CDPSE - Certified Data Privacy Solutions Engineer — Questions and Answers
Question 1: A data subject requests rectification of inaccurate data. What obligation does the controller have regarding third parties who received the incorrect data?
- Notify third parties only if technically feasible
- Inform each recipient of the rectification unless it is impossible or involves disproportionate effort (Correct answer)
- No obligation to notify third parties
- Notify the supervisory authority about the error
Correct answer: Inform each recipient of the rectification unless it is impossible or involves disproportionate effort
GDPR Article 19 requires controllers to notify all recipients of the corrected data unless doing so is impossible or involves disproportionate effort.
Question 2: Which privacy-enhancing technology is most commonly used to enable privacy-preserving advertising measurement without sharing individual user data between platforms?
- Data anonymization
- Tokenization
- Role-based access control
- Private set intersection (PSI) (Correct answer)
Correct answer: Private set intersection (PSI)
Private set intersection (PSI) allows two parties to find common elements in their datasets without revealing elements that are not in common, used in ad measurement to match conversions without exposing full user lists.
Question 3: A user needs to prove to an online service that they are over the age of 21 to access age-restricted content. To protect their privacy, they want to provide this proof without revealing their actual date of birth. Which cryptographic technique allows a prover to convince a verifier that a statement is true, without revealing any information beyond the validity of the statement itself?
- Secure Multi-Party Computation (SMPC)
- Zero-Knowledge Proof (ZKP) (Correct answer)
- Attribute-Based Encryption (ABE)
- Digital Signature
Correct answer: Zero-Knowledge Proof (ZKP)
A Zero-Knowledge Proof (ZKP) is a cryptographic protocol that enables one party (the prover) to prove to another party (the verifier) that they know a value or that a statement is true, without conveying any information apart from the fact that the statement is indeed true. This is the perfect technical control for use cases like age verification, where the service only needs to know 'yes' or 'no' to the statement 'Is this person over 21?', not the person's actual birthday.
Question 4: During a privacy risk assessment, what is the role of threat modeling?
- To systematically identify actors, motivations, and attack vectors that could compromise personal data (Correct answer)
- To calculate the financial cost of potential data breaches
- To assign compliance ratings to third-party vendors
- To identify vulnerabilities in network infrastructure only
Correct answer: To systematically identify actors, motivations, and attack vectors that could compromise personal data
Threat modeling in privacy risk assessment identifies who might misuse data, why, and how, enabling more targeted and effective risk treatment.
Question 5: Why is data lineage documentation important for CDPSE professionals?
- It reduces the cost of cloud data storage
- It speeds up database query performance
- It enables organizations to trace data transformations and demonstrate compliance accountability (Correct answer)
- It automatically enforces access control policies
Correct answer: It enables organizations to trace data transformations and demonstrate compliance accountability
Data lineage provides an auditable record of how personal data has been processed and transformed, which is essential for regulatory accountability and breach investigations.
Question 6: What distinguishes l-diversity from k-anonymity as a privacy technique?
- L-diversity removes all quasi-identifiers from the dataset
- L-diversity ensures sensitive attribute values are sufficiently diverse within each anonymization group (Correct answer)
- L-diversity applies differential privacy noise to each group
- L-diversity requires more records per equivalence class
Correct answer: L-diversity ensures sensitive attribute values are sufficiently diverse within each anonymization group
L-diversity extends k-anonymity by requiring that each equivalence class contains at least l well-represented values for sensitive attributes, preventing homogeneity attacks.
Question 7: Which of the following is a key limitation of k-anonymity as a privacy-enhancing technique?
- It cannot be applied to datasets with more than 10 attributes
- It is vulnerable to homogeneity and background knowledge attacks (Correct answer)
- It permanently destroys the utility of the dataset
- It requires homomorphic encryption to implement correctly
Correct answer: It is vulnerable to homogeneity and background knowledge attacks
K-anonymity can be defeated by homogeneity attacks (when all records in a group share the same sensitive value) and background knowledge attacks using external information.
