Courseiva
Back to ISACA Certified Data Privacy Solutions Engineer (CDPSE) (CDPSE) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise ISACA Certified Data Privacy Solutions Engineer (CDPSE) (CDPSE) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CDPSE
exam code
ISACA
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CDPSE topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which THREE factors are critical for balancing privacy and utility when using k-anonymity?

Question 2mediummulti select
Full question →

Which TWO actions help improve privacy in a containerized environment (e.g., Kubernetes)?

Question 3hardmulti select
Full question →

A privacy engineer is implementing differential privacy on a dataset using Google Cloud's Differential Privacy library. Which THREE configuration steps are critical for minimizing re-identification risk?

Question 4hardmulti select
Full question →

Which THREE factors should be considered when defining a data retention schedule?

Question 5mediummulti select
Full question →

Which TWO options represent common risks when data life cycle management is not implemented?

Question 6mediummulti select
Full question →

Which TWO metrics are used to measure the effectiveness of data minimization?

Question 7easymulti select
Full question →

Which TWO attributes are essential to include in a data mapping register for privacy compliance?

Question 8mediummulti select
Full question →

Which TWO methods are commonly used to achieve data minimization in a legacy database?

Question 9easymulti select
Full question →

Which THREE tasks are associated with 'Data Classification' during the life cycle?

Question 10hardmulti select
Full question →

Which TWO outcomes result from effective data classification?

Question 11hardmulti select
Full question →

Which THREE components should be included in a data inventory to ensure it is actionable for DSR (Data Subject Request) fulfillment?

Question 12easymulti select
Full question →

Which THREE documents are typically required for compliance with global privacy regulations?

Question 13mediummulti select
Full question →

Which TWO of the following are key privacy engineering objectives when designing a system that processes sensitive health data?

Question 14mediummulti select
Full question →

Which THREE techniques effectively protect data during the 'use' phase of the life cycle?

Question 15mediummulti select
Full question →

Which TWO of the following should be considered when aligning privacy strategy with broader business objectives?

Question 16hardmulti select
Full question →

Which THREE factors influence the maturity level of an organization's privacy governance?

Question 17mediummulti select
Full question →

Which TWO technical controls are effective for limiting the scope of PII access in a cloud-based SQL environment?

Question 18hardmulti select
Full question →

Which THREE privacy engineering activities are performed during the 'Maintenance' phase of the system lifecycle?

Question 19mediummulti select
Full question →

Which TWO techniques should be used to protect PII in non-production environments to ensure the data remains non-identifiable?

Question 20mediummulti select
Full question →

When implementing Privacy by Design (PbD) in a new mobile application, which TWO of the following are considered proactive technical controls?

These CDPSE practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CDPSE questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.