ISACA · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A privacy engineer is configuring Azure Data Factory to ensure PII is masked during integration. Which feature should be configured to apply dynamic data masking on SQL targets?
Azure Policy definition
SQL Dynamic Data Masking policies
DDM is the direct tool for masking sensitive data at the database level.
Data Factory Mapping Data Flows
Azure Key Vault access policies
A practitioner is deploying a Google Cloud Storage bucket. To ensure that files containing PII are automatically redacted before being accessed by external users, which Cloud DLP action should be integrated?
IAM conditions
Storage Transfer Service
Bucket lock
Cloud DLP de-identification template
DLP de-identification templates define how data is masked or tokenized.
A privacy engineer is implementing differential privacy on a dataset using Google Cloud's Differential Privacy library. Which THREE configuration steps are critical for minimizing re-identification risk?
Choosing a random seed that is publicly known
Defining appropriate sensitivity bounds for the input data
Sensitivity bounds dictate the amount of noise required.
Increasing the dataset size to infinite
Setting a low Epsilon value for higher privacy loss limit
Lower epsilon provides a stronger privacy guarantee.
Enabling Delta parameter for probabilistic privacy guarantees
Delta represents the probability of breaking the epsilon guarantee.
In a Google Cloud environment, you need to implement a policy to automatically redact PII from documents uploaded to Cloud Storage. Which service should be integrated?
Cloud Storage buckets lifecycle policy
Cloud Identity and Access Management
Cloud Logging
Cloud Data Loss Prevention (DLP) API
The DLP API provides native integration to redact sensitive data from storage sources.
When implementing Privacy by Design (PbD) in a new mobile application, which TWO of the following are considered proactive technical controls?
Periodic external audits
End-user training
Comprehensive incident response plan
Default privacy settings
Ensuring the most restrictive settings are enabled by default is a proactive control.
Data minimization
Collecting only what is necessary is a core PbD principle.
In AWS Glue, a developer needs to ensure that sensitive columns are automatically identified and redacted during ETL jobs. Which component is best suited for this?
AWS Glue Schema Registry
AWS Lake Formation
Amazon Macie
Glue DataBrew
DataBrew provides visual transformations and PII redaction capabilities.
Want more Privacy Engineering practice?
Practice this domainDuring a data mapping exercise in BigID, you need to identify data that has exceeded its retention period. Which attribute should be used to filter the data inventory?
Data Subject ID
Classification Level
Encryption Status
Retention Expiration Date
This field tracks when data is eligible for disposal according to policy.
Data Source Type
When configuring AWS Macie to perform data minimization, which configuration is required to prevent the service from scanning internal metadata fields that do not contain customer PII?
S3 Bucket Policy
S3 Exclusion Rules
Exclusion rules allow filtering out specific buckets or paths from discovery.
Object Tagging
VPC Endpoint Configuration
IAM Policy Restriction
In Collibra, you are mapping a data element to a business term to support data minimization. What is the effect of changing the 'Data Stewardship' workflow status to 'Deprecated'?
Triggers an immediate deletion task in the source DB
Archives the metadata record and removes it from search
Deprecation effectively hides the data from the business catalog, reducing unnecessary usage.
Deletes the physical data source
Prevents unauthorized users from editing the metadata
While using the Salesforce Data Masking tool, which option should be selected to ensure that production data copied to a sandbox is rendered unusable for unauthorized parties?
Object Permissions
Field Level Security
Anonymization Masking
This replaces sensitive values with scrambled data, rendering it unusable for production identification.
Data Refresh
You are managing Azure Information Protection (AIP) labels. Which action is necessary to ensure that documents classified as 'Highly Confidential' are automatically encrypted?
Modify the Information Rights Management (IRM) template
Configure Protection settings in the Label
Protection settings within the sensitivity label allow for automatic encryption.
Apply Azure Policy
Enable Auto-Labeling on the Data Source
In Google Cloud Data Loss Prevention (DLP), which transformation method should be applied to a column containing email addresses to maintain format while ensuring privacy?
Redaction
Masking
Bucketization
Format-Preserving Encryption
This keeps the email format while encrypting the content.
Want more Data Life Cycle Management practice?
Practice this domainDuring a DPIA (Data Protection Impact Assessment), a CDPSE identifies a high risk to data subjects due to the use of AI-driven profiling. What is the appropriate next step?
Proceed with the project and monitor for data breaches.
Consult with the Data Protection Officer (DPO) to determine if regulatory consultation is necessary.
