Enhance Your Career With Available Preparation Guide for CDPSE Exam [Q14-Q36]

Share

Enhance Your Career With Available Preparation Guide for CDPSE Exam

Get Special Discount Offer of CDPSE Certification Exam Sample Questions and Answers


ISACA CDPSE Exam Certification Details:

Exam Price ISACA Nonmember$760 (USD)
Schedule ExamExam Registration
Exam NameISACA Certified Data Privacy Solutions Engineer (CDPSE)
Books / TrainingVirtual Instructor-Led Training
In-Person Training & Conferences
Customized, On-Site Corporate Training
CDPSE Planning Guide
Duration210 mins
Passing Score450 / 800
Exam CodeCDPSE
Exam Price ISACA Member$575 (USD)
Number of Questions120

 

NEW QUESTION 14
An organization want to develop an application programming interface (API) to seamlessly exchange personal data with an application hosted by a third-party service provider. What should be the FIRST step when developing an application link?

  • A. Data hashing
  • B. Data normalization
  • C. Data mapping
  • D. Data tagging

Answer: C

 

NEW QUESTION 15
Data collected by a third-party vendor and provided back to the organization may not be protected according to the organization's privacy notice. Which of the following is the BEST way to address this concern?

  • A. Re-assess the information security requirements.
  • B. Validate contract compliance.
  • C. Review the privacy policy.
  • D. Obtain independent assurance of current practices.

Answer: A

 

NEW QUESTION 16
Which of the following is the BEST way to distinguish between a privacy risk and compliance risk?

  • A. Perform a privacy risk audit.
  • B. Validate a privacy risk attestation.
  • C. Conduct a privacy risk remediation exercise.
  • D. Conduct a privacy risk assessment.

Answer: A

 

NEW QUESTION 17
Which of the following protocols BEST protects end-to-end communication of personal data?

  • A. Hypertext Transfer Protocol (HTTP)
  • B. Transport Layer Security Protocol (TLS)
  • C. Secure File Transfer Protocol (SFTP)
  • D. Transmission Control Protocol (TCP)

Answer: B

 

NEW QUESTION 18
Which of the following helps define data retention time is a stream-fed data lake that includes personal data?

  • A. Information security assessments
  • B. Data privacy standards
  • C. Privacy impact assessments (PIAs)
  • D. Data lake configuration

Answer: C

 

NEW QUESTION 19
During the design of a role-based user access model for a new application, which of the following principles is MOST important to ensure data privacy is protected?

  • A. Two-person rule
  • B. Segregation of duties
  • C. Unique user credentials
  • D. Need-to-know basis

Answer: B

 

NEW QUESTION 20
A global financial institution is implementing data masking technology to protect personal data used for testing purposes in non-production environments. Which of the following is the GREATEST challenge in this situation?

  • A. Complex relationships within and across systems must be retained for testing.
  • B. Access to personal data is not strictly controlled in development and testing environments.
  • C. Personal data across the various interconnected systems cannot be easily identified.
  • D. Data masking tools are complex and difficult to implement.

Answer: D

 

NEW QUESTION 21
Which of the following helps to ensure the identities of individuals in two-way communication are verified?

  • A. Secure Shell (SSH)
  • B. Virtual private network (VPN)
  • C. Transport Layer Security (TLS)
  • D. Mutual certificate authentication

Answer: D

 

NEW QUESTION 22
Which of the following is the BEST way to protect personal data in the custody of a third party?

  • A. Include requirements to comply with the organization's privacy policies in the contract.
  • B. Add privacy-related controls to the vendor audit plan.
  • C. Have corporate counsel monitor privacy compliance.
  • D. Require the third party to provide periodic documentation of its privacy management program.

Answer: A

Explanation:
In GDPR parlance, organizations that use third-party service providers are often, but not always, considered data controllers, which are entities that determine the purposes and means of the processing of personal data, which can include directing third parties to process personal data on their behalf. The third parties that process data for data controllers are known as data processors.

 

NEW QUESTION 23
An organization is concerned with authorized individuals accessing sensitive personal customer information to use for unauthorized purposes. Which of the following technologies is the BEST choice to mitigate this risk?

  • A. User behavior analytics
  • B. Mobile device management (MDM)
  • C. Intrusion monitoring
  • D. Email filtering system

Answer: C

 

NEW QUESTION 24
An organization is developing a wellness smartwatch application and is considering what information should be collected from the application users. Which of the following is the MOST legitimate information to collect for business reasons in this situation?

