Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Isaca CDPSE Practice Exam with Questions & Answers | Set: 3

Questions 21

To ensure the protection of personal data, privacy policies should mandate that access to information system applications be authorized by the.

Options:
A.

general counsel.

B.

database administrator.

C.

business application owner

D.

chief information officer (CIO)

Isaca CDPSE Premium Access
Questions 22

Which of the following BEST enables an organization to ensure privacy-related risk responses meet organizational objectives?

Options:
A.

Integrating security and privacy control requirements into the development of risk scenarios

B.

Prioritizing privacy-related risk scenarios as part of enterprise risk management ERM) processes

C.

Using a top-down approach to develop privacy-related risk scenarios for the organization

D.

Assigning the data protection officer accountability for privacy protection controls

Questions 23

Which of the following is a foundational goal of data privacy laws?

Options:
A.

Privacy laws are designed to protect companies' collection of personal data

B.

Privacy laws are designed to prevent the collection of personal data

C.

Privacy laws are designed to provide transparency for the collection of personal data

D.

Privacy laws are designed to give people rights over the collection of personal data

Questions 24

Which of the following is BEST used to validate compliance with agreed-upon service levels established with a third party that processes personal data?

Options:
A.

Key risk indicators (KRIs)

B.

Key performance indicators (KPIS)

C.

Industry benchmarks

D.

Contractual right to audit

Questions 25

An organization uses analytics derived from archived transaction data to create individual customer profiles for customizing product and service offerings. Which of the following is the IT privacy practitioner’s BEST recommendation?

Options:
A.

Anonymize personal data.

B.

Discontinue the creation of profiles.

C.

Implement strong access controls.

D.

Encrypt data at rest.

Questions 26

It is MOST important to consider privacy by design principles during which phase of the software development life cycle (SDLC)?

Options:
A.

Application design

B.

Requirements definition

C.

Implementation

D.

Testing

Questions 27

Which of the following should be established FIRST before authorizing remote access to a data store containing personal data?

Options:
A.

Privacy policy

B.

Network security standard

C.

Multi-factor authentication

D.

Virtual private network (VPN)

Questions 28

Which of the following is the BEST way to address privacy concerns when an organization captures personal data from a third party through an open application

programming interface (API)?

Options:
A.

Develop a service level agreement (SLA) with the third party

B.

Implement encryption for the data transmission

C.

Obtain consent from the data subjects

D.

Review the specification document of the open API.

Questions 29

Which of the following scenarios should trigger the completion of a privacy impact assessment (PIA)?

Options:
A.

Updates to data quality standards

B.

New inter-organizational data flows

C.

New data retention and backup policies

D.

Updates to the enterprise data policy

Questions 30

Who is ULTIMATELY accountable for the protection of personal data collected by an organization?

Options:
A.

Data processor

B.

Data owner

C.

Data custodian

D.

Data protection officer

Exam Code: CDPSE
Certification Provider: Isaca
Exam Name: Certified Data Privacy Solutions Engineer
Last Update: Jul 15, 2025
Questions: 218

Isaca Free Exams

Isaca Free Exams
Examstrack offers comprehensive free resources and practice tests for Isaca exams.