CDPSE · domain
Privacy Risk Management And Compliance
Practise ISACA Certified Data Privacy Solutions Engineer (CDPSE) (CDPSE) Privacy Risk Management And Compliance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Privacy Risk Management And Compliance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Privacy Risk Management And Compliance
Privacy Risk Management And Compliance questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Privacy Risk Management And Compliance exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Privacy Risk Management And Compliance questions (45)
Click any question to see the full explanation, or start a practice session above.
A multinational company is transferring data between its US and EU subsidiaries. Which mechanism is most effective for ensuring cross-border data transfer compliance after the invalidation of previous frameworks?
Medium2An organization's privacy policy is updated to reflect a new vendor. What is the most important follow-up action?
Easy3When mapping data flows to identify privacy risks, a practitioner discovers that personal data is being transferred to a non-affiliated third party. What is the immediate requirement?
Easy4Which TWO actions should a CDPSE take to demonstrate 'Privacy by Design' in a software project?
Easy5When conducting a privacy risk assessment, what is the significance of 'Data Lifecycle Management'?
Medium6During a DPIA (Data Protection Impact Assessment), a CDPSE identifies a high risk to data subjects due to the use of AI-driven profiling. What is the appropriate next step?
Hard7When a third-party vendor reports a data breach, what is the first step the CDPSE should take?
Hard8Which THREE documents are typically required for compliance with global privacy regulations?
Easy9During a Data Mapping exercise, the CDPSE discovers that a legacy database stores PII in cleartext. The system is scheduled for decommissioning in 18 months. What is the most appropriate privacy risk mitigation strategy?
Medium10An organization is evaluating a cloud service provider (CSP) for storing sensitive customer data. Under the GDPR, what is the most critical step the CDPSE must perform to manage third-party privacy risk?
Hard11Which TWO security measures are most effective in protecting against unauthorized access to PII?
Medium12A CDPSE practitioner is conducting a Privacy Impact Assessment (PIA) for a new marketing application that uses behavioral tracking. Which action should be prioritized to ensure compliance with privacy-by-design principles?
Medium13In the event of a personal data breach, which TWO actions are required to satisfy the notification obligations under many modern privacy regulations (e.g., GDPR)?
Medium14Which TWO actions should a CDPSE prioritize when assessing a vendor for privacy compliance?
Medium15A company is implementing a new CCPA compliance tool. Which feature should be used to automate the 'Right to Opt-Out' request process for web visitors?
Medium16A third-party vendor is providing an API integration for customer support. As a CDPSE, what is the first step you should take in the third-party privacy risk management lifecycle?
Easy17Which TWO factors must be considered when determining if a cross-border data transfer is lawful under GDPR?
Hard18Which THREE elements are essential in a Data Protection Impact Assessment (DPIA) report?
Medium19When managing privacy risks, which TWO approaches help in 'Data Minimization'?
Medium20A CDPSE practitioner is conducting a Privacy Impact Assessment (PIA) for a new marketing application. During the data flow mapping phase, they identify that PII is being transferred to a cloud service provider located in a non-equivalent jurisdiction. Which action should the practitioner prioritize to ensure compliance with the GDPR?
Medium21Which THREE types of personal data are typically considered 'special category' or 'sensitive' data under privacy regulations?
Hard22A company is using an automated system to make credit decisions. What is the main privacy concern regarding the 'Right to Explanation'?
Hard23An organization is implementing a 'Privacy by Design' framework for a machine learning model used to predict customer churn. Which technique should be utilized to minimize privacy risk while maintaining model utility?
Hard24When establishing a Privacy Risk Assessment methodology, which TWO components are essential to ensure the assessment is repeatable and defensible?
Medium25A company is considering the use of a data broker. Which privacy risk is most significant?
Hard26What is the first step in creating a data inventory for a privacy program?
Easy27During an audit, it is found that an application logs user session tokens including sensitive user IDs. What is the correct privacy recommendation?
Medium28How can a CDPSE ensure that personal data is only kept for as long as necessary?
Medium29What is the primary purpose of a Data Privacy Impact Assessment (DPIA)?
Easy30Your organization is preparing for a CCPA/CPRA audit. You are asked to verify the 'Right to Opt-Out of Sale or Sharing' implementation. Which technical requirement must be validated to ensure compliance with the Global Privacy Control (GPC) signal?
Hard31Which THREE activities should be included in an organization's privacy compliance monitoring program to identify potential regulatory non-compliance?
Hard32A CDPSE is reviewing a vendor's privacy controls. Which finding would be considered a major non-compliance risk?
Hard33A CDPSE is advising on a website redesign. What is the most important privacy-related feature for a contact form?
Easy34Which technique should be used to protect personal data during software testing?
Medium35A CDPSE is auditing a legacy application that stores passwords in plain text. What is the most effective immediate mitigation strategy?
Hard36When evaluating a third-party's security, what should the CDPSE focus on to ensure effective privacy risk management?
Hard37A company wants to collect geolocation data from mobile users. Which privacy principle should be applied first?
Easy38Which THREE steps are vital when responding to a Data Subject Access Request (DSAR)?
Hard39Which of the following is the most critical element to include in a Privacy Notice under GDPR to fulfill the 'Right to be Informed'?
Easy40A company is preparing for a CCPA audit. Which internal process is most important to demonstrate compliance regarding the 'Right to Know'?
Medium41A company is implementing a Bring Your Own Device (BYOD) policy. What is the primary privacy challenge?
Medium42A multinational company is evaluating a SaaS solution. As a CDPSE, you must ensure that the vendor's data retention policy aligns with your organization's internal privacy standards. Where should this requirement be formally documented?
Medium43Which document should a CDPSE review to understand the organization's legal basis for processing employee personal data?
Easy44What does 'Privacy by Default' imply regarding system configuration?
Easy45Which THREE items should be included in a Privacy Policy that aligns with global transparency requirements?
HardOther domains
All CDPSE exam domains
Frequently asked questions
- What does the Privacy Risk Management And Compliance domain cover on the CDPSE exam?
- Privacy Risk Management And Compliance questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 45 Privacy Risk Management And Compliance questions in the CDPSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Privacy Risk Management And Compliance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.