Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CDPSE Practice Questions with Explanations

Updated 9 min read
Key takeaway

These original CDPSE-style questions practise privacy governance, risk, data life cycle, and engineering decisions.

  • Choose an answer before reading each explanation, then examine why the alternatives are weaker.
  • They are independent study examples, not ISACA exam items, a full mock, or a predictor of the official scaled score.
On this page7 sections
  1. How to use the questions
  2. Question 1: purpose and data minimization
  3. Question 2: honor a deletion request
  4. Question 3: respond to an active exposure
  5. Question 4: assess a vendor model
  6. Review the reasoning, not only the key
  7. Question 5: test whether retention works A service has an approved retention schedule, but the engineering team cannot show whether expired records are removed from a reporting store. Which evidence best tests the control? A. The policy and employee acknowledgment B. A sample of expired records traced through the deletion process, with completion results C. A list of employees who attended privacy training D. A screenshot of the account settings page Answer: B. The question asks whether the control operates in the reporting store. A policy describes the intended rule, but it does not prove deletion. Training concerns awareness, and a settings screen may show user controls without showing back-end retention. Trace a sample through the actual process and record the outcome. Question 6: limit an interface response A mobile application needs to show delivery status. Its API currently returns a customer's full profile, although the screen uses only order status and estimated arrival. Which change most directly applies data minimization? A. Encrypt the full profile before returning it B. Return only the order fields the screen requires C. Increase the profile retention period D. Ask the customer to accept a longer privacy notice Answer: B. The API should expose only information needed for the stated function. Encryption can protect confidentiality but does not reduce unnecessary disclosure to the application. Increasing retention holds the data longer, and a notice does not make an excessive response necessary. How to learn from a question set For each item, identify the requirement and decision point before reading the key. Then label the distractor that was most tempting. If you chose encryption for an overbroad response, the gap may be confusing protection with minimization. If you chose a policy document as evidence of execution, you may be confusing design with operation. After reviewing the explanation, change one fact and predict what should change. If an application needs a postal address to deliver a package, that field may be necessary for the transaction. If the same address is also used for marketing, the question becomes one of purpose, choice, access and retention. Varying facts tests whether the concept transfers. Keep question-bank percentages in context. They describe that question set and cannot be converted to the official scaled score. Use repeated performance on new mixed items, explanations of the alternatives, and coverage of all four domains as complementary readiness evidence. These original examples teach reasoning and are not a prediction of ISACA exam content.

How to use the questions

Read each scenario, identify what the question asks, and choose one option before reading the key. Notice qualifiers such as first, best, or most important. Then explain what facts support the answer, who has authority, and which domain or task is involved. The questions below are original examples and do not copy or reconstruct ISACA exam items.

The official CDPSE exam has 120 multiple-choice questions in 210 minutes. A handful of practice examples cannot reproduce that experience or estimate the 450 scaled passing threshold. Use them to test a line of reasoning, then practise with current official materials and the full outline.

Question 1: purpose and data minimization

A fitness app wants to collect precise location every minute to recommend nearby classes. The recommendation feature only needs the user’s city. What is the strongest design recommendation?

  1. Collect precise location and rely on encryption to address privacy concerns.
  2. Collect only the coarse location needed for the feature, explain the purpose, and allow the feature to work without continuous precise tracking where feasible.
  3. Keep all location records indefinitely in case the company adds features later.
  4. Remove names from the location table and treat the data as anonymous.

Correct answer: B. The feature can use less precise data, so minimization and purpose limitation reduce exposure at the source. Transparency and choice should fit the actual processing. Encryption remains useful but does not justify collecting unnecessary detail. Indefinite retention conflicts with a defined need. Removing names alone does not establish anonymity because location trails can identify people or be linked with other data.

Question 2: honor a deletion request

A customer requests account deletion. The service removes the primary profile but retains purchase data in an analytics warehouse and a vendor backup. The organization has a documented retention obligation for some transactions. What should the privacy team do next?

  1. Confirm that the primary profile is gone and close the request immediately.
  2. Delete every copy at once, including records that must be retained under the stated obligation.
  3. Trace the affected copies, apply the applicable retention rule, restrict any data that must remain, and coordinate deletion or expiry across analytics and vendor systems.
  4. Ask the vendor to certify deletion without checking what it received or what backup process applies.

Correct answer: C. The team needs an end-to-end view of the data and must distinguish records that can be deleted from those retained for a defined obligation. Restrict use and document the basis for retained data, then coordinate the lifecycle across the warehouse and provider. A primary-system deletion alone is incomplete. Immediate deletion can violate the stated obligation, while an unsupported vendor statement does not show which copies were addressed.

Question 3: respond to an active exposure

A developer discovers that an API response exposed personal information to users who should not see it. The application is still sending the response. Which action should happen first?

  1. Wait for the next scheduled privacy impact assessment to review the API.
  2. Contain the exposure through the incident process, preserve relevant evidence, and notify the responsible privacy and security roles for assessment and response.
  3. Publish a new privacy notice before changing the API.
  4. Delete all application logs so the information cannot be viewed again.

Correct answer: B. The exposure is active, so containment and incident handling take priority while evidence is preserved and appropriate roles are engaged. A routine assessment can follow or run in parallel. A notice does not stop the disclosure, and deleting logs can destroy evidence needed to understand scope and response obligations.

Question 4: assess a vendor model

A service provider proposes using customer support transcripts to improve its general-purpose model. The contract permits processing for the company’s service, but the team has not assessed whether general model improvement fits that purpose. What is the best next step?

