Courseiva

ISACA Certified Data Privacy Solutions Engineer (CDPSE) (CDPSE) (CDPSE) — Questions 175

215 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
MCQhard

A multinational company intends to implement a Global Privacy Policy. What is the greatest challenge to its effective governance?

A.Incompatible local regulatory mandates.
B.Lack of translation services.
C.Difficulty in choosing a document management system.
D.Inability to find a privacy officer for every region.
E.Resistance from the Marketing department.
AnswerA

Different legal jurisdictions often have mutually exclusive privacy requirements.

Why this answer

Conflicting local legal requirements often impede a single global policy.

2
Multi-Selectmedium

Which TWO actions should be taken when decommissioning an old server containing PII?

Select 2 answers
A.Saving logs to a cloud bucket
B.Cryptographic erasure of the drives
C.Moving data to a temporary folder
D.Physical destruction of the drives
E.Reformatting the partition
AnswersB, D

Renders data unrecoverable.

Why this answer

Cryptographic erasure and physical destruction are industry-standard methods for ensuring data cannot be recovered.

3
MCQmedium

A multinational company is transferring data between its US and EU subsidiaries. Which mechanism is most effective for ensuring cross-border data transfer compliance after the invalidation of previous frameworks?

A.Restricting all data transfers to only encrypted tunnels.
B.Relying on the internal 'Group Privacy Policy' as an adequacy decision.
C.Implementing Standard Contractual Clauses (SCCs) alongside a Transfer Impact Assessment (TIA).
D.Self-certification under the U.S. Commerce Department's privacy program.
AnswerC

The combination of SCCs and a TIA is the current standard for ensuring adequate protection.

Why this answer

Standard Contractual Clauses (SCCs) are the most widely used legal mechanism for international data transfers.

4
MCQeasy

An organization's privacy policy is updated to reflect a new vendor. What is the most important follow-up action?

A.Archiving the previous version of the privacy policy for internal records.
B.Requesting a new SOC 2 report from the new vendor.
C.Communicating the privacy policy update to the data subjects.
D.Updating the internal audit schedule to include the new vendor.
AnswerC

Notifying users of changes to how their data is handled is a legal requirement.

Why this answer

Transparency is a core principle; individuals must be notified of changes that affect their data rights.

5
MCQhard

In a Google Cloud environment, you need to implement a policy to automatically redact PII from documents uploaded to Cloud Storage. Which service should be integrated?

A.Cloud Storage buckets lifecycle policy
B.Cloud Identity and Access Management
C.Cloud Logging
D.Cloud Data Loss Prevention (DLP) API
AnswerD

The DLP API provides native integration to redact sensitive data from storage sources.

Why this answer

Cloud Data Loss Prevention (DLP) API allows for the inspection, de-identification, and redaction of PII within unstructured data.

6
MCQeasy

What is the first step in conducting a privacy audit?

A.Asking employees for their lunch preferences.
B.Buying new security software.
C.Defining the scope and objectives of the audit.
D.Writing the final audit report.
AnswerC

Without scope, an audit lacks direction and purpose.

Why this answer

Defining the scope is critical to ensuring the audit focuses on the right areas.

7
Multi-Selectmedium

Which TWO technical controls are effective for limiting the scope of PII access in a cloud-based SQL environment?

Select 2 answers
A.Column-level security
B.Row-level security
C.Public network access
D.Full database export
E.Verbose error logging
AnswersA, B

Hides specific sensitive columns.

Why this answer

Column-level security and Row-level security provide the most granular access control to prevent unauthorized PII visibility.

8
MCQhard

You are configuring an API gateway to implement 'Data Minimization' via response filtering. How is this typically achieved for JSON payloads?

A.By using TLS 1.3 encryption
B.By increasing the request timeout
C.By implementing field-level response transformation
D.By modifying the backend database schema
AnswerC

This acts as a filter to remove specific keys from the JSON payload at the gateway level.

Why this answer

Response transformation or JSON schema validation allows the gateway to strip sensitive fields from the response body before it reaches the client.

9
MCQmedium

When evaluating a third-party vendor's privacy maturity, which document is most critical for the privacy practitioner to review during the due diligence process?

A.A SOC 2 Type II report or independent privacy audit report.
B.The vendor's public stock market performance.
C.The vendor's marketing brochure.
D.The vendor's internal organizational chart.
AnswerA

These reports provide independent assurance regarding the efficacy of the vendor's controls.

