← All CDPSE Flashcard Decks

Risk Management Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management flashcards as text
  1. Which risk treatment option involves purchasing cyber liability insurance to cover costs associated with a data breach?

    Answer: Risk transfer

    Risk transfer shifts the financial consequences of a risk to a third party, such as an insurer, though the underlying risk and liability may still remain.

  2. A privacy risk assessment reveals a HIGH inherent risk for a customer data analytics program. After applying controls, residual risk drops to LOW. What should the CDPSE do next?

    Answer: Document the controls and obtain risk owner sign-off on residual risk

    Once residual risk is reduced to an acceptable level, the CDPSE should document the controls applied and obtain formal acceptance from the risk owner.

  3. Which of the following BEST represents the concept of 'privacy risk' as distinct from 'security risk'?

    Answer: Privacy risk encompasses harms to individuals from inappropriate use of their personal data

    Privacy risk centers on potential harms to data subjects—such as discrimination, loss of autonomy, or reputational damage—rather than organizational financial losses alone.

  4. A CDPSE is mapping privacy risks across the data lifecycle. At which stage is the risk of unauthorized secondary use MOST likely to occur?

    Answer: Data use and sharing

    Unauthorized secondary use—using data for purposes beyond the original collection intent—most commonly manifests during the use and sharing stage of the data lifecycle.

  5. Which of the following is a leading indicator that privacy risk management processes are effective?

    Answer: Reduction in the number of privacy risks escalated without treatment

    A reduction in unaddressed escalated risks indicates that risk treatment processes are working effectively and risks are being resolved proactively.

  6. An organization wants to use a risk scoring matrix for privacy risks. Which TWO dimensions are MOST commonly used in such a matrix?

    Answer: Impact and likelihood

    A standard risk matrix plots likelihood (probability of occurrence) against impact (magnitude of harm) to produce a risk score.

  7. A CDPSE is advising on a new IoT product that collects continuous location data from users. Which privacy risk is MOST significant and should be prioritized?

    Answer: Risk of inferred sensitive attributes from location patterns

    Continuous location data can reveal sensitive inferences such as medical appointments, religious practices, or political activities, making inference risk the most significant concern.