ISACA CDPSE Certification Sample Questions

CDPSE Dumps, CDPSE PDF, CDPSE VCE, ISACA Data Privacy Solutions Engineer VCE, ISACA Data Privacy Solutions Engineer PDFThe purpose of this Sample Question Set is to provide you with information about the ISACA Data Privacy Solutions Engineer (CDPSE) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CDPSE certification test. To get familiar with real exam environment, we suggest you try our Sample ISACA Data Privacy Solutions Engineer Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual ISACA Certified Data Privacy Solutions Engineer (CDPSE) certification exam.

These sample questions are simple and basic questions that represent likeness to the real ISACA Data Privacy Solutions Engineer exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium ISACA CDPSE Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

ISACA CDPSE Sample Questions:

01. The MOST effective way to incorporate privacy by design principles into applications is to include privacy requirements in:
a) software testing guidelines.
b) senior management approvals.
c) software development practices.
d) secure coding practices
 
02. Which of the following is the BEST way to ensure that application hardening is included throughout the software development life cycle (SDLC)?
a) Include qualified application security personnel as part of the process.
b) Ensure comprehensive application security testing immediately prior to release.
c) Require an annual third-party audit of new client software solutions.
d) Require an annual internal audit of SDLC processes.
 
03. To ensure the protection of personal data, privacy policies should mandate that access to information system applications be authorized by the:
a) general counsel.
b) business application owner.
c) chief information officer (CIO).
d) database administrator.
 
04. Which of the following should an organization do FIRST to ensure it can respond to all data subject access requests in a timely manner?
a) Create a policy for handling access requests.
b) Confirm what is required for disclosure.
c) Understand the data in its possession.
d) Invest in a platform to automate data review.
 
05. An organization's work-from-home policy allows employees to access corporate IT assets remotely. Which of the following controls is MOST important to mitigate the risk of potential personal data compromise?
a) Firewall rules review
b) Intrusion detection system (IDS)
c) Intrusion prevention system (IPS)
d) Encryption of network traffic
 
06. Which of the following BEST enables an organization to ensure privacy-related risk responses meet organizational objectives?
a) Prioritizing privacy-related risk scenarios as part of enterprise risk management (ERM) processes
b) Assigning the data protection officer accountability for privacy protection controls
c) Integrating security and privacy control requirements into the development of risk scenarios
d) Using a top-down approach to develop privacy-related risk scenarios for the organization
 
07. An organization is considering whether to expand its operations into additional international jurisdictions. After performing a privacy risk assessment, the organization decides not to begin operating in those jurisdictions. Which of the following BEST describes this type of risk response?
a) Risk acceptance
b) Risk avoidance
c) Risk transfer
d) Risk reduction
 
08. When is the BEST time during the secure development life cycle to perform privacy threat modeling?
a) Prior to the production release
b) When identifying business requirements
c) During functional verification testing
d) Early in the design phase
 
09. A multi-national organization has decided that regional human resources (HR) team members must be limited in their access to employee data only within their regional office. Which of the following is the BEST approach?
a) Discretionary access control (DAC)
b) Attribute-based access control (ABAC)
c) Provision-based access control (PBAC)
d) Mandatory access control (MAC)
 
10. Which of the following is the BEST way to reduce the risk of compromise when transferring personal information using email?
a) Centrally managed encryption
b) Password-protected .zip files
c) End user-managed encryption
d) Private cloud storage space

Answers:

Question: 01
Answer: c
Question: 02
Answer: a
Question: 03
Answer: b
Question: 04
Answer: c
Question: 05
Answer: d
Question: 06
Answer: a
Question: 07
Answer: b
Question: 08
Answer: d
Question: 09
Answer: b
Question: 10
Answer: a

Note: For any error in ISACA Certified Data Privacy Solutions Engineer (CDPSE) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.9 / 5 (84 votes)