Question 8: An online service requires users to prove they are over the age of 18 to access age-restricted content. To maximize user privacy and adhere to the principle of data minimization, the service wants to verify a user's age without ever receiving or storing their actual date of birth. Which cryptographic method would be most suitable for this use case?
- Synthetic Data Generation
- Federated Learning
- k-Anonymization
- Zero-Knowledge Proof (Correct answer)
Correct answer: Zero-Knowledge Proof
A Zero-Knowledge Proof (ZKP) is a cryptographic protocol where one party (the prover) can prove to another party (the verifier) that a statement is true, without conveying any information apart from the fact that the statement is indeed true. In this case, the user proves they are over 18 without revealing their birthdate.
Question 9: Which approach to privacy governance treats privacy as a competitive differentiator and business enabler rather than just a compliance obligation?
- Privacy as a business value and trust driver (Correct answer)
- Minimal viable compliance posture
- Risk transfer through cyber insurance
- Compliance-first governance
Correct answer: Privacy as a business value and trust driver
Treating privacy as a business value positions it as a trust-building asset that can differentiate products and attract privacy-conscious customers.
Question 10: Which type of audit evaluates both the design and operating effectiveness of privacy controls?
- Penetration test
- Compliance checklist review
- Desk review
- Control effectiveness audit (Correct answer)
Correct answer: Control effectiveness audit
A control effectiveness audit tests whether controls are both properly designed to address risks and actually operating as intended in practice over time.
Question 11: Which activity BEST supports the principle of data minimization during system design?
- Encrypting all collected fields
- Backing up data to multiple geographic regions
- Collecting only the data elements strictly required for the defined purpose (Correct answer)
- Applying role-based access controls to all data
Correct answer: Collecting only the data elements strictly required for the defined purpose
Data minimization means not collecting personal data beyond what is necessary, reducing the privacy risk surface from the outset.
Question 12: Which of the following BEST describes the difference between a privacy risk assessment and a Data Protection Impact Assessment (DPIA)?
- A DPIA is legally mandated for high-risk processing under GDPR, while a privacy risk assessment is a general best-practice tool (Correct answer)
- A privacy risk assessment replaces the need for a DPIA under all frameworks
- A DPIA is broader and covers all organizational risks, while a privacy risk assessment is narrower
- A DPIA focuses on technical controls while a privacy risk assessment focuses on legal compliance
Correct answer: A DPIA is legally mandated for high-risk processing under GDPR, while a privacy risk assessment is a general best-practice tool
Under GDPR Article 35, a DPIA is legally required for high-risk processing activities, whereas a privacy risk assessment is a broader, framework-agnostic practice.
Question 13: Which NIST privacy framework function focuses on developing organizational understanding to manage privacy risk to individuals?
- Communicate
- Protect-P
- Respond
- Identify-P (Correct answer)
Correct answer: Identify-P
The Identify-P function in the NIST Privacy Framework establishes understanding of data processing activities and associated privacy risks.
Question 14: A CDPSE candidate is designing a data retention schedule. Which factor is MOST critical to determine first?
- Available storage capacity
- Cost of storage media
- User access frequency
- Legal and regulatory retention requirements (Correct answer)
Correct answer: Legal and regulatory retention requirements
Legal and regulatory requirements set the minimum and maximum retention periods that override business convenience or cost considerations.
Question 15: A privacy governance framework should include which of the following as a primary component for managing third-party data processors?
- Data Processing Agreements (DPAs) with contractual privacy obligations (Correct answer)
- Prohibition of all data sharing with third parties
- On-site inspections of all processor facilities
- Annual security audits of all vendors
Correct answer: Data Processing Agreements (DPAs) with contractual privacy obligations
DPAs are the contractual mechanism requiring third-party processors to uphold the controller's privacy obligations.
