CDPSE Sample Questions

CDPSE Sample Questions & Answers

Privacy engineering, including technology stacks and privacy-related security controls, carries by far the most weight, alongside privacy governance and day-to-day operations, risk management and compliance, and the data life cycle from collection to destruction.

Launch the full CDPSE simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Privacy Engineering · Anonymization and Pseudonymization

    True or False: Once personal data has been pseudonymized, it is no longer considered personal data under the GDPR and is exempt from its requirements.

    Show answer & explanation

    Correct answer: B

    This is false. The GDPR explicitly defines pseudonymization and considers pseudonymized data to still be personal data, as it can be re-identified with additional information. While pseudonymization is a recommended security measure that can reduce risks and help meet data protection principles, it does not remove the data from the scope of the regulation. Anonymized data, in contrast, is outside the scope of the GDPR.

  2. Question 2Intermediate

    Privacy Governance · Vendor and Supply Chain Management

    An e-commerce company uses a third-party cloud provider for hosting its entire infrastructure. The contract includes a Data Processing Agreement (DPA). During a routine audit, it is discovered that the cloud provider has been storing backup snapshots in a geographic region not specified in the DPA, a direct violation of the agreement. What is the MOST critical clause in the DPA that gives the e-commerce company leverage to address this issue?

    Show answer & explanation

    Correct answer: C

    The right to audit clause is the most critical contractual tool in this scenario. It grants the data controller (the e-commerce company) the authority to inspect and verify the data processor's (the cloud provider's) compliance with the DPA. This clause provides the legal basis to demand evidence, conduct an audit of the provider's storage locations, and enforce remediation for the contractual breach.

  3. Question 3Advanced

    Privacy Risk Management and Compliance · Program Monitoring and Metrics

    A privacy engineer is reviewing the metrics for the company's data subject access request (DSAR) process. They observe the following trends over the last quarter:

    • The number of incoming requests has increased by 50%.
    • The average time to completion has increased from 15 days to 28 days.
    • The number of requests requiring manual intervention by the legal team has tripled.

    Given these metrics, what is the MOST likely root cause of the performance degradation?

    Show answer & explanation

    Correct answer: C

    The combination of increased completion time and a tripling of manual legal interventions strongly points to a failure in the underlying automation. When automated tools cannot find or collate a subject's data from the various production and legacy systems, the process breaks down. This forces manual searches and requires legal review to ensure completeness and handle exceptions, which perfectly explains the observed metrics.

  4. Question 4AdvancedSelect 3

    Privacy Engineering · Connectivity

    A company is implementing a zero-trust security architecture to better protect personal data stored across its hybrid cloud environment. Which of the following are core principles and technologies required for this implementation? (Select THREE).

    Show answer & explanation

    Correct answers: B, C, D

    This is a foundational principle of zero trust. Every access request is treated as if it originates from an untrusted network, requiring rigorous verification each time.

    Another core tenet of zero trust is to grant the minimum level of access needed for a task, for the shortest time possible, to minimize the potential impact of a compromised account.

    Zero trust architecture operates on the assumption that a breach is inevitable or has already occurred. Technologies like micro-segmentation are used to create granular zones and policies that prevent an attacker from moving freely within the network.

  5. Question 5Intermediate

    Data Life Cycle Management · Data Disclosure and Transfer

    A multinational corporation wants to transfer personal data of its EU employees to its headquarters in the United States for payroll processing. Following recent legal precedents invalidating previous transfer mechanisms, the company seeks the most legally robust and defensible solution for this recurring transfer. Which option provides the highest level of assurance for this specific scenario?

    Show answer & explanation

    Correct answer: D

    For intra-group transfers within a multinational corporation, Binding Corporate Rules (BCRs) are considered the 'gold standard'. While more complex and time-consuming to establish than SCCs, they represent a comprehensive, approved framework for data protection across the entire corporate group. Once approved by a data protection authority, they provide a very strong legal basis for recurring, systematic transfers like payroll processing.

  6. Question 6Intermediate

    Privacy Engineering · Anonymization and Pseudonymization

    A manufacturing company is setting up a new data warehouse to analyze production line efficiency. To reduce the risk of re-identification of employee performance data within the warehouse datasets, while still allowing for statistical analysis, a privacy engineer ensures that each record in a released dataset is indistinguishable from at least 14 other records based on quasi-identifiers. This technique is known as ______.

