CDPSE Risk Management 3 — Questions and Answers
Question 1: Which risk treatment option involves purchasing cyber liability insurance to cover costs associated with a data breach?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to a third party, such as an insurer, though the underlying risk and liability may still remain.
Question 2: A privacy risk assessment reveals a HIGH inherent risk for a customer data analytics program. After applying controls, residual risk drops to LOW. What should the CDPSE do next?
- Escalate the residual risk to the board for approval
- Document the controls and obtain risk owner sign-off on residual risk (Correct answer)
- Discontinue the program since inherent risk was high
- Conduct a full audit before allowing the program to launch
Correct answer: Document the controls and obtain risk owner sign-off on residual risk
Once residual risk is reduced to an acceptable level, the CDPSE should document the controls applied and obtain formal acceptance from the risk owner.
Question 3: Which of the following BEST represents the concept of 'privacy risk' as distinct from 'security risk'?
- Privacy risk focuses solely on financial losses from breaches
- Privacy risk encompasses harms to individuals from inappropriate use of their personal data (Correct answer)
- Privacy risk applies only to healthcare and financial sectors
- Privacy risk is always lower in magnitude than security risk
Correct answer: Privacy risk encompasses harms to individuals from inappropriate use of their personal data
Privacy risk centers on potential harms to data subjects—such as discrimination, loss of autonomy, or reputational damage—rather than organizational financial losses alone.
Question 4: A CDPSE is mapping privacy risks across the data lifecycle. At which stage is the risk of unauthorized secondary use MOST likely to occur?
- Data collection
- Data storage
- Data use and sharing (Correct answer)
- Data destruction
Correct answer: Data use and sharing
Unauthorized secondary use—using data for purposes beyond the original collection intent—most commonly manifests during the use and sharing stage of the data lifecycle.
Question 5: Which of the following is a leading indicator that privacy risk management processes are effective?
- Number of data breach notifications sent to regulators
- Percentage of employees completing annual privacy training
- Reduction in the number of privacy risks escalated without treatment (Correct answer)
- Frequency of board-level privacy risk reviews
Correct answer: Reduction in the number of privacy risks escalated without treatment
A reduction in unaddressed escalated risks indicates that risk treatment processes are working effectively and risks are being resolved proactively.
Question 6: An organization wants to use a risk scoring matrix for privacy risks. Which TWO dimensions are MOST commonly used in such a matrix?
- Impact and likelihood (Correct answer)
- Cost and duration
- Complexity and urgency
- Detectability and severity
Correct answer: Impact and likelihood
A standard risk matrix plots likelihood (probability of occurrence) against impact (magnitude of harm) to produce a risk score.
Question 7: A CDPSE is advising on a new IoT product that collects continuous location data from users. Which privacy risk is MOST significant and should be prioritized?
- Risk of data becoming outdated
- Risk of inferred sensitive attributes from location patterns (Correct answer)
- Risk of users opting out of data collection
- Risk of insufficient data volume for analytics
Correct answer: Risk of inferred sensitive attributes from location patterns
Continuous location data can reveal sensitive inferences such as medical appointments, religious practices, or political activities, making inference risk the most significant concern.
Which risk treatment option involves purchasing cyber liability insurance to cover costs associated with a data breach?