Why this answer

A SOC 2 Type II report or a dedicated privacy audit report provides independent verification of the vendor's privacy controls.

10
Multi-Selectmedium

When implementing Privacy by Design (PbD) in a new mobile application, which TWO of the following are considered proactive technical controls?

Select 2 answers
A.Periodic external audits
B.End-user training
C.Comprehensive incident response plan
D.Default privacy settings
E.Data minimization
AnswersD, E

Ensuring the most restrictive settings are enabled by default is a proactive control.

Why this answer

Data minimization and privacy-default configurations are foundational proactive PbD controls.

11
Multi-Selecteasy

Which THREE tasks are associated with 'Data Classification' during the life cycle?

Select 3 answers
A.Identifying sensitive data elements
B.Refreshing the server hardware
C.Applying policy controls based on labels
D.Backing up the database
E.Assigning classification labels
AnswersA, C, E

The first step in classification.

Why this answer

Identifying data, assigning a label, and applying specific policy rules are the steps in classification.

12
Multi-Selectmedium

Which TWO metrics are used to measure the effectiveness of data minimization?

Select 2 answers
A.Database query response time
B.Reduction in overall data volume
C.Increase in storage capacity
D.Decrease in records containing PII
E.User satisfaction scores
AnswersB, D

Less data stored is a direct indicator of minimization.

Why this answer

Reduction in total storage and the volume of PII-containing records are standard minimization metrics.

13
MCQeasy

When designing a data retention policy, which technical configuration in S3 best automates the process?

A.S3 Lifecycle policy
B.S3 Replication
C.S3 Inventory
D.S3 Object Lock
AnswerA

This automates deletion based on expiration dates.

Why this answer

S3 Lifecycle policies allow for automatic transition or deletion of objects based on age.

14
MCQeasy

When mapping data flows to identify privacy risks, a practitioner discovers that personal data is being transferred to a non-affiliated third party. What is the immediate requirement?

A.Request the third party to delete the data until a contract is signed.
B.Disable the API endpoint connecting to the third party to prevent further data exposure.
C.Validate that the transfer is supported by an appropriate legal basis and documented in the Records of Processing Activities (ROPA).
D.Immediately notify the supervisory authority of the data transfer.
AnswerC

ROPA documentation is a fundamental requirement under GDPR for all processing activities.

Why this answer

The inventory must identify the purpose and legal basis for the transfer before processing continues.

15
MCQeasy

What is the primary function of a 'Data Protection Impact Assessment' (DPIA) from an engineering perspective?

A.To test software security
B.To identify privacy risks in system design
C.To document legal agreements
D.To manage budget
AnswerB

It is a foundational privacy-by-design activity.

Why this answer

A DPIA helps identify privacy risks in the design phase so that controls can be implemented early.

16
Multi-Selectmedium

Which TWO of the following should be considered when aligning privacy strategy with broader business objectives?

Select 2 answers
A.The specific font used in corporate emails.
B.The organization's stated risk appetite.
C.Applicable legal and regulatory requirements.
D.The number of employees who take public transit.
E.The physical location of the office breakroom.
AnswersB, C

Privacy controls must be balanced against the organization's business goals and risk tolerance.

Why this answer

Alignment requires understanding the organization's risk appetite and the legal/regulatory landscape in which it operates.

17
MCQmedium

A privacy engineer is configuring Azure Data Factory to ensure PII is masked during integration. Which feature should be configured to apply dynamic data masking on SQL targets?

A.Azure Policy definition
B.SQL Dynamic Data Masking policies
C.Data Factory Mapping Data Flows
D.Azure Key Vault access policies
AnswerB

DDM is the direct tool for masking sensitive data at the database level.

Why this answer

Dynamic Data Masking (DDM) in Azure SQL Database allows masking sensitive data, which can be enforced via integration pipelines.

18
Multi-Selecteasy

Which TWO actions should a CDPSE take to demonstrate 'Privacy by Design' in a software project?

Select 2 answers
A.Use the same password for all database administrative users.
B.Only conduct a privacy review after the application has been deployed.
C.Include privacy requirements in the project specification and user stories.
D.Hide all privacy settings from the user to prevent tampering.
E.Conduct regular privacy testing during the development lifecycle.
AnswersC, E

Embedding requirements at the start is the definition of Privacy by Design.

Why this answer

Documenting privacy requirements and performing regular testing are essential evidence of Privacy by Design.

19
MCQmedium

An organization wants to monitor data access patterns for potential privacy violations. Which tool is best for detecting unusual access to PII tables?

