Technical Privacy Controls Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Technical Privacy Controls flashcards as text
Which technique allows a dataset to be shared while ensuring that no combination of attributes can uniquely identify an individual by guaranteeing at least k records share each combination of quasi-identifiers?
Answer: k-anonymity
k-anonymity ensures each record is indistinguishable from at least k-1 others based on quasi-identifier combinations, reducing re-identification risk.
A privacy engineer notes that a k-anonymized dataset still reveals sensitive attribute values through homogeneity attack. Which enhancement addresses this?
Answer: Applying l-diversity to ensure diversity of sensitive values within each equivalence class
l-diversity extends k-anonymity by requiring that each equivalence class contains at least l well-represented distinct sensitive values, preventing homogeneity attacks.
An organization deploys federated learning for a machine learning model trained on personal health data across multiple hospitals. What is the PRIMARY privacy advantage over centralized training?
Answer: Raw personal data never leaves each hospital's local environment
Federated learning trains on local data at each node and shares only model updates (gradients), so raw personal health records are never centralized.
A privacy engineer is reviewing cookie consent implementation. Which technical configuration ensures that a session cookie is not accessible to JavaScript (mitigating XSS-based cookie theft)?
Answer: Setting the HttpOnly attribute on the cookie
The HttpOnly flag instructs the browser not to expose the cookie to JavaScript APIs, preventing XSS scripts from stealing session cookies containing user identity.
What is the primary privacy risk associated with embedding third-party fonts, scripts, or pixels directly from external CDNs in a web application?
Answer: The user's IP address and browser fingerprint are exposed to the third-party server on each page load
Each request to an external CDN reveals the user's IP address, referrer URL, and browser details to the third party, enabling tracking without the user's knowledge.
A CDPSE practitioner is assessing a biometric authentication system. Which control BEST mitigates the risk that compromised biometric templates cannot be replaced like passwords?
Answer: Using cancelable biometrics (transformed/revocable templates) rather than raw biometric data
Cancelable biometrics apply a revocable transformation so that if a template is compromised, a new transformation can be issued—unlike raw biometric data which cannot be changed.
An engineer needs to ensure that personal data in a database cannot be altered or deleted without detection. Which control provides tamper evidence for stored records?
Answer: Cryptographic hashing with hash chaining or a Merkle tree structure
Hash chaining or Merkle trees create a cryptographic dependency between records so that any modification to historical data is immediately detectable by recomputing the chain.