Question 16: When is risk avoidance the MOST appropriate treatment strategy for a privacy risk?
- When the cost of controls exceeds the potential loss
- When the processing activity's risk cannot be reduced to an acceptable level by any means (Correct answer)
- When senior management decides to accept the risk without controls
- When the risk can be transferred to a third-party processor
Correct answer: When the processing activity's risk cannot be reduced to an acceptable level by any means
Risk avoidance—stopping the activity that creates the risk—is appropriate when no feasible controls can reduce risk to within the organization's risk appetite.
Question 17: Which privacy engineering principle, if applied before an incident occurs, MOST reduces the volume of data exposed during a breach?
- Data minimization (Correct answer)
- Privacy notice clarity
- Transparency
- User consent management
Correct answer: Data minimization
Data minimization limits the collection and retention of personal data, directly reducing the number of records and fields that can be exposed in a breach.
Question 18: Which of the following is the MOST significant privacy challenge when deploying large language models (LLMs) trained on personal data?
- LLMs cannot comply with GDPR because they process natural language
- LLMs may memorize and reproduce training data containing personal information upon prompting (Correct answer)
- LLMs must use differential privacy, making them too inaccurate for practical use
- LLMs always require consent from all individuals whose data was used
Correct answer: LLMs may memorize and reproduce training data containing personal information upon prompting
Research has demonstrated that LLMs can memorize verbatim sequences from training data, meaning personal information could be extracted through targeted prompts.
Question 19: Which of the following is a primary engineering goal when implementing the right to rectification under GDPR?
- To log the IP address from which the rectification request was made.
- To ensure the inaccurate data is archived securely before being corrected.
- To notify the data subject within 48 hours that the correction has been made.
- To propagate the correction to all systems and databases where the inaccurate data is stored. (Correct answer)
Correct answer: To propagate the correction to all systems and databases where the inaccurate data is stored.
The core of the right to rectification (Article 16 of GDPR) is to ensure that inaccurate personal data is corrected. From an engineering perspective, this means the correction must be propagated across all systems, including downstream systems, backups, and archives, where the incorrect data resides to ensure its integrity and prevent further processing of inaccurate information. Failing to do so would render the correction ineffective.
Question 20: A privacy engineer is evaluating two database architectures: one stores full PII for analytics, the other stores only hashed identifiers with separate re-identification keys held by a different team. Which principle does the second architecture embody?
- Separation of Duties combined with Pseudonymization (Correct answer)
- End-to-End Security
- Full Functionality
- Visibility and Transparency
Correct answer: Separation of Duties combined with Pseudonymization
Pseudonymization combined with separation of duties ensures that no single team can re-identify individuals, reducing insider threat and unauthorized linkage.
Question 21: An organization collects customer email addresses for order confirmations but later uses them for marketing newsletters. This violates which data lifecycle principle?
- Purpose limitation (Correct answer)
- Data accuracy
- Integrity and confidentiality
- Storage limitation
Correct answer: Purpose limitation
Purpose limitation requires that personal data collected for a specific purpose must not be used for incompatible secondary purposes without a new legal basis.
Question 22: What is 'data mapping' in the context of the personal data lifecycle?
- Encrypting data as it flows between systems
- Backing up data to multiple geographic locations
- Documenting where personal data originates, moves, and is stored across the organization (Correct answer)
- Converting data from one format to another
Correct answer: Documenting where personal data originates, moves, and is stored across the organization
Data mapping creates a comprehensive inventory of personal data flows, which is foundational to demonstrating compliance and identifying privacy risks.
Question 23: The NIST Privacy Framework is designed to help organizations manage privacy risks. The Framework's 'Core' is a set of activities and outcomes that enables communication of privacy priorities. Which of the following is NOT one of the five high-level Functions of the NIST Privacy Framework Core?
