CDPSE Risk Management 4 — Questions and Answers
Question 1: During a privacy risk assessment, what is the role of threat modeling?
- To identify vulnerabilities in network infrastructure only
- To systematically identify actors, motivations, and attack vectors that could compromise personal data (Correct answer)
- To calculate the financial cost of potential data breaches
- To assign compliance ratings to third-party vendors
Correct answer: To systematically identify actors, motivations, and attack vectors that could compromise personal data
Threat modeling in privacy risk assessment identifies who might misuse data, why, and how, enabling more targeted and effective risk treatment.
Question 2: An organization's privacy risk register has not been updated in 18 months. Which of the following risks is MOST likely to be understated as a result?
- Risks from legacy systems already identified
- Risks from new regulatory requirements or business changes (Correct answer)
- Risks from previously accepted low-severity items
- Risks that were transferred to insurance coverage
Correct answer: Risks from new regulatory requirements or business changes
A stale risk register fails to capture risks introduced by new regulations, business processes, or technology changes that occurred since the last update.
Question 3: Which framework explicitly requires organizations to conduct a Legitimate Interest Assessment (LIA) as part of privacy risk evaluation?
- NIST Privacy Framework
- ISO 27701
- GDPR (Correct answer)
- CCPA
Correct answer: GDPR
GDPR requires a Legitimate Interest Assessment when processing is based on legitimate interests, to balance the controller's interests against the rights of data subjects.
Question 4: A CDPSE is conducting a privacy risk assessment for a machine learning model trained on customer purchase history. Which risk is UNIQUE to this type of processing?
- Unauthorized access by external attackers
- Inference of sensitive attributes not explicitly provided by users (Correct answer)
- Failure to encrypt data at rest
- Improper data retention schedules
Correct answer: Inference of sensitive attributes not explicitly provided by users
ML models can infer sensitive attributes (e.g., health status, political views) from seemingly innocuous behavioral data, creating a unique re-identification or inference risk.
Question 5: Which of the following BEST illustrates the concept of 'privacy harm' in risk assessment?
- An organization paying a regulatory fine for a breach
- A data subject losing employment after medical data is disclosed to their employer (Correct answer)
- An IT system experiencing downtime due to a ransomware attack
- An organization failing a third-party security audit
Correct answer: A data subject losing employment after medical data is disclosed to their employer
Privacy harm refers to real-world negative consequences suffered by individuals, such as economic loss, discrimination, or emotional distress resulting from misuse of their data.
Question 6: When is risk avoidance the MOST appropriate treatment strategy for a privacy risk?
- When the cost of controls exceeds the potential loss
- When the risk can be transferred to a third-party processor
- When the processing activity's risk cannot be reduced to an acceptable level by any means (Correct answer)
- When senior management decides to accept the risk without controls
Correct answer: When the processing activity's risk cannot be reduced to an acceptable level by any means
Risk avoidance—stopping the activity that creates the risk—is appropriate when no feasible controls can reduce risk to within the organization's risk appetite.
Question 7: A CDPSE is reviewing a cloud migration project. Which privacy risk is introduced SPECIFICALLY by moving personal data to a cloud provider?
- Risk of data loss due to hardware failure
- Risk of data being subject to foreign government access laws (Correct answer)
- Risk of employees accessing data without authorization
- Risk of data becoming corrupted during migration
Correct answer: Risk of data being subject to foreign government access laws
Cloud providers may be subject to the laws of their home country (e.g., US CLOUD Act), allowing foreign governments to compel access to data stored by those providers.
During a privacy risk assessment, what is the role of threat modeling?