Courseiva

CDPSE · domain

Privacy Risk Management And Compliance

Practise ISACA Certified Data Privacy Solutions Engineer (CDPSE) (CDPSE) Privacy Risk Management And Compliance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

45 questions12 easy18 medium15 hard

Focused practice

Practice Privacy Risk Management And Compliance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Privacy Risk Management And Compliance

Privacy Risk Management And Compliance questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Privacy Risk Management And Compliance exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Privacy Risk Management And Compliance questions (45)

Click any question to see the full explanation, or start a practice session above.

1

A multinational company is transferring data between its US and EU subsidiaries. Which mechanism is most effective for ensuring cross-border data transfer compliance after the invalidation of previous frameworks?

Medium
2

An organization's privacy policy is updated to reflect a new vendor. What is the most important follow-up action?

Easy
3

When mapping data flows to identify privacy risks, a practitioner discovers that personal data is being transferred to a non-affiliated third party. What is the immediate requirement?

Easy
4

Which TWO actions should a CDPSE take to demonstrate 'Privacy by Design' in a software project?

Easy
5

When conducting a privacy risk assessment, what is the significance of 'Data Lifecycle Management'?

Medium
6

During a DPIA (Data Protection Impact Assessment), a CDPSE identifies a high risk to data subjects due to the use of AI-driven profiling. What is the appropriate next step?

Hard
7

When a third-party vendor reports a data breach, what is the first step the CDPSE should take?

Hard
8

Which THREE documents are typically required for compliance with global privacy regulations?

Easy
9

During a Data Mapping exercise, the CDPSE discovers that a legacy database stores PII in cleartext. The system is scheduled for decommissioning in 18 months. What is the most appropriate privacy risk mitigation strategy?

Medium
10

An organization is evaluating a cloud service provider (CSP) for storing sensitive customer data. Under the GDPR, what is the most critical step the CDPSE must perform to manage third-party privacy risk?

Hard
11

Which TWO security measures are most effective in protecting against unauthorized access to PII?

Medium
12

A CDPSE practitioner is conducting a Privacy Impact Assessment (PIA) for a new marketing application that uses behavioral tracking. Which action should be prioritized to ensure compliance with privacy-by-design principles?

Medium
13

In the event of a personal data breach, which TWO actions are required to satisfy the notification obligations under many modern privacy regulations (e.g., GDPR)?

Medium
14

Which TWO actions should a CDPSE prioritize when assessing a vendor for privacy compliance?

Medium
15

A company is implementing a new CCPA compliance tool. Which feature should be used to automate the 'Right to Opt-Out' request process for web visitors?

Medium
16

A third-party vendor is providing an API integration for customer support. As a CDPSE, what is the first step you should take in the third-party privacy risk management lifecycle?

Easy
17

Which TWO factors must be considered when determining if a cross-border data transfer is lawful under GDPR?

Hard
18

Which THREE elements are essential in a Data Protection Impact Assessment (DPIA) report?

Medium
19

When managing privacy risks, which TWO approaches help in 'Data Minimization'?

Medium
20

A CDPSE practitioner is conducting a Privacy Impact Assessment (PIA) for a new marketing application. During the data flow mapping phase, they identify that PII is being transferred to a cloud service provider located in a non-equivalent jurisdiction. Which action should the practitioner prioritize to ensure compliance with the GDPR?

Medium
21

Which THREE types of personal data are typically considered 'special category' or 'sensitive' data under privacy regulations?

Hard
22

A company is using an automated system to make credit decisions. What is the main privacy concern regarding the 'Right to Explanation'?

Hard
23

An organization is implementing a 'Privacy by Design' framework for a machine learning model used to predict customer churn. Which technique should be utilized to minimize privacy risk while maintaining model utility?

Hard
24

When establishing a Privacy Risk Assessment methodology, which TWO components are essential to ensure the assessment is repeatable and defensible?

Medium
25

A company is considering the use of a data broker. Which privacy risk is most significant?

Hard
26

What is the first step in creating a data inventory for a privacy program?

Easy
27

During an audit, it is found that an application logs user session tokens including sensitive user IDs. What is the correct privacy recommendation?

Medium
28

How can a CDPSE ensure that personal data is only kept for as long as necessary?

Medium
29

What is the primary purpose of a Data Privacy Impact Assessment (DPIA)?

Easy
30

Your organization is preparing for a CCPA/CPRA audit. You are asked to verify the 'Right to Opt-Out of Sale or Sharing' implementation. Which technical requirement must be validated to ensure compliance with the Global Privacy Control (GPC) signal?

Hard
31

Which THREE activities should be included in an organization's privacy compliance monitoring program to identify potential regulatory non-compliance?

Hard
32

A CDPSE is reviewing a vendor's privacy controls. Which finding would be considered a major non-compliance risk?

Hard
33

A CDPSE is advising on a website redesign. What is the most important privacy-related feature for a contact form?

Easy
34

Which technique should be used to protect personal data during software testing?

Medium
35

A CDPSE is auditing a legacy application that stores passwords in plain text. What is the most effective immediate mitigation strategy?

Hard
36

When evaluating a third-party's security, what should the CDPSE focus on to ensure effective privacy risk management?

Hard
37

A company wants to collect geolocation data from mobile users. Which privacy principle should be applied first?

Easy
38

Which THREE steps are vital when responding to a Data Subject Access Request (DSAR)?

Hard
39

Which of the following is the most critical element to include in a Privacy Notice under GDPR to fulfill the 'Right to be Informed'?

Easy
40

A company is preparing for a CCPA audit. Which internal process is most important to demonstrate compliance regarding the 'Right to Know'?

Medium
41

A company is implementing a Bring Your Own Device (BYOD) policy. What is the primary privacy challenge?

Medium
42

A multinational company is evaluating a SaaS solution. As a CDPSE, you must ensure that the vendor's data retention policy aligns with your organization's internal privacy standards. Where should this requirement be formally documented?

Medium
43

Which document should a CDPSE review to understand the organization's legal basis for processing employee personal data?

Easy
44

What does 'Privacy by Default' imply regarding system configuration?

Easy
45

Which THREE items should be included in a Privacy Policy that aligns with global transparency requirements?

Hard

Frequently asked questions

What does the Privacy Risk Management And Compliance domain cover on the CDPSE exam?
Privacy Risk Management And Compliance questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 45 Privacy Risk Management And Compliance questions in the CDPSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Privacy Risk Management And Compliance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ISACA Certified Data Privacy Solutions Engineer (CDPSE) (CDPSE) Privacy Risk Management And Compliance Practice Questions