A.Vulnerability assessment report
B.Database Activity Monitoring (DAM)
C.Network load balancer logs
D.Backup integrity check
AnswerB

DAM tools specifically track queries and row-level access patterns.

Why this answer

Database activity monitoring (DAM) or audit logs analyzed by a SIEM can flag anomalous access behavior.

20
MCQmedium

In Google Cloud Data Loss Prevention (DLP), which transformation method should be applied to a column containing email addresses to maintain format while ensuring privacy?

A.Redaction
B.Masking
C.Bucketization
D.Format-Preserving Encryption
AnswerD

This keeps the email format while encrypting the content.

Why this answer

Pseudonymization (using a crypto-hash or format-preserving encryption) allows the email structure to persist while the real identity is hidden.

21
MCQmedium

When conducting a privacy risk assessment, what is the significance of 'Data Lifecycle Management'?

A.It identifies privacy risks at each stage from collection to deletion.
B.It reduces the power consumption of the storage systems.
C.It determines the software development methodology.
D.It ensures that the database is always updated with the latest patches.
AnswerA

A risk assessment must cover the entire data lifecycle to be complete.

Why this answer

Understanding the lifecycle (collection to disposal) is necessary to ensure privacy is managed at every stage.

22
MCQhard

An organization is updating its privacy governance framework to comply with GDPR. The Data Protection Officer (DPO) needs to ensure that the accountability principle is met. Which of the following actions best demonstrates accountability?

A.Outsourcing all data processing activities to a third-party vendor.
B.Implementing a strong password policy for all employees.
C.Establishing a centralized Record of Processing Activities (ROPA).
D.Creating a public-facing website privacy notice.
AnswerC

The ROPA is a mandatory document under GDPR Article 30 that demonstrates a controller's accountability.

Why this answer

Accountability requires demonstrating compliance, which is best achieved through comprehensive documentation and audit trails.

23
MCQhard

During a DPIA (Data Protection Impact Assessment), a CDPSE identifies a high risk to data subjects due to the use of AI-driven profiling. What is the appropriate next step?

A.Proceed with the project and monitor for data breaches.
B.Consult with the Data Protection Officer (DPO) to determine if regulatory consultation is necessary.
C.Inform the public about the risk to maintain transparency.
D.Switch to a less intrusive profiling algorithm without re-evaluating the DPIA.
AnswerB

If risks remain high, the regulator may need to be involved per GDPR Article 36.

Why this answer

Consultation with the DPO is required when a DPIA identifies a high risk that cannot be mitigated by the project team.

24
MCQeasy

Why is it important to have a defined data retention policy as part of privacy governance?

A.To satisfy customer requests for free gifts.
B.To save costs on hardware maintenance.
C.To increase storage space.
D.To comply with data minimization and reduce risk.
AnswerD

Limiting data exposure is a primary goal of retention management.

Why this answer

Data minimization is a key privacy principle; retaining data only as long as necessary reduces risk.

25
MCQmedium

When encrypting data for long-term storage, which configuration is most important for privacy?

A.Disabling logging
B.Hardcoding the key
C.Frequent key rotation
D.Using a single global key
AnswerC

This limits the window of vulnerability for encrypted data.

Why this answer

Key rotation ensures that even if one key is compromised, the impact on the data is contained, and it supports long-term data protection.

26
MCQmedium

A privacy engineer is implementing differential privacy in a data analytics pipeline. To ensure the privacy budget remains intact over multiple queries, which technique should be applied?

A.Implementing k-anonymity on the original dataset
B.Increasing the sensitivity of the query function
C.Utilizing composition theorems to track cumulative privacy loss
D.Applying a fixed noise distribution regardless of query count
AnswerC

Composition theorems provide the mathematical framework to calculate the total privacy budget spent.

Why this answer

Composition theorems in differential privacy allow for the tracking of the cumulative privacy loss (epsilon) as multiple queries are performed on the same dataset.

27
MCQhard

A privacy engineer is implementing 'Tokenization' for credit card processing. Where should the 'vault' be situated to ensure the highest level of privacy?

A.In the same database as the application logs
B.In a physically or logically segregated environment
C.On the end-user's local workstation
D.Integrated directly into the web server memory
AnswerB

Segregation limits exposure and restricts access to the sensitive mapping database.

Why this answer

The vault containing the cleartext data must be isolated in a highly secure environment, often off-site or in a segregated network segment, to minimize the PCI-DSS scope.

