Technical Privacy Controls Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Technical Privacy Controls flashcards as text
Which anonymization technique replaces actual values with fictional but realistic-looking substitutes that maintain referential integrity?
Answer: Tokenization
Tokenization replaces sensitive values with non-sensitive tokens that can be mapped back via a secure token vault, preserving referential integrity.
A privacy engineer is implementing differential privacy. What is the primary mechanism used to protect individual records?
Answer: Adding calibrated statistical noise to query results
Differential privacy adds mathematically calibrated noise to outputs so that the inclusion or exclusion of any single record has negligible impact on results.
What does the 'epsilon' parameter (ε) control in a differential privacy implementation?
Answer: The privacy-utility trade-off (lower = stronger privacy)
Epsilon (ε) is the privacy budget; a smaller ε means more noise is added, providing stronger privacy at the cost of data utility.
An organization needs to share patient datasets with researchers while preventing re-identification. Which de-identification standard is mandated under HIPAA?
Answer: Expert Determination or Safe Harbor method
HIPAA provides two de-identification methods: Expert Determination (statistical verification) and Safe Harbor (removal of 18 specified identifiers).
Which access control model is BEST suited for enforcing data minimization by granting access based on job function rather than individual identity?
Answer: Role-Based Access Control (RBAC)
RBAC assigns permissions to roles tied to job functions, naturally limiting data access to what each role needs, supporting data minimization.
A developer wants to allow analytics on encrypted data without decrypting it. Which cryptographic technique enables computation directly on ciphertext?
Answer: Homomorphic encryption
Homomorphic encryption allows mathematical operations to be performed on ciphertext, producing an encrypted result that, when decrypted, equals the result of the same operation on plaintext.
What is the primary purpose of a Privacy-Enhancing Technology (PET) called 'secure multi-party computation' (SMPC)?
Answer: Allowing multiple parties to jointly compute a function without revealing their private inputs
SMPC enables multiple parties to collaboratively compute results from their combined private data without any party exposing its raw inputs to others.