PassFish

CDPSE practice questions — 10 free

Certified Data Privacy Solutions Engineer · every answer carries the reasoning, and why each other option fails.
394 questions
8 chapters of notes
EN + ZH languages

Tap an option to see the answer, the reasoning, and why the other three fail.

Question 1 of 10

What should be the PRIMARY consideration of a multinational organization deploying a user and entity behavior analytics (UEBA) tool to centralize the monitoring of anomalous employee behavior?

Why A is correct

The essence of a UEBA tool is aggregating employee behavioral data from every country onto a single central platform for analysis, and that aggregation is itself a cross-border transfer of personal data. Most jurisdictions impose independent legal-basis requirements for personal data leaving the country (adequacy determinations, standard contractual clauses, consultation with local employee representatives, etc.); without that basis, the entire deployment is legally unworkable no matter how useful the tool is. So the foremost question is whether and on what basis the data can be transferred at all, not whether the tool is convenient or whether users must be notified.

Question 2 of 10

Which of the following is the BEST way to address threats to mobile device privacy when using beacons as a tracking technology?

Why D is correct

A beacon relies on low-energy Bluetooth continuously broadcasting an identifier; as long as a phone has Bluetooth scanning turned on, it will be recognized and located, letting merchants reconstruct movement patterns. To cut off this tracking chain at the root, Bluetooth service must be disabled—if the broadcast can't be received, the tracking can't happen either. Disabling location services doesn't block proximity recognition on the Bluetooth side; antivirus and trojan scanning target malicious code, whereas beacon tracking exploits the device's normal system capabilities and doesn't fall under malware.

Question 3 of 10

Which of the following would BEST enable a data warehouse to limit access to individual database objects?

Why B is correct

The question asks what limits a data warehouse's access down to the level of an individual database object. A virtual private database (VPD) is a mature database-layer mechanism: it automatically attaches policy predicates to a query based on the user's identity at execution time, so the same SQL statement returns different rows and objects to different users — exactly achieving object-level, row-level isolation. Private storage volumes and dictionary-type options are either storage-layer partitioning or merely metadata description, and neither performs access determination. The given answer is D, which does not match the community vote of B.

Question 4 of 10

What type of personal information can be collected by a mobile application without consent?

Why D is correct

To determine whether consent is needed, first determine whether the data points to an identifiable natural person. Full name and phone number are direct identifiers, and geolocation can reconstruct an individual's whereabouts with high precision — all of these are Personal Data that must be disclosed and consented to. Accelerometer readings, by themselves, are merely a physical measure of device motion and do not directly link to a specific person's identity; they are generally treated as non-personal data, and so can be collected without separate consent. It should be noted that once this kind of sensor data is combined with other data to the point of re-identifying an individual, its nature changes.

Question 5 of 10

Which of the following zones within a data lake requires sensitive data to be encrypted or tokenized?

Why C is correct

A data lake is typically layered: the raw zone holds data ingested directly from various source systems without any cleansing or processing, with sensitive fields left untouched — and this layer has the largest data volume, feeding subsequent processing by multiple parties. Precisely because sensitive data exists here in its raw form, it must be encrypted or tokenized before it can move on to the cleansing zone and trusted zone for analysis. Data in the later layers has already been processed, with a much smaller risk exposure.

Question 6 of 10

An email opt-in form on a website applies to which privacy principle?

Why B is correct

An email opt-in form lets the user take an affirmative, revocable action to grant authorization -- exactly what the principle of consent looks like in practice: obtaining a data subject's voluntary, specific, informed permission before processing personal data. The trick to this type of question is to look at what the form is actually doing -- it does not verify whether data is correct, nor is it externally explaining processing rules; it is capturing an authorization status, so it falls under consent. Transparency and consent often appear together, but transparency addresses "has the matter been clearly explained," while consent addresses "has permission been obtained" -- the two must not be conflated.

Question 7 of 10

Using hash values With stored personal data BEST enables an organization to

Why B is correct

Explanation Using hash values with stored personal data best enables an organization to detect changes to the data, because hash values are unique and fixed outputs that are generated from the data using a mathematical algorithm. If the data is altered in any way, even by a single bit, the hash value will change dramatically. Therefore, by comparing the current hash value of the data with the original or expected hash value, the organization can verify the integrity and authenticity of the data. If the hash values match, it means that the data has not been tampered with. If the hash values differ, it means that the data has been corrupted or modified. References: * Ensuring Data Integrity with Hash Codes, Microsoft Learn * What is 'hashing,' and does it help avoid the obligations imposed by the new privacy regulations?, Data Privacy Dish

Question 8 of 10

When implementing systems that transmit or store personal data, what should an organization prioritize to ensure compliance with privacy regulations?

