE exam blueprint published by ISACA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CDPSE domains — no account required.
The Courseiva CDPSE question bank contains 45 questions in the Privacy Risk Management And Compliance domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Privacy Risk Management And Compliance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included