Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CDPSE Exam Format and Time Management

Updated 9 min read
Key takeaway

CDPSE is a computer-based exam with 120 multiple-choice questions and 210 minutes.

  • ISACA describes items that may ask for the correct or best answer and may include scenarios supporting more than one question.
  • The average allowance is 105 seconds per item; answer all questions because incorrect responses are not penalized.
On this page6 sections
  1. Question count and time limit
  2. What scenario questions ask you to do
  3. A practical pacing plan
  4. Worked example: multiple questions from one scenario
  5. Reduce avoidable time loss
  6. Use question wording to locate the privacy decision A scenario may mention a data subject, product owner, privacy engineer, vendor, and security team in the same paragraph. Identify what the question asks before evaluating each role. “What should be assessed first?” differs from “which control reduces exposure?” and “who approves residual risk?” The right answer should match both the requested action and the actor with authority to take it. When several questions refer to one scenario, later items may test different parts of the same facts. Do not carry an answer from an earlier item forward unless the stem establishes that decision. One item may ask which data is necessary; another may ask how to restrict access after the collection design is approved. Re-read the final sentence so you answer the specific question, not the broader story. The exam presents 120 items in 210 minutes. The average is 105 seconds per item, but use checkpoints rather than rigid cutoffs. Reaching item 30 at about 52 minutes leaves roughly 158 minutes for 90 items. If you have used much more, make a reasoned choice on clear items and avoid spending several minutes debating two options that each require facts absent from the stem. Practice a two-pass reasoning habit On the first read, identify the purpose, sensitive data, affected person or system, and requested decision. On the second, compare the answers against those facts. A choice that protects data in general may still fail because it does not address the stated risk. If the item asks about retention, an access review alone is incomplete. If it asks about unauthorized disclosure, a future deletion schedule does not fix the current exposure. Use elimination carefully. Remove options that assume consent where the facts do not establish it, collect extra data without a stated need, or place responsibility on a party who does not control the decision. Then compare the remaining choices for scope and evidence. Choose the most direct answer supported by the stem rather than the most elaborate control stack. After a timed practice, note where time went. If scenario sets are slow because you reread every detail, summarize the facts in a short phrase. If you move quickly but miss qualifiers such as “first” or “least,” slow down at the actual ask. Time management improves when the reading habit targets the source of lost time, not through indiscriminate skimming.

Question count and time limit

The CDPSE exam has 120 multiple-choice questions and a 3.5-hour, or 210-minute, time limit. ISACA’s candidate guide describes conventional question stems and scenario questions. A scenario may provide one situation and ask two or more related questions. Candidates choose the correct or best answer from the options.

Dividing 210 minutes by 120 questions gives an average of 105 seconds per question. This is a pacing guide, not a rule that every item should take the same time. A short recognition question may take less than a minute. A scenario with several data flows, roles, or technical constraints may need more reading and comparison.

What scenario questions ask you to do

CDPSE questions can ask which action is best, what should happen first, or which control most directly addresses a stated concern. Look for the decision the stem is asking you to make. Several options may be reasonable in the long run, but only one may fit the current facts and sequence.

A scenario may describe a product change, a privacy assessment, a vendor, a rights request, or a technical safeguard. Separate facts from assumptions. Note the purpose, people affected, data involved, processing steps, decision authority, and evidence. Then identify whether the question concerns governance, risk and compliance, the data life cycle, or privacy engineering.

For example, if a team proposes a new data use but has not mapped the source, recipients, and retention, an immediate decision to buy an encryption tool may be premature. If a breach is underway, containment and incident procedures may take priority over a routine assessment. The words “first,” “best,” and “most” signal that order and scope matter.

A practical pacing plan

Begin by using the exam tutorial to understand the interface. During the exam, read the full stem before looking for familiar keywords. Identify the requested action and any constraints such as purpose, deadline, access, consent, or retention. If the answer is clear, select it and move on. If two choices remain, compare which one addresses the stated problem with the least unsupported assumption.

  1. Keep a steady pace and watch the remaining time at natural checkpoints.
  2. Answer straightforward items promptly without turning easy questions into extended debates.
  3. Spend additional time on scenarios that require comparing roles, evidence, or control scope.
  4. If the interface permits review, mark uncertain items and return after answering the rest.
  5. Reserve a final portion of time to check unanswered questions and confirm selections.

The exact review tools and navigation behavior are provided in the testing experience and tutorial. Learn the current interface rather than relying on a prep provider’s description. Whatever tools are available, do not leave questions blank: ISACA states that incorrect answers do not reduce the score.

Worked example: multiple questions from one scenario

A healthcare scheduling service wants to use appointment records to predict missed visits. A vendor will host the model. The organization has an existing notice that describes scheduling operations but says nothing about prediction. The data team has not mapped model inputs, vendor access, retention, or whether predictions affect appointment priority.

If asked for the best first action, map the proposed processing and clarify its purpose, data inputs, affected people, recipients, and expected decisions. That information supports a privacy-focused assessment and a requirements review. Jumping directly to encryption would address one security property while leaving purpose, fairness, access, retention, and notice unresolved.