- Govern-P
- Remediate-P (Correct answer)
- Identify-P
- Protect-P
Correct answer: Remediate-P
The five Functions of the NIST Privacy Framework Core are Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P. These functions are designed to help an organization manage privacy risks from the executive level to the operational level. 'Remediate' is not one of the core functions, although remediation activities would fall under the other functions as part of a risk response.
Question 24: Which element of privacy governance ensures that personal data is only used for the purposes for which it was originally collected?
- Data integrity
- Storage limitation
- Purpose limitation (Correct answer)
- Confidentiality
Correct answer: Purpose limitation
Purpose limitation restricts the use of personal data to the specific, stated purposes communicated at collection.
Question 25: Which of the following is NOT a lawful basis for refusing a data subject access request under GDPR?
- The request is repetitive
- Providing the data would adversely affect the rights of others
- The data was collected from a third party (Correct answer)
- The request is manifestly unfounded
Correct answer: The data was collected from a third party
The origin of data from a third party is not a valid ground for refusing an access request; organizations must provide data regardless of its source.
Question 26: A company stores personal data on decommissioned server hard drives in a locked warehouse. What is the MAIN privacy risk?
- Unauthorized physical access leading to data recovery (Correct answer)
- Loss of data availability for business use
- Increased regulatory audit frequency
- Data accuracy degradation over time
Correct answer: Unauthorized physical access leading to data recovery
Retaining unwiped storage media creates a risk that data could be physically accessed and recovered using forensic tools.
Question 27: Which technique enables a researcher to determine whether a specific individual's data is in a dataset without the organization revealing the dataset contents?
- Secure multi-party computation
- Private information retrieval (PIR) (Correct answer)
- Differential privacy
- Homomorphic encryption
Correct answer: Private information retrieval (PIR)
Private information retrieval (PIR) allows a user to query a database and retrieve a record without the database owner learning which record was accessed.
Question 28: What is the key difference between a privacy audit and a security audit?
- Privacy audits are only performed by external parties; security audits can be internal
- Security audits are legally required; privacy audits are voluntary
- Privacy audits evaluate compliance with personal data rights and regulations; security audits assess technical controls protecting data confidentiality and integrity (Correct answer)
- Privacy audits focus on financial data; security audits focus on personal data
Correct answer: Privacy audits evaluate compliance with personal data rights and regulations; security audits assess technical controls protecting data confidentiality and integrity
While overlapping, privacy audits focus on regulatory compliance, individual rights, and data use legitimacy, whereas security audits focus on technical protections against unauthorized access.
Question 29: Which of the following BEST represents the concept of 'privacy risk' as distinct from 'security risk'?
- Privacy risk focuses solely on financial losses from breaches
- Privacy risk applies only to healthcare and financial sectors
- Privacy risk encompasses harms to individuals from inappropriate use of their personal data (Correct answer)
- Privacy risk is always lower in magnitude than security risk
Correct answer: Privacy risk encompasses harms to individuals from inappropriate use of their personal data
Privacy risk centers on potential harms to data subjects—such as discrimination, loss of autonomy, or reputational damage—rather than organizational financial losses alone.
Question 30: What is the role of supplementary measures in cross-border data transfers under SCCs?
- To reduce the cost of compliance with transfer rules
- To replace SCCs when they are too complex to implement
- To notify data subjects about international transfers automatically
- To provide additional technical or contractual protections when the destination country's laws may undermine SCC guarantees (Correct answer)
Correct answer: To provide additional technical or contractual protections when the destination country's laws may undermine SCC guarantees
Supplementary measures—such as encryption, pseudonymization, or additional contractual commitments—strengthen SCC protections where destination country laws pose elevated risks.
CDPSE - Certified Data Privacy Solutions Engineer
The CDPSE certification, offered by ISACA, validates technical privacy implementation skills across governance, risk management, data lifecycle, and engineering domains. It is designed for IT and security professionals who design and implement enterprise privacy solutions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds