ISACA CDPSE — Certified Data Privacy Solutions Engineer · Domain 3 · 23% of exam

Data Life Cycle Management

Drill 20 practice questions focused entirely on Data Life Cycle Management for the ISACA CDPSE exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A privacy solutions engineer is helping a healthcare analytics company build its data life cycle program. The company handles a mix of marketing contact lists, employee HR records, and patient clinical data. Leadership wants a foundational mechanism that will drive consistent handling — such as encryption strength, access restrictions, and retention periods — as each dataset moves through collection, processing, and disposal. What should the engineer establish FIRST to enable these differentiated controls across the data life cycle?

Reviewed for accuracy · Report an issue
Question 2 of 20

A retail company's mobile app initially collects only an email address to create an account, with the stated purpose of order confirmation. Over the following months, the product team wants to progressively collect additional data (birthdate, purchase preferences, location) as users interact with new features, to power a personalized recommendation engine. As the privacy engineer advising on the data life cycle, what is the MOST appropriate control to embed before this progressive collection begins?

Reviewed for accuracy · Report an issue
Question 3 of 20

A privacy engineer is reviewing a new marketing web form before launch. The business wants to capture as much prospect information as possible for future campaigns, so the form currently includes 22 fields, including date of birth, household income, and national ID number. The stated purpose is to send prospects an email newsletter and occasional product offers. Which action best aligns the form design with the data minimization and collection limitation principles?

Reviewed for accuracy · Report an issue
Question 4 of 20

A privacy engineer is reviewing an online registration form for a new loyalty program. The business purpose is limited to sending members promotional offers and tracking reward points. The current form collects name, email, home address, date of birth, mobile number, national ID number, and household income. The marketing team insists all fields are 'useful for future analytics we might do.' Which action BEST aligns the form with the collection limitation principle?

Reviewed for accuracy · Report an issue
Question 5 of 20

A fitness app product team wants to add a new feature that recommends nearby running routes. The proposed design requests continuous background access to precise GPS location, the device contact list, microphone, and calendar entries. As the data privacy solutions engineer reviewing the collection design against the data life cycle principle of collection limitation, which recommendation should you make?

Reviewed for accuracy · Report an issue
Question 6 of 20

A customer submits a valid erasure request, and the privacy team confirms the individual's personal data must be deleted from production systems. During execution, the data engineer notes that the same records also exist in encrypted backup tapes that are retained for 90 days on a rolling cycle for disaster recovery. Immediately overwriting the backups would break the recovery chain and violate the organization's business continuity obligations. What is the MOST appropriate way to handle the personal data residing on the backup media?

Reviewed for accuracy · Report an issue
Question 7 of 20

A privacy solutions engineer must decommission a customer's data from a multi-tenant SaaS platform where all tenants' encrypted records share the same underlying storage volumes and backup sets. The customer contract requires that their personal data be rendered permanently unrecoverable within 30 days of termination, but physical media cannot be destroyed because other active tenants' data resides on the same volumes. Which approach BEST satisfies the destruction requirement?

Reviewed for accuracy · Report an issue
Question 8 of 20

A financial services firm is decommissioning several on-premises servers containing customer personal data on solid-state drives (SSDs). The IT team proposes running a multi-pass overwrite utility, the same procedure historically used on the firm's magnetic hard drives, to sanitize the SSDs before the servers are sold to a refurbisher. As the privacy solutions engineer reviewing the disposal plan, what is your MOST important concern?

Reviewed for accuracy · Report an issue
Question 9 of 20

A retailer terminates a contract with a cloud-based marketing analytics processor that held several million customer records. The contract requires the processor to destroy all personal data upon termination. As the data privacy solutions engineer, what is the MOST important action to ensure the disposal obligation is actually met?

Reviewed for accuracy · Report an issue
Question 10 of 20

A privacy engineer maintains data flow diagrams for a customer analytics platform. The platform team has just integrated a new third-party enrichment API that appends demographic attributes to existing customer records before they are loaded into the warehouse. The enrichment adds no new source systems, but the data now includes attributes not present in the original collection. What should the privacy engineer do FIRST to keep the data mapping accurate and support downstream lifecycle controls?