28
MCQmedium

When conducting a Privacy Impact Assessment (PIA) for a new application, what is the role of 'Data Mapping'?

A.To provide encryption keys
B.To automate user consent
C.To purge old data records
D.To define the flow of PII throughout the application
AnswerD

Mapping shows where data moves and resides, critical for assessing risk.

Why this answer

Data mapping identifies the flow and storage locations, which is the foundation for conducting a meaningful PIA.

29
MCQmedium

When classifying data for privacy, what does a 'Restricted' label usually signify?

A.Data requiring limited access and enhanced protection
B.Data that can be shared publicly
C.Data that has no retention period
D.Data that is no longer needed
AnswerA

Restricted data is sensitive and needs limited, controlled access.

Why this answer

Restricted data is highly sensitive and requires strict access controls and specific handling to prevent unauthorized access.

30
MCQhard

When establishing a data disposal policy in Informatica Enterprise Data Catalog, what must be configured to ensure the disposal process is auditable?

A.Retention Period Policy
B.Delete Flag in Schema
C.Data Lineage Refresh
D.Audit Log Configuration
AnswerD

Enabling audit logs ensures that every deletion action is logged with a timestamp and user ID.

Why this answer

Audit logs within the Informatica platform ensure that data deletion events are recorded for compliance purposes.

31
Multi-Selectmedium

Which TWO methods are commonly used to achieve data minimization in a legacy database?

Select 2 answers
A.Mirroring the database
B.Implementing multi-factor authentication
C.Anonymization of records
D.Purging of obsolete data
E.Increasing database indexing
AnswersC, D

Removes the link to the identity, minimizing privacy risk.

Why this answer

Anonymization and data purging are direct methods to reduce the footprint of sensitive data.

32
Multi-Selecthard

Which THREE factors are critical for balancing privacy and utility when using k-anonymity?

Select 3 answers
A.Selection of quasi-identifiers
B.The chosen k-value
C.The total number of users
D.The generalization level
E.The server CPU count
AnswersA, B, D

These are the target of generalization.

Why this answer

Choosing the right quasi-identifiers, the value of k, and the generalization level are key to balancing privacy and utility.

33
MCQhard

Which governance mechanism is best suited for managing privacy risks in an agile development environment?

A.Appointing a privacy champion in each agile squad.
B.Requiring a full DPIA before every sprint.
C.Waiting for the security sign-off at the end of the project.
D.Hard-coding privacy requirements in the source code.
AnswerA

Embedded privacy champions provide real-time guidance.

Why this answer

Privacy champions embedded in squads ensure privacy is addressed throughout the agile cycle.

34
MCQmedium

A company needs to share customer demographics with a third party. Which technique allows for statistical analysis without revealing individual identities?

A.Differential privacy
B.Encryption
C.Data deletion
D.Pseudonymization
AnswerA

It provides a mathematical guarantee of privacy for individuals in a statistical dataset.

Why this answer

Differential privacy adds mathematical noise to prevent individual re-identification while preserving global trends.

35
MCQeasy

A practitioner is setting up data minimization. Which feature in Google Cloud Spanner helps ensure that data is stored in specific regions for local compliance?

A.Placement Policies
B.Encryption at Rest
C.Access Control Lists
D.Backup Retention
E.Schema Validation
AnswerA

This allows control over data geography.

Why this answer

Spanner uses 'Placement Policies' (or node configurations) to dictate where data is stored, supporting data residency compliance.

36
MCQmedium

Which component in an API gateway is used to ensure PII is not sent to third-party endpoints?

A.Rate limiting
B.Request transformation policy
C.OAuth 2.0 validation
D.CORS policy
AnswerB

This allows modifying the request payload to remove PII.

Why this answer

A request transformation policy can be used to scrub or redact specific headers or body fields before the request is forwarded.

37
MCQeasy

What is the primary function of a 'Data Inventory' in a privacy program?

A.To record the location, purpose, and sensitivity of personal data
B.To automatically encrypt files
C.To manage physical server hardware
D.To perform user authentication
AnswerA

An inventory provides the 'where, why, and what' for privacy management.

Why this answer

A data inventory acts as the master record of what data exists, where it is, and who owns it, serving as the basis for all life cycle activities.

38
MCQeasy

Which document should a CDPSE practitioner review first when establishing a new privacy governance program?

