
Isaca Certification CDPSE Real Exam Questions and Answers FREE Updated on Feb 19, 2022
CDPSE Ultimate Study Guide - PracticeDump
ISACA Data Privacy Solutions Engineer Exam Syllabus Topics:
| Topic | Details | Weights |
|---|---|---|
| Privacy Architecture (Infrastructure, Applications/Software and Technical Privacy Controls) | - Coordinate and/or perform privacy impact assessment (PIA) and other privacy-focused assessments to identify appropriate tracking technologies, and technical privacy controls. - Participate in the development of privacy control procedures that align with privacy policies and business needs. - Implement procedures related to privacy architecture that align with privacy policies. - Collaborate with cybersecurity personnel on the security risk assessment process to address privacy compliance and risk mitigation - Collaborate with other practitioners to ensure that privacy programs and practices are followed during the design, development, and implementation of systems, applications, and infrastructure. - Evaluate the enterprise architecture and information architecture to ensure it supports privacy by design principles and considerations. - Evaluate advancements in privacy-enhancing technologies and changes in the regulatory landscape. - Identify, validate, and/or implement appropriate privacy and security controls according to data classification procedures. | 36% |
| Privacy Governance (Governance, Management and Risk Management) | -Identify the internal and external privacy requirements specific to the organization's governance and risk management programs and practices. - Participate in the evaluation of privacy policies, programs, and policies for their alignment with legal requirements, regulatory requirements, and/or industry best practices. - Coordinate and/or perform privacy impact assessments (PIA) and other privacy-focused assessments. - Participate in the development of procedures that align with privacy policies and business needs. - Implement procedures that align with privacy policies. - Participate in the management and evaluation of contracts, service levels, and practices of vendors and other external parties. - Participate in the privacy incident management process. - Collaborate with cybersecurity personnel on the security risk assessment process to address privacy compliance and risk mitigation. - Collaborate with other practitioners to ensure that privacy programs and practices are followed during the design, development, and implementation of systems, applications, and infrastructure. - Develop and/or implement a prioritization process for privacy practices. - Develop, monitor, and/or report performance metrics and trends related to privacy practices. - Report on the status and outcomes of privacy programs and practices to relevant stakeholders. - Participate in privacy training and promote awareness of privacy practices. - Identify issues requiring remediation and opportunities for process improvement. | 34% |
| Data Lifecycle (Data Purpose and Data Persistence) | - Identify the internal and external privacy requirements relating to the organization's data lifecycle practices. - Coordinate and/or perform privacy impact assessments (PIA) and other privacy-focused assessments relating to the organization’s data lifecycle practices. - Participate in the development of data lifecycle procedures that align with privacy policies and business needs. - Implement procedures related to data lifecycle that align with privacy policies. - Collaborate with other practitioners to ensure that privacy programs and practices are followed during the design, development, and implementation of systems, applications, and infrastructure. - Evaluate the enterprise architecture and information architecture to ensure it supports privacy by design principles and data lifecycle considerations. - Identify, validate, and/or implement appropriate privacy and security controls according to data classification procedures. - Design, implement, and/or monitor processes and procedures to keep the inventory and dataflow records current. | 30% |
NEW QUESTION 62
Which of the following is the best reason for a health organization to use desktop virtualization to implement stronger access control to systems containing patient records?
- A. Unlimited functionalities and highly secured applications
- B. Limited functions and capabilities of a secured operating environment
- C. Improved data integrity and reduced effort for privacy audits
- D. Monitored network activities for unauthorized use
Answer: D
NEW QUESTION 63
When choosing data sources to be used within a big data architecture, which of the following data attributes MUST be considered to ensure data is not aggregated?
- A. Accuracy
- B. Consistency
- C. Reliability
- D. Granularity
Answer: D
NEW QUESTION 64
Which of the following system architectures BEST supports anonymity for data transmission?
- A. Plug-in-based
- B. Client-server
- C. Front-end
- D. Peer-to-peer
Answer: B
NEW QUESTION 65
Which key stakeholder within an organization should be responsible for approving the outcomes of a privacy impact assessment (PIA)?
- A. Data custodian
- B. Data processor
- C. Privacy data analyst
- D. Data owner
Answer: D
NEW QUESTION 66
A migration of personal data involving a data source with outdated documentation has been approved by senior management. Which of the following should be done NEXT?
- A. Ensure appropriate data classification.
- B. Engage an external auditor to review the source data.
- C. Review data flow post migration.
- D. Check the documentation version history for anomalies.
Answer: C
NEW QUESTION 67
How can an organization BEST ensure its vendors are complying with data privacy requirements defined in their contracts?
- A. Compare contract requirements against vendor deliverables.
- B. Obtain independent assessments of the vendors' data management processes.
- C. Review self-attestations of compliance provided by vendor management.
- D. Perform penetration tests of the vendors' data security.
Answer: A
NEW QUESTION 68
Which of the following MUST be available to facilitate a robust data breach management response?
