← All CDPSE Flashcard Decks

Mixed Deck — All CDPSE Topics Flashcards

100 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CDPSE Topics flashcards as text
  1. An engineer recommends that a new payment system fail to a locked-out state rather than an open state if authentication fails. This is an example of which security principle aligned with Privacy by Design?

    Answer: Fail Secure (Fail Safe)

    Fail Secure ensures that when a system fails, it defaults to denying access rather than inadvertently granting it.

  2. A privacy engineer needs to prevent internal analysts from seeing raw PII in a production database while still enabling query-based analytics. Which control is MOST appropriate?

    Answer: Dynamic data masking that substitutes real values at query time for unauthorized users

    Dynamic data masking presents masked values to unauthorized users at query time without altering the underlying stored data, balancing utility and privacy.

  3. Which governance principle ensures that individuals are informed about how their personal data will be used at or before the time of collection?

    Answer: Openness and transparency

    Openness and transparency require organizations to make their data processing practices known to individuals before or at the point of collection.

  4. What is the key difference between a privacy audit and a security audit?

    Answer: Privacy audits evaluate compliance with personal data rights and regulations; security audits assess technical controls protecting data confidentiality and integrity

    While overlapping, privacy audits focus on regulatory compliance, individual rights, and data use legitimacy, whereas security audits focus on technical protections against unauthorized access.

  5. A data privacy solutions engineer is embedding the Privacy Impact Assessment (PIA) process into the company's system development lifecycle (SDLC). At which stage should the PIA be initiated to be MOST effective?

    Answer: During the initial design and planning phase.

    To be most effective and align with the principle of 'Privacy by Design', a PIA should be initiated as early as possible in the project lifecycle. Starting during the design and planning phase allows privacy considerations to influence the system's architecture, data flows, and features, rather than retrofitting privacy controls later, which is often more costly and less effective.

  6. Which metric is MOST useful for evaluating incident response effectiveness from a privacy perspective?

    Answer: Mean time to detect and contain a privacy breach

    Mean time to detect and contain directly measures the speed and efficiency of the incident response process, minimizing harm to data subjects.

  7. Which of the following best describes a 'data subject' under GDPR?

    Answer: An identified or identifiable natural person whose personal data is processed

    A data subject is a living, identified or identifiable natural person to whom personal data relates.

  8. Which of the following correctly distinguishes pseudonymization from anonymization under GDPR?

    Answer: Pseudonymized data is still personal data under GDPR because re-identification is possible with additional information

    GDPR Recital 26 clarifies that pseudonymized data remains personal data because it can be re-identified using separately held information, while truly anonymized data falls outside GDPR scope.

  9. A new mobile app will use biometric data for authentication. What makes this scenario particularly significant from a DPIA perspective?

    Answer: Biometric data is a special category under GDPR requiring heightened protection

    Biometric data used for unique identification is classified as a special category under GDPR Article 9, which imposes stricter processing conditions and heightens the need for a DPIA.

  10. A software development company needs a large, realistic dataset to test a new application's features and performance. However, using real customer production data is strictly forbidden by their privacy policy. Which PET provides the best solution for creating a statistically representative but entirely artificial dataset for this purpose?

    Answer: Synthetic Data Generation

    Synthetic data generation involves creating an entirely new, artificial dataset that preserves the statistical properties, patterns, and correlations of the original real data without containing any of the original data points. This makes it ideal for testing, development, and analysis without exposing real personal information.

  11. Which of the following BEST describes the concept of 'residual risk' in the context of a DPIA?

    Answer: Risk that remains after all identified mitigation measures have been applied

    Residual risk is the level of privacy risk that persists even after all feasible safeguards and mitigations have been implemented.

  12. An organization deploys federated learning for a machine learning model trained on personal health data across multiple hospitals. What is the PRIMARY privacy advantage over centralized training?

    Answer: Raw personal data never leaves each hospital's local environment

    Federated learning trains on local data at each node and shares only model updates (gradients), so raw personal health records are never centralized.

  13. Which privacy governance role is PRIMARILY responsible for ensuring data processing activities comply with applicable privacy laws on a day-to-day basis?

    Answer: Data Protection Officer (DPO)

    The DPO is the formal role under GDPR with specific independence and advisory responsibilities for monitoring compliance with data protection obligations.

  14. A company processes health data under a research exemption. What privacy control is MOST critical to implement?

    Answer: Pseudonymization of the health data before analysis

    Pseudonymization reduces re-identification risk while still enabling legitimate research under many privacy frameworks.

  15. A privacy engineer is evaluating a vendor's cloud storage service. Which cryptographic control gives the organization the STRONGEST assurance that the vendor cannot access stored personal data?

    Answer: Customer-managed keys stored in an external Hardware Security Module (HSM) the vendor cannot access

    Holding encryption keys in an external HSM that the vendor cannot access ensures that even with full access to ciphertext, the vendor cannot decrypt personal data.

  16. In the context of cookie consent, what does the ePrivacy Directive require before placing non-essential cookies?

    Answer: Prior informed consent from the user before placing non-essential cookies such as analytics or advertising cookies

    The ePrivacy Directive requires prior informed consent for non-essential cookies (analytics, advertising, tracking), while strictly necessary cookies are exempt.

  17. Under COPPA (Children's Online Privacy Protection Act), what is required before collecting personal data from children under 13 in the US?

    Answer: Verifiable parental consent obtained before collection begins

    COPPA mandates verifiable parental consent before any personal information is collected from children under 13, given their limited legal capacity to consent.

  18. A privacy engineer is evaluating two database architectures: one stores full PII for analytics, the other stores only hashed identifiers with separate re-identification keys held by a different team. Which principle does the second architecture embody?

    Answer: Separation of Duties combined with Pseudonymization

    Pseudonymization combined with separation of duties ensures that no single team can re-identify individuals, reducing insider threat and unauthorized linkage.

  19. An engineer is configuring logging for a system that processes health records. Which of the following is the MOST important privacy consideration for log files?

    Answer: PII should be redacted or tokenized in logs unless explicitly required for the audit purpose

    Logs frequently become secondary repositories of PII; redacting or tokenizing sensitive fields limits exposure while preserving operational and audit value.

  20. Which TLS configuration setting most directly reduces the risk of exposing personal data if a server's long-term private key is later compromised?

    Answer: Perfect Forward Secrecy (PFS)

    Perfect Forward Secrecy uses ephemeral session keys so that compromising the server's private key cannot decrypt previously recorded sessions.