A.The list of current vendors.
B.The software inventory.
C.The existing business strategy and risk appetite.
D.The technical architecture diagram.
AnswerC

Privacy strategy must align with overall business risk appetite.

Why this answer

Organizational strategy defines the scope and objectives for privacy.

39
Multi-Selecthard

Which TWO outcomes result from effective data classification?

Select 2 answers
A.Improved application of security controls
B.Automated enforcement of retention policies
C.Increased server processing speed
D.Reduction in data volume
E.Improved user interface design
AnswersA, B

Allows applying tighter controls to sensitive data.

Why this answer

Classification enables targeted security controls and informs retention requirements.

40
Multi-Selecthard

Which THREE factors should be considered when defining a data retention schedule?

Select 3 answers
A.The number of concurrent users
B.Regulatory/Legal requirements
C.Storage server hardware cost
D.Statutory limitations periods
E.Operational business utility
AnswersB, D, E

Laws often dictate mandatory retention periods.

Why this answer

Legal requirements, business utility, and statutory limitations are the core drivers of any retention policy.

41
MCQmedium

Which of the following is the most effective method for evaluating the maturity of a privacy governance program?

A.Checking for the presence of a Privacy Impact Assessment template.
B.Reviewing the number of cookies on the public website.
C.Using an established Privacy Capability Maturity Model (PCMM).
D.Asking employees if they like the privacy policy.
AnswerC

PCMMs provide objective criteria for measuring program maturity.

Why this answer

Capability Maturity Models provide a structured approach to assessing maturity levels.

42
MCQeasy

What is the primary function of a privacy policy for external users?

A.To prevent all data collection.
B.To list the names of all employees.
C.To act as a legal contract for system performance.
D.To inform data subjects about the processing of their data.
AnswerD

Transparency is a core requirement of privacy laws like GDPR.

Why this answer

Transparency is the main goal of external-facing privacy policies.

43
MCQeasy

In the context of data classification, which metadata field is most critical for determining the disposal date?

A.Data Owner
B.Retention Start Date
C.Encryption Key ID
D.Classification Label
AnswerB

This is the specific field that drives the disposal timer.

Why this answer

The 'Created Date' or 'Last Modified' field is the baseline for calculating the disposal date based on a fixed retention period.

44
MCQhard

When configuring AWS Macie to perform data minimization, which configuration is required to prevent the service from scanning internal metadata fields that do not contain customer PII?

A.S3 Bucket Policy
B.S3 Exclusion Rules
C.Object Tagging
D.VPC Endpoint Configuration
E.IAM Policy Restriction
AnswerB

Exclusion rules allow filtering out specific buckets or paths from discovery.

Why this answer

Exclusion rules in AWS Macie allow users to define paths or patterns to ignore, minimizing the scan footprint.

45
MCQhard

You are auditing a system for 'Data Minimization'. Which discovery finding would be a primary concern?

A.Holding data beyond the retention period
B.Using AES-256 for encryption
C.Using a pseudonym for database keys
D.Encrypting backups
AnswerA

This violates the principle of storing only what is needed for as long as needed.

Why this answer

Storing PII longer than the legal or business necessity period is a direct violation of data minimization and retention principles.

46
MCQeasy

A privacy analyst is conducting a data map in ServiceNow. Which feature allows them to link a database table directly to a 'Processing Activity' record?

A.Workflow Designer
B.Configuration Item (CI) Relation
C.Business Service Mapping
D.Data Asset Mapping
AnswerD

This feature connects technical data sources to business processing activities.

Why this answer

ServiceNow's Privacy Management module uses 'Data Source Mapping' to link IT assets to business processes.

47
MCQmedium

When establishing a privacy steering committee, who should be included to ensure organizational support?

A.Only the Human Resources team.
B.External consultants only.
C.Only the IT staff.
D.Senior representatives from Legal, IT, HR, and Marketing.
AnswerD

Cross-functional representation ensures holistic policy ownership.

Why this answer

Executive sponsorship from cross-functional leadership is vital for authority.

48
MCQmedium

A CDPSE practitioner is integrating privacy controls into the SDLC. Which action best ensures privacy by design during the requirements gathering phase?

A.Installing a firewall after code completion.
B.Reviewing audit logs after the system launch.
C.Performing a DPIA after production deployment.
D.Conducting a privacy impact assessment on functional requirements.
AnswerD

Evaluating requirements for privacy risks is a core principle of Privacy by Design.

Why this answer

Privacy by design requires embedding privacy requirements early in the SDLC.