Reviewed for accuracy · Report an issue
Question 11 of 20

A privacy solutions engineer is reviewing a newly created data flow diagram for a customer loyalty program. The diagram accurately depicts systems, storage locations, and cross-border transfers. However, during review the engineer notices that one downstream analytics platform receives transaction data that was originally collected only to process reward redemptions. What is the engineer's MOST important next action based on this observation?

Reviewed for accuracy · Report an issue
Question 12 of 20

During a review of a retailer's website, a privacy solutions engineer discovers that the current data flow diagrams do not reflect several third-party JavaScript tags (advertising and analytics pixels) that transmit visitor identifiers to external vendors. Marketing added these tags directly through the tag manager without notifying privacy or IT. What is the MOST important reason to update the data flow diagrams to capture these tags before taking other action?

Reviewed for accuracy · Report an issue
Question 13 of 20

A privacy engineer is asked to update the organization's data flow diagrams for a customer relationship management (CRM) platform before a new marketing analytics initiative launches. During the mapping exercise, the engineer discovers that a subprocessor replicates a copy of customer records to a data center in a third country that is not documented in the current record of processing activities or any transfer mechanism. What should the privacy engineer do FIRST?

Reviewed for accuracy · Report an issue
Question 14 of 20

A privacy solutions engineer is establishing the organization's first enterprise data inventory to support Data Life Cycle Management. During initial interviews, several business units confirm they store customer personal data in departmentally-provisioned SaaS tools and local spreadsheets that were never registered with IT. Which action should the engineer take FIRST to ensure the data inventory accurately reflects where personal data resides?

Reviewed for accuracy · Report an issue
Question 15 of 20

A privacy engineer is building the organization's first data inventory to support Data Life Cycle Management. The engineering team has already catalogued each data store with system name, hosting location, data owner, and the categories of personal data held. During review, the DPO notes that the inventory cannot be used to enforce retention limitation or purpose limitation because a critical attribute is missing. Which attribute should be added to each inventory entry to MOST directly enable these controls?

Reviewed for accuracy · Report an issue
Question 16 of 20

A privacy engineer at a fast-growing fintech company established a data inventory 18 months ago as a one-time project. Since then, the company launched three new mobile products, acquired a competitor, and migrated several systems to the cloud. During a recent regulatory inquiry, the company could not accurately identify all systems processing customer financial data. Which action would MOST effectively prevent this problem from recurring?

Reviewed for accuracy · Report an issue
Question 17 of 20

A privacy engineer is supporting a project that migrates customer records from an on-premises order-management system into a new SaaS platform. During the extract-transform-load (ETL) process, the team discovers that several free-text 'notes' fields in the legacy system contain embedded personal data (e.g., health remarks, alternate contact details) that were never part of the documented data model. What should the privacy engineer recommend FIRST before the load step proceeds?

Reviewed for accuracy · Report an issue
Question 18 of 20

A retail company is migrating customer records from an aging on-premises CRM to a new cloud-based data warehouse that will support both operations and analytics. The legacy CRM has accumulated 15 years of records, including many inactive accounts, duplicate entries, and free-text notes fields containing sensitive personal data collected under purposes that no longer apply. The project manager wants to lift-and-shift all records as-is to meet the migration deadline, then clean up later. As the privacy solutions engineer, what should you recommend FIRST?

Reviewed for accuracy · Report an issue
Question 19 of 20

A data privacy solutions engineer discovers that a marketing analytics team routinely exports customer datasets from the production data warehouse into ad-hoc spreadsheets and personal cloud drives to build campaign models. Each export creates uncontrolled copies of personal data that persist indefinitely, outside any retention schedule or access control. Which action should the engineer prioritize to address the underlying data persistence risk?

Reviewed for accuracy · Report an issue
Question 20 of 20

A privacy solutions engineer reviews a company's data storage strategy. Active customer records are kept in a high-performance database, while records inactive for over two years are automatically moved to a low-cost cold storage tier. During the review, the engineer finds that cold storage retains records indefinitely because the archival process was designed only to reduce storage cost, with no linkage to the customers' original retention requirements. What is the engineer's BEST recommendation to align this persistence practice with privacy principles?

Reviewed for accuracy · Report an issue

More CDPSE practice

Keep going with the other ISACA CDPSE — Certified Data Privacy Solutions Engineer domains, or take a full timed mock exam.

← Back to CDPSE overview