← All CDPSE Flashcard Decks

Enhancing Technologies Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Enhancing Technologies flashcards as text
  1. A data engineer needs to share a dataset for research that preserves realistic relationships between variables but contains no real individuals' data. Which PET is most appropriate?

    Answer: Synthetic data generation

    Synthetic data generation creates artificial datasets that preserve statistical relationships from real data without including any actual personal information.

  2. In a trusted execution environment (TEE), data privacy is protected by:

    Answer: Processing sensitive data in an isolated hardware enclave inaccessible to the host OS

    A TEE (such as Intel SGX or ARM TrustZone) provides a hardware-isolated enclave where code and data are protected even from the operating system or hypervisor.

  3. Which privacy-enhancing technology is most commonly used to enable privacy-preserving advertising measurement without sharing individual user data between platforms?

    Answer: Private set intersection (PSI)

    Private set intersection (PSI) allows two parties to find common elements in their datasets without revealing elements that are not in common, used in ad measurement to match conversions without exposing full user lists.

  4. What distinguishes l-diversity from k-anonymity as a privacy technique?

    Answer: L-diversity ensures sensitive attribute values are sufficiently diverse within each anonymization group

    L-diversity extends k-anonymity by requiring that each equivalence class contains at least l well-represented values for sensitive attributes, preventing homogeneity attacks.

  5. An organization uses a technique where personal identifiers are replaced with randomly generated tokens stored in a separate secure vault. This is best described as:

    Answer: Tokenization

    Tokenization replaces sensitive data with non-sensitive placeholder tokens, with the mapping maintained in a secure token vault, allowing re-identification only by those with vault access.

  6. Which of the following best describes a privacy risk associated with federated learning?

    Answer: Model updates (gradients) can potentially leak information about training data through inference attacks

    Gradient inversion and membership inference attacks can extract information about individual training records from the model updates shared during federated learning.

  7. The epsilon (ε) parameter in differential privacy controls:

    Answer: The privacy-utility tradeoff, where lower epsilon means stronger privacy but less accurate results

    Epsilon (ε) is the privacy budget; a smaller epsilon adds more noise for stronger privacy guarantees but reduces the accuracy of aggregate query results.