49
MCQmedium

Which feature in Microsoft Purview Information Protection should be used to automatically identify and classify documents containing credit card numbers as they are created?

A.eDiscovery search
B.Sensitivity labels with auto-labeling
C.Data Loss Prevention (DLP) policy
D.Information Rights Management (IRM)
AnswerB

This feature automatically applies protection based on detected sensitive info types.

Why this answer

Sensitivity labels combined with Auto-labeling policies allow for the automated identification and tagging of sensitive data based on content patterns.

50
MCQeasy

Which role is primarily responsible for the overall oversight of privacy governance within an organization to ensure that privacy policies are being followed?

A.Chief Financial Officer (CFO)
B.Chief Information Officer (CIO)
C.Data Protection Officer (DPO)
D.External Legal Counsel
AnswerC

The DPO is explicitly tasked with monitoring compliance and advising on data protection obligations.

Why this answer

The Data Protection Officer (DPO) or Chief Privacy Officer (CPO) is tasked with the independent oversight of the privacy program.

51
Multi-Selecthard

Which THREE factors influence the maturity level of an organization's privacy governance?

Select 3 answers
A.The amount of office space rented.
B.The consistency of policy application across the enterprise.
C.The number of employees in the IT department.
D.The degree of integration of privacy in automated processes.
E.The depth of continuous monitoring and reporting.
AnswersB, D, E

Consistent application indicates a mature, managed program.

Why this answer

Policy adoption, process automation, and monitoring depth define maturity.

52
MCQeasy

A privacy engineer is auditing log data. Which action best aligns with data minimization requirements for logs?

A.Configuring log masking rules
B.Centralizing logs in a SIEM
C.Enabling full verbose logging
D.Setting a long retention policy
AnswerA

Masking removes or replaces PII in logs.

Why this answer

Log masking or filtering ensures that sensitive information is not persisted in log files.

53
Multi-Selecthard

Which THREE items should be included in a Privacy Impact Assessment (PIA) report?

Select 3 answers
A.The cafeteria's weekly menu.
B.The names of all employees in the marketing department.
C.Assessment of privacy risks to individuals.
D.Description of the personal data being processed.
E.Proposed mitigation measures for identified risks.
AnswersC, D, E

Risk assessment is the core of the PIA.

Why this answer

A PIA must identify the data, the risks, and the mitigation plan.

54
MCQeasy

What is the main purpose of a Privacy Impact Assessment (PIA) in the governance framework?

A.To identify and mitigate privacy risks early in the process.
B.To calculate the financial costs of IT staff.
C.To increase the speed of product deployment.
D.To fulfill a mandatory public relations requirement.
AnswerA

Proactive risk identification is the core purpose of a PIA.

Why this answer

PIAs identify and mitigate privacy risks before processing begins.

55
MCQhard

When a third-party vendor reports a data breach, what is the first step the CDPSE should take?

A.Activate the incident response plan to assess the scope and notify affected individuals if required.
B.Review the vendor's insurance policy coverage.
C.Demand the vendor perform an independent audit of their systems.
D.Suspend all services provided by the vendor immediately.
AnswerA

The IRP provides the necessary structure for handling the breach effectively.

Why this answer

The immediate step is to follow the Incident Response Plan (IRP) to assess the impact and initiate containment.

56
Multi-Selecteasy

Which THREE documents are typically required for compliance with global privacy regulations?

Select 3 answers
A.Data Processing Agreements (DPAs) with third-party vendors.
B.A daily log of all staff internet activity.
C.A list of all company-issued laptops.
D.A public-facing privacy notice.
E.A record of processing activities (ROPA).
AnswersA, D, E

DPAs are legally required for managing third-party data processing.

Why this answer

A privacy notice, ROPA, and data processing agreements are standard compliance artifacts.

57
MCQmedium

A privacy engineer is configuring Azure SQL Database to ensure that sensitive columns containing PII are hidden from non-privileged users. Which feature should be implemented to achieve dynamic data masking?

A.Always Encrypted
B.Row-Level Security
C.Transparent Data Encryption
D.Dynamic Data Masking
AnswerD

DDM is the specific SQL feature designed to mask sensitive data in the result set of a query.

Why this answer

Dynamic Data Masking (DDM) limits sensitive data exposure by masking it to non-privileged users at the query execution level.

58
Multi-Selectmedium

Which TWO actions help improve privacy in a containerized environment (e.g., Kubernetes)?

Select 2 answers
A.Increasing container replica count
B.Kubernetes Secrets management
C.Using public container registries
D.Disabling logging
E.Kubernetes Network Policies
AnswersB, E

Protects keys and passwords.

Why this answer

Network policies and secrets management are essential for limiting access and protecting sensitive data in containers.

59
MCQhard

When using Varonis to identify 'stale' data for minimization, what criteria must be defined to avoid false positives?

A.File size threshold
B.Last Accessed Date
C.File extension
D.User account status
AnswerB

This is the primary metric for defining data as 'stale' or inactive.

Why this answer

Varonis requires defining the 'Last Accessed' timeframe to distinguish between actively used data and candidates for deletion.

60
MCQeasy

Which of the following is an example of a Privacy-Enhancing Technology (PET) that focuses on data minimization?

A.Synthetic data generation
B.Hardware Security Modules (HSMs)
C.AES-256 Encryption
D.Vulnerability scanning
AnswerA

Synthetic data allows for analysis without using real PII.

Why this answer

Synthetic data generation creates new data that mimics the properties of real data without containing the original PII.

61
MCQmedium

Which of the following activities is essential for maintaining effective privacy governance over third-party processors?

A.Only hiring large, well-known vendors.
B.Including mandatory privacy clauses in contracts and auditing compliance.
C.Trusting the processor's own marketing brochures.
D.Giving the vendor full access to the corporate network.
AnswerB

Contractual accountability and audit rights are essential for third-party governance.

Why this answer

Due diligence and contractual clauses are critical for third-party risk management.

62
MCQmedium

In the context of Privacy by Design, what is the primary role of an 'Access Control Matrix' in a microservices architecture?

A.Principle of least privilege implementation
B.Log aggregation
C.Threat modeling
D.Data classification
AnswerA

The matrix ensures granular control based on need-to-know.

Why this answer

It explicitly maps subjects to objects and permissions, ensuring the principle of least privilege.

63
Multi-Selectmedium

Which THREE of the following are considered standard 'Privacy-Enhancing Technologies' (PETs) used for data protection in analytics?

Select 3 answers
A.Network Intrusion Detection System
B.Differential Privacy
C.Secure Multi-Party Computation
D.Full-Disk Encryption
E.Homomorphic Encryption
AnswersB, C, E

Adds mathematical noise to protect individual identity.

Why this answer

Differential privacy, secure multi-party computation, and homomorphic encryption are core PETs designed for privacy-preserving computation.

64
Multi-Selectmedium

Which TWO of the following should be considered when aligning privacy strategy with the business?

Select 2 answers
A.The local cafeteria menu.
B.The current market share of competitors.
C.The weather forecast in the corporate headquarters.
D.Primary business objectives and growth plans.
E.The organizational risk appetite.
AnswersD, E

Privacy supports rather than hinders business objectives.

Why this answer

Risk appetite and business goals are the two primary anchors for privacy strategy.

65
Multi-Selecthard

When designing a privacy-preserving data pipeline, which TWO strategies help achieve 'Data Minimization'?

Select 2 answers
A.Disabling all audit logging
B.Truncating or hashing identifiers before ingestion
C.Increasing the retention period for backups
D.Storing all raw data in a data lake for future use
E.Aggregating data points to a higher level of abstraction
AnswersB, E

This reduces the granularity of data at the entry point of the pipeline.

Why this answer

Data aggregation and truncation/hashing are effective ways to reduce the granularity of data and minimize the presence of identifiable information.

66
MCQmedium

During a Data Mapping exercise, the CDPSE discovers that a legacy database stores PII in cleartext. The system is scheduled for decommissioning in 18 months. What is the most appropriate privacy risk mitigation strategy?

A.Accept the risk formally and do nothing until the system is shut down.
B.Anonymize all records in the database immediately.
C.Decommission the database immediately regardless of business impact.
D.Apply field-level encryption or database transparent data encryption (TDE) as a compensating control.
AnswerD

Encryption reduces the impact of a potential breach while awaiting decommissioning.

Why this answer

When immediate re-engineering is not feasible, compensating controls such as encryption or access restriction must be applied to mitigate the risk until decommissioning.

67
MCQhard

An organization is evaluating a cloud service provider (CSP) for storing sensitive customer data. Under the GDPR, what is the most critical step the CDPSE must perform to manage third-party privacy risk?