If a second question asks which engineering control to prioritize after the use is approved, the answer could focus on limiting the vendor’s access to necessary fields and controlling use of outputs, depending on the facts supplied. Do not repeat the first answer automatically. The correct action changes with the question and the scenario’s stated stage.

A strong answer explanation should name the domain and explain why the chosen action fits now. It should also state why other options are incomplete: a notice alone is not a technical control, encryption does not determine whether a new purpose is appropriate, and a model accuracy test alone does not establish fair or compliant use.

Reduce avoidable time loss

Candidates often lose time by rereading without identifying the decision, applying a favorite framework that the question never invokes, or changing an answer because a distractor contains a familiar technical term. Use the facts provided. If the item supplies an organizational requirement, treat it as a constraint. If a legal conclusion depends on jurisdiction-specific facts not stated, avoid adding your own assumptions.

Another time trap is treating every question as a technical implementation problem. The correct action may be to clarify accountability, validate evidence, limit use, or obtain an authorized decision. Conversely, a governance answer is not automatically best when the scenario asks for a specific technical safeguard and provides enough design context.

During preparation, use timed sets to identify where time goes. If scenario reading is slow, practise summarizing each stem in one sentence. If you rush and miss qualifiers, pause before selecting and restate what the item asks. Track the reasoning pattern, not just whether a practice answer was right.

Use question wording to locate the privacy decision A scenario may mention a data subject, product owner, privacy engineer, vendor, and security team in the same paragraph. Identify what the question asks before evaluating each role. “What should be assessed first?” differs from “which control reduces exposure?” and “who approves residual risk?” The right answer should match both the requested action and the actor with authority to take it. When several questions refer to one scenario, later items may test different parts of the same facts. Do not carry an answer from an earlier item forward unless the stem establishes that decision. One item may ask which data is necessary; another may ask how to restrict access after the collection design is approved. Re-read the final sentence so you answer the specific question, not the broader story. The exam presents 120 items in 210 minutes. The average is 105 seconds per item, but use checkpoints rather than rigid cutoffs. Reaching item 30 at about 52 minutes leaves roughly 158 minutes for 90 items. If you have used much more, make a reasoned choice on clear items and avoid spending several minutes debating two options that each require facts absent from the stem. Practice a two-pass reasoning habit On the first read, identify the purpose, sensitive data, affected person or system, and requested decision. On the second, compare the answers against those facts. A choice that protects data in general may still fail because it does not address the stated risk. If the item asks about retention, an access review alone is incomplete. If it asks about unauthorized disclosure, a future deletion schedule does not fix the current exposure. Use elimination carefully. Remove options that assume consent where the facts do not establish it, collect extra data without a stated need, or place responsibility on a party who does not control the decision. Then compare the remaining choices for scope and evidence. Choose the most direct answer supported by the stem rather than the most elaborate control stack. After a timed practice, note where time went. If scenario sets are slow because you reread every detail, summarize the facts in a short phrase. If you move quickly but miss qualifiers such as “first” or “least,” slow down at the actual ask. Time management improves when the reading habit targets the source of lost time, not through indiscriminate skimming.

Use question wording to locate the privacy decision A scenario may mention a data subject, product owner, privacy engineer, vendor, and security team in the same paragraph. Identify what the question asks before evaluating each role. “What should be assessed first?” differs from “which control reduces exposure?” and “who approves residual risk?” The right answer should match both the requested action and the actor with authority to take it. When several questions refer to one scenario, later items may test different parts of the same facts. Do not carry an answer from an earlier item forward unless the stem establishes that decision. One item may ask which data is necessary; another may ask how to restrict access after the collection design is approved. Re-read the final sentence so you answer the specific question, not the broader story. The exam presents 120 items in 210 minutes. The average is 105 seconds per item, but use checkpoints rather than rigid cutoffs. Reaching item 30 at about 52 minutes leaves roughly 158 minutes for 90 items. If you have used much more, make a reasoned choice on clear items and avoid spending several minutes debating two options that each require facts absent from the stem. Practice a two-pass reasoning habit On the first read, identify the purpose, sensitive data, affected person or system, and requested decision. On the second, compare the answers against those facts. A choice that protects data in general may still fail because it does not address the stated risk. If the item asks about retention, an access review alone is incomplete. If it asks about unauthorized disclosure, a future deletion schedule does not fix the current exposure. Use elimination carefully. Remove options that assume consent where the facts do not establish it, collect extra data without a stated need, or place responsibility on a party who does not control the decision. Then compare the remaining choices for scope and evidence. Choose the most direct answer supported by the stem rather than the most elaborate control stack. After a timed practice, note where time went. If scenario sets are slow because you reread every detail, summarize the facts in a short phrase. If you move quickly but miss qualifiers such as “first” or “least,” slow down at the actual ask. Time management improves when the reading habit targets the source of lost time, not through indiscriminate skimming.

Common questions

How many CDPSE questions are there?

The exam has 120 multiple-choice questions.

How long is the exam?

210 minutes, or 3.5 hours.

How much time is available per question?

The average is 105 seconds, although scenario length varies.

Are there scenario questions?

Yes. ISACA says some questions may share a scenario and require answers to multiple related items.

Is there a penalty for a wrong answer?

No. ISACA says scoring is based on correct answers, so answer every question.