Why B is correct

Organizations handling personal data—whether it's for customers, clients, or employees—must ensure their systems comply with relevant data protection regulations like the GDPR, CCPA, or HIPAA. A critical part of this involves carefully reviewing system configurations during setup to verify compliance with privacy and security requirements. Answer B is the most accurate because it reflects a deliberate and proactive approach to ensuring that information systems are configured to support legal compliance. This means reviewing each setting to verify that: Encryption is enabled for both data in transit and at rest Access control mechanisms follow the principle of least privilege Audit logs and monitoring systems are functional and retained Default accounts and weak passwords are removed or secured Unnecessary services or ports are disabled Many privacy violations occur not because of flaws in technology, but due to misconfigured systems. Vendors often ship products with default settings that prioritize usability over security. These defaults may expose personal data to unauthorized access or fail to meet legal standards. Now let’s examine the other options: A. Use vendor default settings This is risky. Default configurations often lack strong security controls, such as encryption, password protection, or access limitations. Relying on them without review invites compliance gaps and vulnerabilities. C. Choose the least restrictive mode This contradicts the principle of least privilege, which is central to data protection. An unrestricted mode could lead to overexposure of personal data, making the system vulnerable to breaches and non-compliance. D. Enable only core features While minimalist design has benefits, this option lacks the specificity needed for compliance. A system might operate with only basic features, but still fail to encrypt data or enforce access controls, resulting in regulatory violations. In conclusion, system compliance with data privacy laws isn't automatic—it requires intentional effort. Organizations must assess and tailor their system configurations to ensure security, transparency, and privacy controls are actively enforced. This is why reviewing configurations with a compliance lens (Option B) is the most effective and legally responsible approach. How to open VCE Files Use VCE Exam Simulator to open VCE files Sign Up Learn More Full Version Top Isaca Certifications Top Isaca Certification Exams CISM CISA AAISM CRISC AAIA AAIR COBIT 2019 CGEIT COBIT 5 CDPSE AI Fundamentals Site Search: All Vendors CompTIA Security+ Practice Test SY0-701 Dumps AZ-104 Dumps Video Courses CompTIA Network+ Practice Test 200-301 Dumps SAA-C03 Dumps What we offer Comptia A+ Practice Test AI-900 Dumps DP-700 Dumps Share VCE File Microsoft Azure Administrator SAP-C02 Dumps AZ-305 Dumps Certifications Guide Cisco CCNA Practice Test AIF-C01 Dumps AI-102 Dumps Free Practice Tests Cisco CCNP Enterprise N10-009 Dumps PL-300 Dumps Archive Amazon AWS Architect Associate AZ-900 Dumps 350-401 Dumps Blog PMI PMP Certification Practice Test MD-102 Dumps CS0-003 Dumps Sitemap Google Professional Cloud Architect CLF-C02 Dumps AZ-500 Dumps Contact Us ISACA CISM Practice Test CISSP Dumps FCP_FGT_AD-7.6 Dumps Terms of Service Privacy Policy Rss --> IT Training IT Courses --> Exam Formatter Tutorial Passguide Trandumper Examexpress --> Convert VCE to PDF --> Examcollection.com materials do not contain actual questions and answers from Cisco's certification exams. Payments will appear on your bank statement as "Examcollection.com". © 2026 ExamCollection --> © 2026 ExamCollection SPECIAL OFFER: GET 10% OFF Pass your Exam with ExamCollection's PREMIUM files! ExamCollection Certified Safe Files Guaranteed to have ACTUAL Exam Questions Up-to-Date Exam Study Material - Verified by Experts Instant Downloads Enter Your Email Address to Receive Your 10% Off Discount Code Please enter a correct email to Get your Discount Code Get My Discount Code A Confirmation Link will be sent to this email address to verify your login We value your privacy. We will not rent or sell your email address SPECIAL OFFER: GET 10% OFF Use Discount Code: MIN10OFF A confirmation link was sent to your e-mail. Please check your mailbox for a message from support@examcollection.com and follow the directions. Shop Now Download Free Demo of VCE Exam Simulator Experience Avanset VCE Exam Simulator for yourself. Simply submit your e-mail address below to get started with our interactive software demo of your free trial. Realistic exam simulation and exam editor with preview functions Whole exam in a single file with several different question types Customizable exam-taking mode & detailed score reports Your E-mail Download Demo Free Demo Limits: In the demo version you will be able to access only first 5 questions from exam.

Question 9 of 10

In a system implementation project where production data must be used for testing, which of the following practices would MOST effectively protect customer data privacy?

Why C is correct

The core risk of bringing production data into a test environment is that the test environment's access control, logging, and hardening are generally weaker than production, with more people having access (developers, contractors, third party tools) — a leak there means real customer data is exposed. Data obfuscation (masking, tokenization, synthetic substitution) replaces real personal identifiers before the data enters the test environment, while preserving the format and statistical characteristics needed for testing, which removes at the root the premise that real personal data exists in the test environment at all — this is the most thorough approach.

Question 10 of 10

Which of the following metrics would BEST demonstrate how privacy compliance can be achieved throughout the supply chain?

Why D is correct

The metric needs to target how compliance is actually implemented and verified across the supply chain. The number of privacy audits conducted on third-party vendors directly reflects the extent to which the organization extends compliance requirements upstream and downstream and verifies them — how many vendors were audited, what proportion of key vendors that covers — and it is trackable, comparable, and can drive improvement. The number of violations is a lagging, outcome-based indicator that tells you where problems have already occurred, while the number of PIAs and the time taken to fulfill rights requests both reflect only internal organizational activity, not the supply chain dimension.

These 10 are a sample

See the full bank