Technical Privacy Controls Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Technical Privacy Controls flashcards as text
A web application encodes user-submitted data before rendering it in the browser. Which privacy-relevant attack does this primarily prevent?
Answer: Cross-site scripting (XSS)
Output encoding prevents XSS by ensuring user-supplied content is treated as data rather than executable script, protecting session cookies and personal data from theft.
Which TLS configuration setting most directly reduces the risk of exposing personal data if a server's long-term private key is later compromised?
Answer: Perfect Forward Secrecy (PFS)
Perfect Forward Secrecy uses ephemeral session keys so that compromising the server's private key cannot decrypt previously recorded sessions.
An organization implements a Content Security Policy (CSP) header. Which privacy threat does this primarily mitigate?
Answer: Third-party tracking scripts loading unauthorized resources
CSP restricts which sources can load scripts and resources, preventing unauthorized third-party trackers or data-exfiltration scripts from executing.
A CDPSE candidate is reviewing an API that returns full user objects including SSN and date of birth even when only the username is needed. Which privacy principle is violated?
Answer: Data minimization
Returning more personal data than the consuming application needs violates data minimization, which requires collecting and exposing only data adequate and relevant for the specified purpose.
What is the technical function of a 'salt' when hashing passwords for storage?
Answer: It is a random value prepended to the password before hashing to defeat precomputed rainbow tables
A salt is a unique random value added to each password before hashing, ensuring identical passwords produce different hashes and rendering precomputed rainbow tables useless.
Which storage-level control protects personal data on a laptop against disclosure if the device is stolen?
Answer: Full-disk encryption (FDE)
Full-disk encryption renders data on a stolen device unreadable without the decryption key, protecting personal data against physical access attacks.
A privacy engineer needs to prevent internal analysts from seeing raw PII in a production database while still enabling query-based analytics. Which control is MOST appropriate?
Answer: Dynamic data masking that substitutes real values at query time for unauthorized users
Dynamic data masking presents masked values to unauthorized users at query time without altering the underlying stored data, balancing utility and privacy.