HomeCDPSE Data Privacy Exam Prep IQuestions 11–20
CDPSE Data Privacy Exam Prep IPart 2 of 3

CDPSE Data Privacy Exam Prep I Exam Questions & Answers 2026 (11–20)

CDPSE Data Privacy Exam Prep I practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise CDPSE Data Privacy Exam Prep I questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q11Which of the following should be the FIRST step when implementing privacy-by-design principles for a new software application?

    • AImplement data minimization techniques
    • BConduct a privacy impact assessment (PIA)
    • CEncrypt all data at rest and in transit
    • DDefine data retention and disposal policies
    Show answer

    ✓ Correct answer: B. Conduct a privacy impact assessment (PIA)

    Conducting a privacy impact assessment (PIA) should be the first step when implementing privacy-by-design principles for a new software application.

  2. Q12A privacy professional is evaluating the enterprise architecture for a new data warehouse. Which of the following should be the MAIN focus to ensure privacy compliance?

    • AData classification and access controls
    • BData ingestion and transformation processes
    • CBackup and disaster recovery procedures
    • DData visualization and reporting capabilities
    Show answer

    ✓ Correct answer: A. Data classification and access controls

    The main focus should be on the data classification and access controls implemented within the enterprise architecture of the new data warehouse to ensure privacy compliance.

  3. Q13Which of the following is the MOST important consideration when selecting a privacy-enhancing technology (PET) to implement?

    • AIntegration with existing security controls
    • BCost and ease of implementation
    • CAdoption and use by industry peers
    • DAlignment with organizational privacy requirements
    Show answer

    ✓ Correct answer: D. Alignment with organizational privacy requirements

    The ability of the PET to align with the organization's privacy requirements is the most important consideration when selecting a privacy-enhancing technology to implement.

  4. Q14A privacy professional is reviewing the security risk assessment conducted by the cybersecurity team for a new software application. Which of the following should be the MAIN focus of the privacy professional's review?

    • ACompleteness of threat modeling and penetration testing
    • BAlignment with organizational security standards
    • CIdentification and mitigation of privacy-specific risks
    • DPrioritization of remediation efforts based on risk scores
    Show answer

    ✓ Correct answer: C. Identification and mitigation of privacy-specific risks

    The main focus of the privacy professional's review should be on the identification and mitigation of privacy-specific risks within the security risk assessment for the new software application.

  5. Q15What should be the MAIN objective when implementing privacy controls for a new mobile application?

    • AMinimize the amount of user data collected
    • BProtect the confidentiality, integrity, and availability of user data
    • CEnsure compliance with all relevant privacy regulations
    • DProvide users with transparency and control over their data
    Show answer

    ✓ Correct answer: B. Protect the confidentiality, integrity, and availability of user data

    The main objective when implementing privacy controls for a new mobile application should be to protect the confidentiality, integrity, and availability of user data collected by the application.

  6. Q16A privacy professional is evaluating the privacy implications of a new Internet of Things (IoT) device. Which of the following should be the MAIN focus of the evaluation?

    • AData collection, storage, and sharing practices
    • BPhysical security of the IoT device
    • CCompliance with industry standards for IoT devices
    • DUser interface and consent mechanisms
    Show answer

    ✓ Correct answer: A. Data collection, storage, and sharing practices

    The main focus of the evaluation should be on the data collection, storage, and sharing practices of the new IoT device, as this has the most significant privacy implications.

  7. Q17A privacy professional is reviewing the implementation of data classification controls within a new enterprise data management system. Which of the following should be the MOST important consideration?

    • AAutomation and integration with data management tools
    • BComprehensiveness of the data classification taxonomy
    • CEase of use for data owners and custodians
    • DAlignment with organizational data privacy and security policies
    Show answer

    ✓ Correct answer: D. Alignment with organizational data privacy and security policies

    The most important consideration when reviewing the implementation of data classification controls should be the alignment with the organization's data privacy and security policies.

  8. Q18A privacy professional is evaluating a proposed change to the enterprise data architecture. Which of the following should be the MAIN focus of the evaluation?

    • AScalability and performance of the new data architecture
    • BAlignment with the organization's data management strategy
    • CImpact on privacy compliance and risk management
    • DCost and resource requirements for the implementation
    Show answer

    ✓ Correct answer: C. Impact on privacy compliance and risk management

    The main focus of the evaluation should be on the impact of the proposed change on the organization's ability to comply with privacy regulations and manage privacy risks.

  9. Q19A privacy professional is reviewing the technical security controls implemented for a new cloud-based application. Which of the following should be the MOST important consideration?

    • ACompliance with the cloud service provider's security standards
    • BAbility to protect the confidentiality, integrity, and availability of customer data
    • CIntegration with the organization's existing security tools and processes
    • DCost and complexity of implementing the security controls
    Show answer

    ✓ Correct answer: B. Ability to protect the confidentiality, integrity, and availability of customer data

    The most important consideration when reviewing the technical security controls for a new cloud-based application should be the ability of those controls to protect the confidentiality, integrity, and availability of customer data.

  10. Q20A privacy professional is evaluating the privacy implications of a proposed change to an existing enterprise information system. Which of the following should be the FIRST step in the evaluation process?

    • AConduct a privacy impact assessment (PIA)
    • BReview the organization's privacy policies and procedures
    • CCollaborate with the system's owners and stakeholders
    • DAssess the technical security controls for the system
    Show answer

    ✓ Correct answer: A. Conduct a privacy impact assessment (PIA)

    The first step in the evaluation process should be to conduct a privacy impact assessment (PIA) to identify the potential privacy risks and impacts associated with the proposed change to the existing enterprise information system.

Free practice here. Timed mocks when you are ready.

Use the free CDPSE Data Privacy Exam Prep I sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.