    Show answer & explanation

    Correct answer: D

    k-anonymity is a property of a dataset where every record is indistinguishable from at least k-1 other records with respect to a set of quasi-identifiers. In this scenario, k is 15 (1 + 14). This technique protects against re-identification by making it difficult to link individuals to specific records.

  7. Question 7Advanced

    Privacy Risk Management and Compliance · Risk Management

    A retail company is implementing a new AI-powered customer analytics platform to personalize marketing campaigns. The platform will ingest customer purchase history, browsing behavior, and loyalty program data. A Privacy Impact Assessment (PIA) has been conducted to identify potential risks.

    The PIA identified several risks, including the potential for unauthorized access to the analytics database, the risk of customer profiles being re-identified from aggregated data, the risk of discriminatory outcomes from biased algorithmic models, and the risk of customers being unable to easily opt-out of the personalization.

    From a privacy engineering perspective, which of the identified risks should be considered the HIGHEST priority to mitigate first, as it presents the most direct and potentially harmful impact on individuals' rights and freedoms?

    Show answer & explanation

    Correct answer: C

    While all listed risks are significant, the risk of algorithmic bias leading to discriminatory outcomes is the highest priority. This type of risk can lead to systemic, unfair treatment of entire groups of customers (e.g., offering discounts only to certain demographics), which is a direct infringement on the fundamental rights to fairness and non-discrimination. Unlike a data breach, which is a potential event, biased decision-making is a continuous, operational harm that undermines the core principles of ethical data use and can have significant legal and reputational consequences.

  8. Question 8Intermediate

    Privacy Engineering · Encryption and Hashing

    A privacy engineer is hardening a new cloud-based database (DBaaS) that will store sensitive customer information, including payment details and personal identifiers. To provide the strongest data protection at rest, which configuration offers the most robust security and control?

    Show answer & explanation

    Correct answer: C

    While TDE with provider-managed keys is a good baseline, using a BYOK strategy with a customer-controlled HSM provides the highest level of security and control. This approach ensures that the cloud provider cannot access the encryption keys, and therefore cannot decrypt the data, even under a legal compulsion. It gives the customer ultimate control over their data's security lifecycle, including the ability to revoke access by destroying the key.

  9. Question 9Advanced

    Privacy Governance · Data Subject Rights, Requests, and Notification

    A data subject submits a valid request for erasure under GDPR Article 17. However, the data in question is part of a financial transaction record that the company is legally required to retain for seven years to comply with anti-money laundering (AML) regulations. What is the correct course of action for the organization?

    Show answer & explanation

    Correct answer: C

    GDPR Article 17(3)(b) provides an exemption to the right to erasure if processing is necessary for compliance with a legal obligation. The correct procedure is to acknowledge the request, inform the data subject that a legal obligation (AML regulations) prevents immediate deletion, restrict the data's processing to only what is necessary for that legal purpose, and inform them of the date when the retention period expires and their data will be deleted.

  10. Question 10Intermediate

    Data Life Cycle Management · Data Inventory, Dataflow Diagram, and Classification

    A privacy engineer is analyzing the following process flow for handling a Data Subject Access Request (DSAR). The goal is to identify the most significant privacy risk or control failure in the process.

    flowchart TD A[Request Received via Email] --> B{Verify Requester Identity}; B --> C[Email IT to 'Find All Data for User X']; C --> D[IT Admin Runs Manual Queries on Prod DB]; D --> E[IT Admin Compiles Results into Excel File]; E --> F[Email Excel File to Legal Team]; F --> G{Legal Review & Redaction}; G --> H[Email Final Report to Requester];
    Show answer & explanation

    Correct answer: C

    The most significant control failure is compiling a complete, sensitive data export into an unstructured format like an Excel file and then transmitting it insecurely via email. This action creates a new, high-risk data asset that is difficult to track, secure, and properly dispose of. It exposes the organization to a significant risk of data spillage or an internal breach, violating the principles of data minimization and security.

Ready for the real thing?

The full CDPSE simulator has every exam-style question, timed mode, and instant scoring.

Go to the CDPSE simulator →