← All CDPSE Flashcard Decks

Enhancing Technologies Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Enhancing Technologies flashcards as text
  1. A healthcare organization needs to share patient data with a pharmaceutical researcher. The data must remain in the healthcare org's environment while the researcher runs queries. Which technology best supports this?

    Answer: A data clean room

    A data clean room provides a controlled, neutral environment where queries can be run on data that never leaves the data owner's control, giving the researcher insights without raw data access.

  2. Which of the following correctly distinguishes pseudonymization from anonymization under GDPR?

    Answer: Pseudonymized data is still personal data under GDPR because re-identification is possible with additional information

    GDPR Recital 26 clarifies that pseudonymized data remains personal data because it can be re-identified using separately held information, while truly anonymized data falls outside GDPR scope.

  3. An organization implements a system where a user's identity is split into multiple cryptographic shares distributed across independent servers, so no single server can reconstruct the identity alone. This is an example of:

    Answer: Secret sharing (e.g., Shamir's Secret Sharing)

    Shamir's Secret Sharing and similar threshold schemes split a secret into shares such that only a quorum of shares (not any single one) can reconstruct the original value.

  4. Which PET approach would be MOST effective for a company that needs to publish a dataset for public research while ensuring that re-identification of individuals is computationally infeasible?

    Answer: Combining differential privacy with generalization and suppression techniques

    Combining differential privacy (probabilistic re-identification resistance) with generalization and suppression provides stronger, mathematically quantifiable privacy guarantees than simple identifier removal or low-k anonymization.

  5. In a privacy-preserving identity verification scenario, which technology allows a user to prove they are over 18 without revealing their exact date of birth?

    Answer: Selective disclosure credentials using zero-knowledge proofs

    Selective disclosure credentials with zero-knowledge proofs let users prove specific claims (e.g., age ≥ 18) derived from a credential without revealing the underlying attribute value.

  6. When evaluating privacy-enhancing technologies, which criterion specifically measures the degree to which the protected dataset still supports the intended analytical or operational purpose?

    Answer: Data utility

    Data utility measures how well a privacy-protected dataset preserves the accuracy and usefulness needed for its intended purpose, forming the key axis of the privacy-utility tradeoff.

  7. A CDPSE professional is assessing a vendor's claim that their product 'fully anonymizes' data using a proprietary algorithm with no published methodology. What is the MOST appropriate response?

    Answer: Require the vendor to demonstrate the algorithm meets a recognized standard and allow independent verification

    Proprietary 'black box' anonymization claims cannot be validated without transparency; the CDPSE professional should require independent verification against recognized standards such as ISO 29101 or NIST guidelines.