Skip to content

CDPSE Practice Questions

Prepare for CDPSE with more than an answer.

185 questions in the full set20 sample questionsUpdated Jan 27, 2026
Level
Professional
Valid for
3 years
Domains covered on the exam 4
  1. Privacy Governance20%
  2. Privacy Risk Management and Compliance18%
  3. Data Life Cycle Management23%
  4. Privacy Engineering39%
  1. 1

    A user of a mobile application revokes their consent for the processing of their personal data for marketing purposes through the app's privacy dashboard. What is the MOST critical IMMEDIATE technical action the system must perform?

    Show answer details

    Correct answer: B

    The most critical and immediate action is to honor the revocation by updating the user's consent status in a central repository. This change must then be propagated to all connected systems (e.g., email platforms, analytics tools) to cease any further processing based on that consent. This ensures the user's choice is respected in real-time or near-real-time, which is a fundamental requirement of valid consent management.

  2. 2

    A US-based company is planning to launch its service in Brazil and must comply with the Lei Geral de Proteção de Dados (LGPD). What should be the FIRST step in the privacy engineering team's compliance project plan?

    Show answer details

    Correct answer: C

    Before any specific compliance actions are taken, the team must first understand their current state. A data mapping exercise identifies what personal data is being processed and where it flows. A gap analysis then compares these existing practices against the specific articles and requirements of the LGPD. This foundational step identifies all areas of non-compliance and informs the entire remediation and implementation plan.

  3. 3

    When designing privacy controls for a containerized microservices application running on Kubernetes, what is the MOST effective method for enforcing fine-grained, secure communication policies between services (pods) to prevent unauthorized access to personal data?

    Show answer details

    Correct answer: B

    A service mesh provides the most effective and granular control for inter-service communication. It operates at a layer above basic network policies. By enforcing mTLS, it ensures that all communication is encrypted and that both services have verified each other's identity. Furthermore, it allows for powerful L7 policies, such as permitting 'Service A' to call the GET method on '/users' in 'Service B', but not the POST method. This identity-based authorization is far more robust for protecting data than simple IP/port-based rules.

  4. 4

    To cultivate a sustainable, organization-wide privacy-aware culture, which training and awareness strategy is MOST effective?

    Show answer details

    Correct answer: C

    Effectiveness in building culture comes from continuous reinforcement and relevance. A one-size-fits-all annual training is often forgotten. A continuous program that provides specific, role-based training (e.g., for developers, marketers, HR), reinforced with practical exercises (like privacy-focused phishing simulations) and ongoing communications (newsletters, lunch-and-learns), is far more effective at embedding privacy into the daily consciousness and practices of the organization.

  5. 5

    A company is decommissioning a data center and must dispose of hard drives containing sensitive personal information. To comply with data protection regulations, the data must be rendered completely unrecoverable. Which data destruction method provides the HIGHEST level of assurance?

    Show answer details

    Correct answer: D

    While other methods provide strong security, physical destruction (such as shredding, disintegration, or incineration) is the only method that provides absolute assurance that the data is unrecoverable. It eliminates any possibility of recovery through advanced forensic techniques that might defeat software-based or magnetic erasure methods. For the highest level of assurance, physical destruction is the definitive final step.

  6. 6

    A financial services firm is developing a machine learning model to detect fraudulent transactions. The model requires training on a large dataset of customer transactions from multiple collaborating banks, none of which can share raw data directly due to privacy regulations. The model's accuracy is paramount, and it must be retrained frequently. Which Privacy Enhancing Technology (PET) would be the MOST appropriate solution for this scenario?

    Show answer details

    Correct answer: C

    Federated Learning is the ideal solution here. It allows a central model to be trained collaboratively without any of the participating organizations having to expose their raw, sensitive data. Each bank trains a local version of the model on its own data, and only the resulting model weights or updates are sent to a central server for aggregation. This directly addresses the core constraint of not sharing raw data while still enabling the creation of a highly accurate, shared model.

  7. 7

    A rapidly scaling technology startup has just secured a new round of funding and plans to expand its operations into the European Union. The company has a flat organizational structure and has handled privacy on an ad-hoc basis so far. What is the MOST effective first step in establishing a formal privacy governance structure to support this growth and ensure compliance?

    Show answer details

    Correct answer: D

    For a rapidly scaling startup with a flat structure, the most effective first step is to embed privacy responsibility within the existing organization. Forming a cross-functional committee (involving engineering, product, legal, marketing) and assigning clear privacy champion roles ensures that privacy is integrated into the company's agile culture from the ground up. This approach is more practical and sustainable than immediately imposing a rigid external structure or focusing solely on tools or documentation without clear ownership.

  8. 8

    A healthcare organization is implementing its data retention policy, which requires that patient electronic health records (EHR) be securely deleted seven years after the patient's last interaction. Which technical controls are ESSENTIAL to enforce this policy effectively? (Select TWO).

    Show answer details

    Correct answer: A, C

    Automation is crucial for reliably enforcing a retention schedule at scale. A script that identifies records meeting the deletion criteria (e.g., last interaction date > 7 years) and triggers a secure deletion method like cryptographic erasure is a core technical control.

    To prove compliance and maintain accountability, it is essential to have a secure, tamper-proof log of all data destruction activities. This log serves as evidence that the retention policy is being followed correctly and provides a trail for any future audits or investigations.

  9. 9

    A social media company is planning to launch a new feature that uses machine learning to analyze user-uploaded photos and automatically suggest tags based on detected objects, faces, and locations. This processing is not essential for the core service. According to the GDPR, which of the following is the PRIMARY trigger for conducting a Data Protection Impact Assessment (DPIA)?

    Show answer details

    Correct answer: C

    Under Article 35 of the GDPR, a DPIA is required when a type of processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. The large-scale processing of special category data (biometrics from faces), combined with location data and innovative use of technology (ML), clearly meets this threshold.

  10. 10

    A telehealth provider, 'CareConnect', is developing a new mobile application for remote patient monitoring. The application will collect real-time biometric data (heart rate, blood oxygen) from wearable IoT devices, patient-reported symptoms via a chatbot, and video consultation recordings. CareConnect's primary goals are to ensure patient trust, comply with HIPAA and GDPR, and implement robust Privacy by Design principles.

    The proposed architecture involves the mobile app sending all data directly to a monolithic backend application hosted in a public cloud. This backend processes the data, stores it in a single large database, and serves it to healthcare providers through a web portal. The CISO has raised concerns that this design creates significant privacy risks and lacks necessary controls for data segregation and minimization.

    As the lead privacy engineer, you are tasked with redesigning the architecture to address these concerns. Which of the following architectural approaches BEST integrates Privacy by Design principles for the CareConnect application?

    Show answer details

    Correct answer: B

    This approach is the strongest example of Privacy by Design. A microservices architecture inherently promotes data segregation and purpose limitation, as each service only handles the data it needs. Storing data in separate, purpose-built databases (e.g., a time-series DB for biometrics, a document store for chat logs) allows for tailored security controls. The API Gateway acts as a central policy enforcement point, ensuring that only authorized services can access specific data types, thus enforcing the principle of least privilege and data minimization.

Create an account to continue.