Courseiva
Privacy Risk Management And CompliancehardMultiple ChoiceObjective-mapped

CDPSE Privacy Risk Management And Compliance Practice Question

Your organization is preparing for a CCPA/CPRA audit. You are asked to verify the 'Right to Opt-Out of Sale or Sharing' implementation. Which technical requirement must be validated to ensure compliance with the Global Privacy Control (GPC) signal?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The server must programmatically honor the GPC signal as a valid opt-out request without requiring user interaction.

The CPRA regulations explicitly require that businesses recognize browser-based opt-out signals, such as the GPC, as a valid request to opt-out of the sale or sharing of personal information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The system must log the user's IP address to verify their residency status before honoring the signal.

    Why it's wrong here

    Excessive data collection to verify residency for an opt-out signal is generally discouraged.

  • The website must automatically trigger a manual consent banner upon detecting the signal.

    Why it's wrong here

    The signal should act as a functional opt-out, not just trigger a banner.

  • The server must programmatically honor the GPC signal as a valid opt-out request without requiring user interaction.

    Why this is correct

    The CPRA requires that opt-out preference signals be honored automatically.

  • The user must be authenticated via OAuth2 to confirm their identity before the signal is processed.

    Why it's wrong here

    Opt-out requests should be processed even for unauthenticated users.

About these practice questions

This CDPSE question is part of Courseiva's 215-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official ISACA exam blueprint

This CDPSE practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CDPSE exam.