Sign In
Home/ISACA/CDPSE/Free questions

CDPSE — Free Practice Questions

10 free sample questions from a bank of 229, with the correct answers and explanations. No signup required — start practising right now.

1What should be the PRIMARY consideration of a multinational organization deploying a user and entity behavior analytics (UEBA) tool to centralize the monitoring of anomalous employee behavior?
  • Cross-border data transfer
  • Support staff availability and skill set
  • User notification
  • Global public interest
Answer: A
2Which of the following is the PRIMARY reason to complete a privacy impact assessment (PIA)?
  • To comply with consumer regulatory requirements
  • To establish privacy breach response procedures
  • To classify personal data
  • To understand privacy risks
Answer: A
3How can an organization BEST ensure its vendors are complying with data privacy requirements defined in their contracts?
  • Review self-attestations of compliance provided by vendor management.
  • Obtain independent assessments of the vendors’ data management processes.
  • Perform penetration tests of the vendors’ data security.
  • Compare contract requirements against vendor deliverables.
Answer: D
4Before executive leadership approves a new data privacy policy, it is MOST important to ensure:
  • a training program is developed.
  • a privacy committee is established.
  • a distribution methodology is identified.
  • a legal review is conducted.
Answer: B
5Which of the following is an IT privacy practitioner’s BEST recommendation to reduce privacy risk before an organization provides personal data to a third party?
  • Tokenization
  • Aggregation
  • Anonymization
  • Encryption
Answer: C
6Which of the following is a responsibility of the audit function in helping an organization address privacy compliance requirements?
  • Approving privacy impact assessments (PIAs)
  • Validating the privacy framework
  • Managing privacy notices provided to customers
  • Establishing employee privacy rights and consent
Answer: D
7An online retail company is trying to determine how to handle users’ data if they unsubscribe from marketing emails generated from the website. Which of the following is the BEST approach for handling personal data that has been restricted?
  • Encrypt users’ information so it is inaccessible to the marketing department.
  • Reference the privacy policy to see if the data is truly restricted.
  • Remove users’ information and accounts from the system.
  • Flag users’ email addresses to make sure they do not receive promotional information.
Answer: C
8Which of the following should be done FIRST when developing an organization-wide strategy to address data privacy risk?
  • Obtain executive support.
  • Develop a data privacy policy.
  • Gather privacy requirements from legal counsel.
  • Create a comprehensive data inventory.
Answer: A
9Which of the following is the BEST way to protect the privacy of data stored on a laptop in case of loss or theft?
  • Strong authentication controls
  • Remote wipe
  • Regular backups
  • Endpoint encryption
Answer: D
10Which of the following should be established FIRST before authorizing remote access to a data store containing personal data?
  • Privacy policy
  • Network security standard
  • Multi-factor authentication
  • Virtual private network (VPN)
Answer: D

Want the full bank of 229 questions for CDPSE? See all practice exams.