If risks remain high, the regulator may need to be involved per GDPR Article 36.
Inform the public about the risk to maintain transparency.
Switch to a less intrusive profiling algorithm without re-evaluating the DPIA.
A company wants to collect geolocation data from mobile users. Which privacy principle should be applied first?
Automated archival of location history after one week.
Publicly disclosing the use of geolocation in the privacy policy.
Data minimization by requesting access to precise location only when necessary.
Data minimization is a core principle ensuring only essential data is collected.
Full encryption of geolocation data in transit.
A CDPSE is auditing a legacy application that stores passwords in plain text. What is the most effective immediate mitigation strategy?
Perform a Data Protection Impact Assessment (DPIA) to document the risk.
Conduct a data breach simulation to see if the vulnerability is exploitable.
Implement an access control list (ACL) to restrict who can see the plain text passwords.
Implement a salted hashing algorithm and re-hash all existing credentials.
Hashing is the industry-standard technical control for storing passwords.
An organization is evaluating a cloud service provider (CSP) for storing sensitive customer data. Under the GDPR, what is the most critical step the CDPSE must perform to manage third-party privacy risk?
Execute a Data Processing Agreement (DPA) that mandates adherence to specific privacy instructions.
A DPA is mandatory for ensuring the processor handles data according to the controller's requirements.
Perform a penetration test on the CSP's multi-tenant environment.
Verify the CSP's physical data center location to ensure it is within the EU.
Review the CSP's SOC 2 Type II report for general system reliability.
When mapping data flows to identify privacy risks, a practitioner discovers that personal data is being transferred to a non-affiliated third party. What is the immediate requirement?
Request the third party to delete the data until a contract is signed.
Disable the API endpoint connecting to the third party to prevent further data exposure.
Validate that the transfer is supported by an appropriate legal basis and documented in the Records of Processing Activities (ROPA).
ROPA documentation is a fundamental requirement under GDPR for all processing activities.
Immediately notify the supervisory authority of the data transfer.
A company is implementing a new CCPA compliance tool. Which feature should be used to automate the 'Right to Opt-Out' request process for web visitors?
A manual email ticketing system for data subject access requests.
Automated Consent Management Platform (CMP) configured with a 'Do Not Sell' signal.
A CMP can manage user preferences and facilitate the 'Do Not Sell' opt-out request.
An automated script that permanently deletes user accounts after 30 days of inactivity.
An internal dashboard for employees to view customer purchase histories.
Want more Privacy Risk Management And Compliance practice?
Practice this domainWhich governance structure is most appropriate for a decentralized organization managing privacy risks?
Hub-and-spoke model with localized privacy champions.
This allows central policy setting with local implementation.
Ad-hoc committee based on project needs.
Outsourcing all privacy functions.
Centralized command-and-control structure.
Which document should a CDPSE practitioner review first when establishing a new privacy governance program?
The list of current vendors.
The software inventory.
The existing business strategy and risk appetite.
Privacy strategy must align with overall business risk appetite.
The technical architecture diagram.
In the context of the NIST Privacy Framework, what is the primary role of the 'Govern' (GV) function?
Creating data erasure requests.
Communicating privacy risks to stakeholders.
Communication and policy are key elements of the GV function.
Detecting privacy breaches.
Implementing technical access controls.
Archiving personal data.
A company is moving to a cloud-based SaaS environment. Who retains the primary responsibility for privacy governance?
The individual data subjects.
The Lead Supervisory Authority.
The Data Controller (the company).
Privacy governance accountability cannot be transferred to a provider.
The Network Infrastructure team.
The Cloud Service Provider (CSP).
When aligning privacy strategy with business objectives, what is the primary metric to demonstrate the value of a privacy program to stakeholders?
Count of privacy training sessions completed.
Reduction in privacy-related regulatory non-compliance fines.
Risk and fine reduction is a direct business value driver.
Total spend on privacy software tools.
Number of privacy patches applied.
You are mapping personal data flows for a global enterprise. Which approach is most effective for demonstrating accountability under GDPR?
Conducting periodic penetration tests.
Maintaining a comprehensive Record of Processing Activities (ROPA).
Article 30 ROPAs are the primary mechanism for demonstrating accountability.
Updating the external privacy policy annually.
Signing NDAs with all employees.
Want more Privacy Governance practice?
Practice this domainThe CDPSE exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Privacy Engineering, Data Life Cycle Management, Privacy Risk Management And Compliance, Privacy Governance. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA CDPSE exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.