ISACA CDPSE — Certified Data Privacy Solutions Engineer · Domain 2 · 18% of exam

Privacy Risk Management and Compliance

Drill 20 practice questions focused entirely on Privacy Risk Management and Compliance for the ISACA CDPSE exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A privacy solutions engineer reviews DPIAs completed by five different business units over the past year. Each unit used its own approach to rate privacy risks, and the resulting risk ratings vary widely for processing activities that involve similar data and similar risk exposure. Senior management cannot compare or prioritize the risks across units. What should the engineer recommend FIRST to address this problem?

Reviewed for accuracy · Report an issue
Question 2 of 20

A privacy engineer completes a DPIA for a new AI-driven credit scoring platform that processes large volumes of financial data and produces automated decisions affecting individuals. After applying all feasible technical and organizational controls, the assessment shows that the residual risk to data subjects remains high. What should the privacy engineer recommend as the NEXT step before the processing begins?

Reviewed for accuracy · Report an issue
Question 3 of 20

A privacy engineer is conducting a DPIA for a new employee wellness platform that will collect health-related biometric data through wearable devices. The DPIA has documented the processing operations, assessed necessity and proportionality, and identified several high risks to employees. Before finalizing the assessment and treatment plan, which action best strengthens the DPIA in accordance with recognized privacy risk management practice?

Reviewed for accuracy · Report an issue
Question 4 of 20

A retailer plans to deploy an AI-driven system that continuously analyzes in-store video feeds combined with loyalty-card purchase history to profile individual shoppers and predict future buying behavior at scale. The privacy engineer must advise the project team on the required first step before development proceeds. Which action is MOST appropriate?

Reviewed for accuracy · Report an issue
Question 5 of 20

An internal privacy audit team is scheduled to assess whether the organization's data retention controls are operating effectively across three business units. Each unit has documented retention schedules and automated deletion jobs. The audit lead wants to provide the audit committee with assurance about how the controls actually perform in practice, not just whether they exist. Which approach will BEST support this assurance objective?

Reviewed for accuracy · Report an issue
Question 6 of 20

A privacy solutions engineer is supporting an internal audit of data subject access request (DSAR) handling across a large customer service organization that processes thousands of requests monthly. The auditor wants to conclude whether the DSAR control is operating effectively throughout the audit period, but the team lacks the time to review every request. What is the MOST appropriate approach for gathering audit evidence?

Reviewed for accuracy · Report an issue
Question 7 of 20

A privacy audit conducted six months ago identified several control deficiencies in a company's marketing data platform. Management submitted remediation plans and reported that all corrective actions are now complete. As the privacy solutions engineer supporting the audit function, what is the MOST important action to take before closing the audit findings?

Reviewed for accuracy · Report an issue
Question 8 of 20

A privacy manager plans an audit of a critical cloud payroll processor that handles employee personal data on the organization's behalf. When defining the audit scope, the processor's contract states that on-site inspections are limited to once per year with 30 days' notice, and the processor offers an independent SOC 2 Type II report and ISO 27701 certificate as alternatives. What should the privacy manager do FIRST to ensure the audit provides adequate assurance over the processor's privacy controls?

Reviewed for accuracy · Report an issue
Question 9 of 20

A privacy officer at a multinational insurer has rolled out mandatory annual privacy awareness training to all employees. Twelve months later, senior management asks for evidence that the training is actually reducing privacy risk within the organization. Completion rates are consistently above 98%. Which of the following would BEST demonstrate the effectiveness of the privacy awareness program?

Reviewed for accuracy · Report an issue
Question 10 of 20

A privacy officer at a healthcare technology company has just completed a compliance gap assessment against a newly applicable data protection regulation. The assessment identified 47 gaps across multiple processing activities, ranging from missing retention schedules to inadequate legal bases for certain data flows. The remediation budget and staff are limited, and the regulation takes effect in six months. What should the privacy officer do FIRST to determine the sequence of remediation efforts?