  1. Allow the provider to proceed because the contract permits service processing.
  2. Clarify the proposed use, map the information and affected parties, assess purpose and risk against requirements, and resolve permitted use and safeguards before sharing data.
  3. Rely on removal of account names as proof that transcripts are anonymous.
  4. Add a longer retention period so the provider can improve the model consistently.

Correct answer: B. The proposed secondary use must be understood and assessed before data are shared. The contract’s service purpose does not automatically authorize general model training. Removing names may leave sensitive details or re-identification paths. Longer retention increases exposure and does not resolve the purpose question. The assessment should inform whether the use is permitted and which technical or contractual controls are needed.

Review the reasoning, not only the key

Across the examples, the best answer begins with the actual problem. Minimize data when the feature does not need precision. Trace copies when a request spans systems. Contain an active exposure before routine review. Clarify purpose before accepting a vendor’s secondary use. A control is valuable when it fits the risk and leaves evidence of operation.

For each wrong answer, name its flaw: it skips assessment, uses a security measure to justify excessive collection, confuses pseudonymization with anonymity, ignores retention obligations, or assumes a contract resolves every issue. Then modify the scenario and see whether the answer changes. If an exposure is active, containment may come first; if a design is still proposed, assessment and requirements mapping may precede implementation.

Question 5: test whether retention works A service has an approved retention schedule, but the engineering team cannot show whether expired records are removed from a reporting store. Which evidence best tests the control? A. The policy and employee acknowledgment B. A sample of expired records traced through the deletion process, with completion results C. A list of employees who attended privacy training D. A screenshot of the account settings page Answer: B. The question asks whether the control operates in the reporting store. A policy describes the intended rule, but it does not prove deletion. Training concerns awareness, and a settings screen may show user controls without showing back-end retention. Trace a sample through the actual process and record the outcome. Question 6: limit an interface response A mobile application needs to show delivery status. Its API currently returns a customer's full profile, although the screen uses only order status and estimated arrival. Which change most directly applies data minimization? A. Encrypt the full profile before returning it B. Return only the order fields the screen requires C. Increase the profile retention period D. Ask the customer to accept a longer privacy notice Answer: B. The API should expose only information needed for the stated function. Encryption can protect confidentiality but does not reduce unnecessary disclosure to the application. Increasing retention holds the data longer, and a notice does not make an excessive response necessary. How to learn from a question set For each item, identify the requirement and decision point before reading the key. Then label the distractor that was most tempting. If you chose encryption for an overbroad response, the gap may be confusing protection with minimization. If you chose a policy document as evidence of execution, you may be confusing design with operation. After reviewing the explanation, change one fact and predict what should change. If an application needs a postal address to deliver a package, that field may be necessary for the transaction. If the same address is also used for marketing, the question becomes one of purpose, choice, access and retention. Varying facts tests whether the concept transfers. Keep question-bank percentages in context. They describe that question set and cannot be converted to the official scaled score. Use repeated performance on new mixed items, explanations of the alternatives, and coverage of all four domains as complementary readiness evidence. These original examples teach reasoning and are not a prediction of ISACA exam content.

Question 5: test whether retention works A service has an approved retention schedule, but the engineering team cannot show whether expired records are removed from a reporting store. Which evidence best tests the control? A. The policy and employee acknowledgment B. A sample of expired records traced through the deletion process, with completion results C. A list of employees who attended privacy training D. A screenshot of the account settings page Answer: B. The question asks whether the control operates in the reporting store. A policy describes the intended rule, but it does not prove deletion. Training concerns awareness, and a settings screen may show user controls without showing back-end retention. Trace a sample through the actual process and record the outcome. Question 6: limit an interface response A mobile application needs to show delivery status. Its API currently returns a customer's full profile, although the screen uses only order status and estimated arrival. Which change most directly applies data minimization? A. Encrypt the full profile before returning it B. Return only the order fields the screen requires C. Increase the profile retention period D. Ask the customer to accept a longer privacy notice Answer: B. The API should expose only information needed for the stated function. Encryption can protect confidentiality but does not reduce unnecessary disclosure to the application. Increasing retention holds the data longer, and a notice does not make an excessive response necessary. How to learn from a question set For each item, identify the requirement and decision point before reading the key. Then label the distractor that was most tempting. If you chose encryption for an overbroad response, the gap may be confusing protection with minimization. If you chose a policy document as evidence of execution, you may be confusing design with operation. After reviewing the explanation, change one fact and predict what should change. If an application needs a postal address to deliver a package, that field may be necessary for the transaction. If the same address is also used for marketing, the question becomes one of purpose, choice, access and retention. Varying facts tests whether the concept transfers. Keep question-bank percentages in context. They describe that question set and cannot be converted to the official scaled score. Use repeated performance on new mixed items, explanations of the alternatives, and coverage of all four domains as complementary readiness evidence. These original examples teach reasoning and are not a prediction of ISACA exam content.

Common questions

Are these official CDPSE questions?

No. They are original examples, not ISACA exam items.

Can these questions predict my score?

No. The set is small and has no official scaled-score conversion.

What should CDPSE practice cover?

The current four domains, applied through realistic decisions and explained alternatives.

How should I review a wrong answer?

Name the missed task, unsupported assumption, and evidence that would change the decision.

Is ISACA’s free quiz a full mock?

No. ISACA describes it as a 10-question quiz.