🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer63 / 147
Question 63 of 147
A privacy engineer is designing a new internal REST API that will allow multiple downstream teams to request customer records. During architecture review, the engineer must decide how the API should behave when a calling service requests fields for which no specific access grant or documented purpose has been configured. Which design approach best embodies privacy by default?
Reviewed for accuracy · Report an issueNext question