← All CDPSE Flashcard Decks

Risk Management Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management flashcards as text
  1. During a privacy risk assessment, what is the role of threat modeling?

    Answer: To systematically identify actors, motivations, and attack vectors that could compromise personal data

    Threat modeling in privacy risk assessment identifies who might misuse data, why, and how, enabling more targeted and effective risk treatment.

  2. An organization's privacy risk register has not been updated in 18 months. Which of the following risks is MOST likely to be understated as a result?

    Answer: Risks from new regulatory requirements or business changes

    A stale risk register fails to capture risks introduced by new regulations, business processes, or technology changes that occurred since the last update.

  3. Which framework explicitly requires organizations to conduct a Legitimate Interest Assessment (LIA) as part of privacy risk evaluation?

    Answer: GDPR

    GDPR requires a Legitimate Interest Assessment when processing is based on legitimate interests, to balance the controller's interests against the rights of data subjects.

  4. A CDPSE is conducting a privacy risk assessment for a machine learning model trained on customer purchase history. Which risk is UNIQUE to this type of processing?

    Answer: Inference of sensitive attributes not explicitly provided by users

    ML models can infer sensitive attributes (e.g., health status, political views) from seemingly innocuous behavioral data, creating a unique re-identification or inference risk.

  5. Which of the following BEST illustrates the concept of 'privacy harm' in risk assessment?

    Answer: A data subject losing employment after medical data is disclosed to their employer

    Privacy harm refers to real-world negative consequences suffered by individuals, such as economic loss, discrimination, or emotional distress resulting from misuse of their data.

  6. When is risk avoidance the MOST appropriate treatment strategy for a privacy risk?

    Answer: When the processing activity's risk cannot be reduced to an acceptable level by any means

    Risk avoidance—stopping the activity that creates the risk—is appropriate when no feasible controls can reduce risk to within the organization's risk appetite.

  7. A CDPSE is reviewing a cloud migration project. Which privacy risk is introduced SPECIFICALLY by moving personal data to a cloud provider?

    Answer: Risk of data being subject to foreign government access laws

    Cloud providers may be subject to the laws of their home country (e.g., US CLOUD Act), allowing foreign governments to compel access to data stored by those providers.