Reviewed for accuracy · Report an issue
Question 11 of 20

During a privacy control assessment, a CDPSE reviews the organization's data subject access request (DSAR) handling process. The documented procedure requires identity verification, a 30-day response window, and manager sign-off before disclosure. The procedure is well-designed and approved, but the assessor finds that over the past six months, 40% of DSARs were fulfilled without any recorded identity verification step. What is the MOST accurate conclusion the assessor should report?

Reviewed for accuracy · Report an issue
Question 12 of 20

A retail company completed a DPIA for a new customer loyalty analytics platform before launch, identifying and treating several privacy risks. The platform has now been operational for eight months. During this period, the analytics vendor introduced a new machine-learning feature that profiles customers to predict purchasing behavior, and the volume of processed data has tripled. The privacy officer wants to ensure the DPIA remains a living document. What is the MOST appropriate action?

Reviewed for accuracy · Report an issue
Question 13 of 20

A multinational retailer operating in the EU, US, and Asia has grown through acquisitions, resulting in fragmented and inconsistent privacy practices across regions. The newly appointed data privacy officer wants to establish a single, structured foundation that maps privacy activities to core privacy principles while remaining adaptable to multiple jurisdictions' laws. Which action should the privacy officer take FIRST to achieve this?

Reviewed for accuracy · Report an issue
Question 14 of 20

A privacy program manager compiles a quarterly privacy dashboard for the steering committee using data pulled from the ticketing system (data subject requests), the incident register, and vendor assessment logs. During review, a committee member questions whether the reported 'average DSAR response time of 12 days' can be trusted, noting that several requests were logged manually after the fact and some were closed without a documented completion date. What should the privacy manager do FIRST to address this concern?

Reviewed for accuracy · Report an issue
Question 15 of 20

A privacy officer is designing a dashboard for continuous monitoring of the privacy program. Executive leadership has complained that the current metrics only reveal problems after they have already caused harm, such as the number of breaches reported and regulatory fines incurred. Leadership wants earlier visibility so corrective action can be taken proactively. Which metric would BEST address this concern?

Reviewed for accuracy · Report an issue
Question 16 of 20

A privacy engineer discovers that PIAs at their organization are consistently initiated only after a new system has entered user acceptance testing, shortly before go-live. As a result, several projects have required costly rework to address privacy findings, and one launch was delayed. What is the MOST effective way to address this recurring problem?

Reviewed for accuracy · Report an issue
Question 17 of 20

A newly appointed privacy officer at a financial services firm is establishing the privacy risk management program. During a workshop, the executive team asks how they should decide which identified privacy risks require formal treatment plans versus which can proceed without additional action. The privacy officer wants to give the organization a consistent, board-endorsed basis for making these decisions across all business units. What should the privacy officer establish FIRST to enable this?

Reviewed for accuracy · Report an issue
Question 18 of 20

A privacy solutions engineer is building a privacy risk register for a new customer-loyalty platform. The team has identified a risk that a misconfigured API could expose customer purchase histories. Before recommending any controls, the engineer wants to prioritize this risk consistently against others in the register. Which approach BEST supports consistent prioritization of this identified privacy risk?

Reviewed for accuracy · Report an issue
Question 19 of 20

A privacy solutions engineer is designing the continuous monitoring component of the privacy program. Leadership wants early warning when privacy risk levels begin trending toward unacceptable exposure, before an actual incident occurs. Which approach BEST supports proactive privacy risk monitoring?

Reviewed for accuracy · Report an issue
Question 20 of 20

A privacy solutions engineer maintains a risk register for a customer analytics platform that was last formally assessed 14 months ago. During a routine review, the engineer learns that the platform has recently begun ingesting geolocation data from a new mobile app, and the organization has expanded operations into two additional countries. Which action should the engineer take FIRST?

Reviewed for accuracy · Report an issue

More CDPSE practice

Keep going with the other ISACA CDPSE — Certified Data Privacy Solutions Engineer domains, or take a full timed mock exam.

← Back to CDPSE overview