  • A. Sleep schedule and calorie intake
  • B. Height, weight, and activities
  • C. Education and profession
  • D. Race, age, and gender

Answer: A

 

NEW QUESTION 25
An organization wants to ensure that endpoints are protected in line with the privacy policy. Which of the following should be the FIRST consideration?

  • A. Hardening the operating systems of endpoint devices
  • B. Implementing network traffic filtering on endpoint devices
  • C. Managing remote access and control
  • D. Detecting malicious access through endpoints

Answer: B

 

NEW QUESTION 26
Which of the following is the GREATEST obstacle to conducting a privacy impact assessment (PIA)?

  • A. The organization lacks knowledge of PIA methodology.
  • B. PIAs need to be performed many times in a year.
  • C. The value proposition of a PIA is not understood by management.
  • D. Conducting a PIA requires significant funding and resources.

Answer: A

 

NEW QUESTION 27
Which of the following tracking technologies associated with unsolicited targeted advertisements presents the GREATEST privacy risk?

  • A. Beacon-based tracking
  • B. Radio frequency identification (RFID)
  • C. Online behavioral tracking
  • D. Website cookies

Answer: D

 

NEW QUESTION 28
Which of the following should be of GREATEST concern when an organization wants to store personal data in the cloud?

  • A. The organization's potential legal liabilities related to the data
  • B. Any vulnerabilities identified in the cloud system
  • C. The data recovery capabilities of the storage provider
  • D. The data security policies and practices of the storage provider

Answer: D

 

NEW QUESTION 29
Which of the following BEST ensures a mobile application implementation will meet an organization's data security standards?

  • A. Privacy impact assessment (PIA)
  • B. User acceptance testing (UAT)
  • C. Automatic dynamic code scan
  • D. Data classification

Answer: A

 

NEW QUESTION 30
Within a business continuity plan (BCP), which of the following is the MOST important consideration to ensure the ability to restore availability and access to personal data in the event of a data privacy incident?

  • A. Online backup frequency
  • B. Offline backup availability
  • C. Recovery point objective (RPO)
  • D. Recovery time objective (RTO)

Answer: C

 

NEW QUESTION 31
Which of the following is MOST important when designing application programming interfaces (APIs) that enable mobile device applications to access personal data?

  • A. The user's ability to select, filter, and transform data before it is shared
  • B. Umbrella consent for multiple applications by the same developer
  • C. Unlimited retention of personal data by third parties
  • D. User consent to share personal data

Answer: D

 

NEW QUESTION 32
A migration of personal data involving a data source with outdated documentation has been approved by senior management. Which of the following should be done NEXT?

  • A. Engage an external auditor to review the source data.
  • B. Check the documentation version history for anomalies.
  • C. Review data flow post migration.
  • D. Ensure appropriate data classification.

Answer: C

 

NEW QUESTION 33
Which of the following BEST represents privacy threat modeling methodology?

  • A. Systematically eliciting and mitigating privacy threats in a software architecture
  • B. Mitigating inherent risks and threats associated with privacy control weaknesses
  • C. Reliably estimating a threat actor's ability to exploit privacy vulnerabilities
  • D. Replicating privacy scenarios that reflect representative software usage

Answer: B

 

NEW QUESTION 34
Which of the following is the BEST way for an organization to limit potential data exposure when implementing a new application?

  • A. Implement a data loss prevention (DLP) system.
  • B. Use only the data required by the application.
  • C. Encrypt all data used by the application.
  • D. Capture the application's authentication logs.

Answer: A

 

NEW QUESTION 35
Which of the following poses the GREATEST privacy risk for client-side application processing?

  • A. A distributed denial of service attack (DDoS) on the company network
  • B. Failure of a firewall protecting the company network
  • C. A remote employee placing communication software on a company server
  • D. An employee loading personal information on a company laptop

Answer: C

 

NEW QUESTION 36
......

Updated CDPSE Dumps Questions Are Available For Passing ISACA Exam: https://www.certkingdompdf.com/CDPSE-latest-certkingdom-dumps.html

New CDPSE Dumps For Preparing Isaca Certification Certified ISACA Exam Well: https://drive.google.com/open?id=1Ij4987DWTFiVXtSj2U-EpOs43uTGhZZC