Isaca

CDPSE practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 162-question bank.

Provider
Isaca
Question bank
162
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CDPSE, a certification listed under Isaca. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isaca. The certification credential is issued by Isaca, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    What should be the PRIMARY consideration of a multinational organization deploying a user and entity behavior analytics (UEBA) tool to centralize the monitoring of anomalous employee behavior?

    Choose one answer.

    • Cross-border data transfer
    • Support staff availability and skill set
    • User notification
    • Global public interest
  2. Question 2 · 1

    Which of the following is an IT privacy practitioner’s BEST recommendation to reduce privacy risk before an organization provides personal data to a third party?

    Choose one answer.

    • Tokenization
    • Aggregation
    • Anonymization
    • Encryption
  3. Question 3 · 1

    An online retail company is trying to determine how to handle users’ data if they unsubscribe from marketing emails generated from the website. Which of the following is the BEST approach for handling personal data that has been restricted?

    Choose one answer.

    • Encrypt users’ information so it is inaccessible to the marketing department.
    • Reference the privacy policy to see if the data is truly restricted.
    • Remove users’ information and accounts from the system.
    • Flag users’ email addresses to make sure they do not receive promotional information.
  4. Question 4 · 1

    Which of the following should be done FIRST when developing an organization-wide strategy to address data privacy risk?

    Choose one answer.

    • Obtain executive support.
    • Develop a data privacy policy.
    • Gather privacy requirements from legal counsel.
    • Create a comprehensive data inventory.
  5. Question 5 · 1

    Which of the following is the BEST way to protect the privacy of data stored on a laptop in case of loss or theft?

    Choose one answer.

    • Strong authentication controls
    • Remote wipe
    • Regular backups
    • Endpoint encryption
  6. Question 6 · 1

    Which of the following should be of GREATEST concern when an organization wants to store personal data in the cloud?

    Choose one answer.

    • The organization’s potential legal liabilities related to the data
    • The data recovery capabilities of the storage provider
    • The data security policies and practices of the storage provider
    • Any vulnerabilities identified in the cloud system
  7. Question 7 · 1

    Which of the following helps define data retention time is a stream-fed data lake that includes personal data?

    Choose one answer.

    • Information security assessments
    • Privacy impact assessments (PIAs)
    • Data privacy standards
    • Data lake configuration
  8. Question 8 · 1

    As part of a major data discovery initiative to identify personal data across the organization, the project team has identified the proliferation of personal data held as unstructured data as a major risk. What should be done FIRST to address this situation?

    Choose one answer.

    • Identify sensitive unstructured data at the point of creation.
    • Classify sensitive unstructured data.
    • Identify who has access to sensitive unstructured data.
    • Assign an owner to sensitive unstructured data.
  9. Question 9 · 1

    Which types of controls need to be applied to ensure accuracy at all stages of processing, storage, and deletion throughout the data life cycle?

    Choose one answer.

    • Processing flow controls
    • Time-based controls
    • Purpose limitation controls
    • Integrity controls
  10. Question 10 · 1

    Which of the following is the BEST approach to minimize privacy risk when collecting personal data?

    Choose one answer.

    • Use a third party to collect, store, and process the data.
    • Collect data through a secure organizational web server.
    • Collect only the data necessary to meet objectives.
    • Aggregate the data immediately upon collection.
  11. Question 11 · 1

    Which of the following should be done FIRST to establish privacy by design when developing a contact-tracing application?

    Choose one answer.

    • Conduct a privacy impact assessment (PIA).
    • Conduct a development environment review.
    • Identify privacy controls for the application.
    • Identify differential privacy techniques.
  12. Question 12 · 1

    Which of the following is MOST important when designing application programming interfaces (APIs) that enable mobile device applications to access personal data?

    Choose one answer.

    • The user’s ability to select, filter, and transform data before it is shared
    • Umbrella consent for multiple applications by the same developer
    • User consent to share personal data
    • Unlimited retention of personal data by third parties
  13. Question 13 · 1

    A migration of personal data involving a data source with outdated documentation has been approved by senior management. Which of the following should be done NEXT?

    Choose one answer.

    • Review data flow post migration.
    • Ensure appropriate data classification.
    • Engage an external auditor to review the source data.
    • Check the documentation version history for anomalies.
  14. Question 14 · 1

    Which of the following is the best way to reduce the risk of compromised credentials when an organization allows employees to have remote access?

    Choose one answer.

    • Enable whole disk encryption on remote devices.
    • Purchase an endpoint detection and response (EDR) tool.
    • Implement multi-factor authentication.
    • Deploy single sign-on with complex password requirements.
  15. Question 15 · 1

    Which of the following is the PRIMARY objective of privacy incident response?

    Choose one answer.

    • To ensure data subjects impacted by privacy incidents are notified.
    • To reduce privacy risk to the lowest possible level
    • To mitigate the impact of privacy incidents
    • To optimize the costs associated with privacy incidents

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free