A.Execute a Data Processing Agreement (DPA) that mandates adherence to specific privacy instructions.
B.Perform a penetration test on the CSP's multi-tenant environment.
C.Verify the CSP's physical data center location to ensure it is within the EU.
D.Review the CSP's SOC 2 Type II report for general system reliability.
AnswerA

A DPA is mandatory for ensuring the processor handles data according to the controller's requirements.

Why this answer

The CDPSE must ensure a Data Processing Agreement (DPA) is in place, as it is the legal mechanism defining the responsibilities of the data processor.

68
Multi-Selecthard

A privacy engineer is implementing differential privacy on a dataset using Google Cloud's Differential Privacy library. Which THREE configuration steps are critical for minimizing re-identification risk?

Select 3 answers
A.Choosing a random seed that is publicly known
B.Defining appropriate sensitivity bounds for the input data
C.Increasing the dataset size to infinite
D.Setting a low Epsilon value for higher privacy loss limit
E.Enabling Delta parameter for probabilistic privacy guarantees
AnswersB, D, E

Sensitivity bounds dictate the amount of noise required.

Why this answer

Differential privacy involves setting epsilon, delta, and ensuring proper noise injection.

69
MCQeasy

Which of the following is a key objective of a data retention policy?

A.To minimize the amount of data stored and reduce risk
B.To maximize data availability
C.To increase storage capacity requirements
D.To keep all data forever for future AI training
AnswerA

Retention policies limit the time data is held, reducing liability.

Why this answer

The primary objective is to maintain data only as long as necessary for business or legal reasons, supporting minimization.

70
MCQhard

When implementing differential privacy in a data analytics pipeline, what is the primary technical trade-off the engineer must balance?

A.Anonymization speed and data volume
B.Privacy budget and accuracy
C.Encryption speed and latency
D.Scalability and storage costs
AnswerB

Differential privacy requires balancing the noise level (privacy) against result utility (accuracy).

Why this answer

The epsilon parameter controls the privacy budget, affecting the accuracy of the output and the level of privacy protection.

71
Multi-Selectmedium

Which TWO security measures are most effective in protecting against unauthorized access to PII?

Select 2 answers
A.Requiring multi-factor authentication (MFA) for access to databases containing PII.
B.Implementing encryption for personal data both in transit and at rest.
C.Removing all passwords from the system to simplify access.
D.Hiding the database server in a locked physical room.
E.Increasing the number of help desk staff.
AnswersA, B

MFA adds a critical layer of security to prevent unauthorized access.

Why this answer

MFA and encryption at rest/in transit are the standard technical controls to protect against unauthorized access.

72
MCQeasy

In the privacy lifecycle, what does the term 'Data Collection' primarily involve?

A.Destroying records
B.Backing up data
C.Obtaining and recording personal data from the subject
D.Encrypting data in transit
AnswerC

Collection refers to the gathering phase.

Why this answer

Data collection is the entry point where PII is gathered from subjects, requiring notice and consent.

73
Multi-Selectmedium

Which TWO of the following are key privacy controls in an AWS environment?

Select 2 answers
A.AWS CloudFront
B.Amazon Macie
C.AWS Key Management Service
D.AWS Auto Scaling
E.AWS Glue Schema Registry
AnswersB, C

Identifies PII in S3.

Why this answer

AWS Macie (for discovery) and AWS KMS (for encryption/control) are critical privacy tools.

74
MCQhard

In a data warehouse, which technique is most effective for protecting PII during the ETL (Extract, Transform, Load) process while still allowing analytics?

A.Using access control lists at the reporting layer
B.Deleting the data during extraction
C.Encrypting the entire database
D.Masking the data during the transformation phase
AnswerD

Masking at ETL time balances the need for analytics with privacy protection.

Why this answer

Data masking during the transformation phase (ETL) allows analytical tools to process the records without seeing the actual PII.

75
MCQmedium

A CDPSE practitioner is conducting a Privacy Impact Assessment (PIA) for a new marketing application that uses behavioral tracking. Which action should be prioritized to ensure compliance with privacy-by-design principles?

A.Enable automated data deletion scripts after the application deployment phase.
B.Incorporate data minimization and purpose limitation settings during the architectural design phase.
C.Configure the database to encrypt all fields regardless of sensitivity to ensure maximum protection.
D.Conduct a post-implementation audit to identify potential data leakage points.
AnswerB

Privacy-by-design necessitates embedding privacy-preserving features during the design phase.

Why this answer

Privacy-by-design requires integrating privacy controls at the development stage rather than as an afterthought.

Page 1 of 3

Page 2

All pages