- A. Lessons learned from prior data breach responses
- B. An inventory of previously impacted individuals
- C. An inventory of affected individuals and systems
- D. Best practices to obfuscate data for processing and storage
Answer: A
NEW QUESTION 69
Which of the following should be considered personal information?
- A. Age
- B. University affiliation
- C. Company address
- D. Biometric records
Answer: D
NEW QUESTION 70
Data collected by a third-party vendor and provided back to the organization may not be protected according to the organization's privacy notice. Which of the following is the BEST way to address this concern?
- A. Re-assess the information security requirements.
- B. Validate contract compliance.
- C. Obtain independent assurance of current practices.
- D. Review the privacy policy.
Answer: A
NEW QUESTION 71
It is MOST important to consider privacy by design principles during which phase of the software development life cycle (SDLC)?
- A. Implementation
- B. Testing
- C. Application design
- D. Requirements definition
Answer: B
NEW QUESTION 72
Which of the following is the BEST way to manage different IT staff access permissions for personal data within an organization?
- A. Role-based access control
- B. Network segmentation
- C. Mandatory access control
- D. Dedicated access system
Answer: A
NEW QUESTION 73
Which of the following is MOST important to ensure when developing a business case for the procurement of a new IT system that will process and store personal information?
- A. Data protection requirements are included.
- B. Security controls are clearly defined.
- C. A risk assessment has been completed.
- D. The system architecture is clearly defined.
Answer: A
NEW QUESTION 74
Which of the following is the PRIMARY consideration to ensure control of remote access is aligned to the privacy policy?
- A. Active remote access is monitored.
- B. Access is only granted to authorized users.
- C. Multi-factor authentication is enabled.
- D. Access is logged on the virtual private network (VPN).
Answer: B
NEW QUESTION 75
Which of the following poses the GREATEST privacy risk for client-side application processing?
- A. Failure of a firewall protecting the company network
- B. A remote employee placing communication software on a company server
- C. An employee loading personal information on a company laptop
- D. A distributed denial of service attack (DDoS) on the company network
Answer: B
NEW QUESTION 76
Which of the following should be established FIRST before authorizing remote access to a data store containing personal data?
- A. Multi-factor authentication
- B. Virtual private network (VPN)
- C. Network security standard
- D. Privacy policy
Answer: D
NEW QUESTION 77
What is the PRIMARY means by which an organization communicates customer rights as it relates to the use of their personal information?
- A. Mailing rights documentation to customers
- B. Publishing a privacy notice
- C. Distributing a privacy rights policy
- D. Gaining consent when information is collected
Answer: D
NEW QUESTION 78
When a government's health division established the complete privacy regulation for only the health market, which privacy protection reference model is being used?
- A. Co-regulatory
- B. Comprehensive
- C. Self-regulatory
- D. Sectoral
Answer: B
NEW QUESTION 79
Which of the following vulnerabilities is MOST effectively mitigated by enforcing multi-factor authentication to obtain access to personal information?
- A. End users forgetting their passwords
- B. Organizations using weak encryption to transmit data
- C. Vulnerabilities existing in authentication pages
- D. End users using weak passwords
Answer: D
NEW QUESTION 80
Before executive leadership approves a new data privacy policy, it is MOST important to ensure:
- A. a legal review is conducted.
- B. a distribution methodology is identified.
- C. a privacy committee is established.
- D. a training program is developed.
Answer: C
NEW QUESTION 81
Which of the following is the GREATEST benefit of adopting data minimization practices?
- A. Storage and encryption costs are reduced.
- B. Compliance requirements are met.
- C. The associated threat surface is reduced.
- D. Data retention efficiency is enhanced.
Answer: D
Explanation:
Unfortunately, the financial liability portion of retained personal information rarely shows up on an organization's financial balance sheet. And yet it is indeed a liability: the impact on an organization when cybercriminals steal that information or when the information is misused is real, in the form of breach response costs, the costs related to reducing harm inflicted on affected parties (think of credit monitoring services, a frequent remedy for stolen credit card numbers), fines from governmental regulators, and the occasional class-action lawsuit.
NEW QUESTION 82
......
ISACA CDPSE Exam Certification Details:
| Passing Score | 450 / 800 |
| Books / Training | Virtual Instructor-Led Training In-Person Training & Conferences Customized, On-Site Corporate Training CDPSE Planning Guide |
| Sample Questions | ISACA CDPSE Sample Questions |
| Exam Name | ISACA Certified Data Privacy Solutions Engineer (CDPSE) |
| Schedule Exam | Exam Registration |
| Exam Code | CDPSE |
| Number of Questions | 120 |
Ultimate Guide to Prepare CDPSE Certification Exam for Isaca Certification: https://www.practicedump.com/CDPSE_actualtests.html
Use Real CDPSE Dumps - ISACA Correct Answers: https://drive.google.com/open?id=14cc9uZKtl7U3ITsvkfpHD-k8Z66jzJ3I