dc dotCreds
ISACA CDPSE Practice Test

ISACA CDPSE Practice Test

Start today’s free 10-question ISACA CDPSE set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full CDPSE bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 ISACA CDPSE questions

Use this ISACA CDPSE practice test to review ISACA Certified Data Privacy Solutions Engineer. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Privacy Frameworks Privacy Risk Management and Compliance (18%)

Leadership wants a target privacy posture for a new business model but teams are debating specific tools before agreeing on desired outcomes. Which response BEST addresses the actual privacy consequences?

Concept tested:
Question 2 of 10
Objective Risk Management Process and Policies Privacy Risk Management and Compliance (18%)

A new facial-recognition pilot has strong executive sponsorship. The project team wants to select controls before documenting the business objective and processing design. The preferred action should be both risk-proportionate and operationally supportable. What should be prioritized next?

Concept tested:
Question 3 of 10
Objective Data Quality (Accuracy) Data Life Cycle Management (23%)

A retailer buys demographic enrichment data quarterly, but no process evaluates source quality, age, or match confidence before the data affects customer segmentation. The controlling issue is the privacy effect of the actual processing, not whether an adjacent safeguard also has value. Which response MOST directly corrects the data-handling issue?

Concept tested:
Question 4 of 10
Objective Data Subject Rights, Requests, and Notification Privacy Governance (20%)

A controller receives a portability request for data provided by the individual, but the analyst proposes sending an internal risk score and proprietary inference model output as well. Which decision BEST addresses the control and accountability gap?

Concept tested:
Question 5 of 10
Objective Monitoring and Logging Privacy Engineering (39%)

Audit logs are editable by the same administrators whose privileged activity the logs are intended to record. Which design decision is MOST defensible?

Concept tested:
Question 6 of 10
Objective Threats and Vulnerabilities Privacy Risk Management and Compliance (18%)

A privacy review finds that an internal API returns every customer attribute even when consuming services use only three fields. No one is challenging the underlying business objective; the decision concerns the privacy control needed to support it. Which recommendation is MOST defensible under the stated facts?

Concept tested:
Question 7 of 10
Objective Data Disclosure and Transfer Data Life Cycle Management (23%)

A processor receives a controller instruction to disclose personal data to a new affiliate for analytics that is not described in the processing agreement. What is the MOST appropriate treatment of the data?

Concept tested:
Question 8 of 10
Objective Privacy Principles (Privacy by Design, Consent, Transparency) Privacy Governance (20%)

A smart-building project needs occupancy trends but does not need to identify individual employees to optimize HVAC schedules. Internal assurance will review the rationale, so the decision needs a clear and supportable privacy basis. Which option BEST supports an auditable privacy decision?

Concept tested:
Question 9 of 10
Objective Asset Management Privacy Engineering (39%)

A privacy engineer finds production datasets in analyst-owned cloud accounts that are not registered in the corporate asset inventory. The organization wants a control it can operate consistently and demonstrate during review. Which option BEST aligns the system with privacy engineering principles?

Concept tested:
Question 10 of 10
Objective Program Monitoring and Metrics Privacy Risk Management and Compliance (18%)

Training completion remains at 99%, but privacy incidents caused by unnecessary data collection have increased for three consecutive quarters. No unstated safeguards or legal exceptions should be assumed. Which decision BEST addresses the assessment or compliance gap?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CDPSE Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question CDPSE PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

ISACA Bundle $9.99 one-time

Unlock all 5 active ISACA Bundle practice banks in one permanent purchase.

What’s includedCISA, CISM, CRISC, CGEIT, CDPSE
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CDPSE bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CDPSE practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily ISACA CDPSE set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 Leadership wants a target privacy posture for a new business model but teams are debating specific tools before agreeing on desired outcomes. Which response BEST addresses the actual privacy consequences?

Answer choices

  1. A. Choose privacy products and controls first, then map their capabilities to framework categories for reporting, under this approach.
  2. B. Define the target privacy outcomes and gap priorities first, then select controls and technologies that support those outcomes, as configured.
  3. C. Standardize one technical implementation across subsidiaries and permit local variation only for documented legal exceptions, as the selected response to the described condition.
  4. D. Treat alignment to a recognized privacy framework as evidence that applicable legal obligations are satisfied, under the proposed approach.

Correct answer

Define the target privacy outcomes and gap priorities first, then select controls and technologies that support those outcomes, as configured.

The correct response is: Define the target privacy outcomes and gap priorities first, then select controls and technologies that support those outcomes. The scenario should be evaluated through the criterion of using a privacy framework to describe current and target outcomes, prioritize gaps, and integrate privacy risk with enterprise governance rather than treating the framework as a compliance checklist. The other choices may be useful in related circumstances, but they do not resolve the controlling issue presented here. Source basis: NIST Privacy Framework Version 1.0, Privacy Framework Core and Profiles.

Wrong-answer review

  • A. Choose privacy products and controls first, then map their capabilities to framework categories for reporting, under this approach.: This choice is insufficient in the stated context. Product mapping can document coverage, but it reverses the risk- and outcome-driven logic of framework use. Although “Choose privacy products and controls first, then map their capabilities to framework categories for reporting” may have value elsewhere, the governing test here is using a privacy framework to describe current and target outcomes, prioritize gaps, and integrate privacy risk with enterprise governance rather than treating the framework as a compliance checklist.
  • C. Standardize one technical implementation across subsidiaries and permit local variation only for documented legal exceptions, as the selected response to the described condition.: The scenario does not support option C as the best answer. A baseline can help governance, but implementation also needs to reflect risk, technology, processing, and business context. “Standardize one technical implementation across subsidiaries and permit local variation only for documented legal exceptions” is secondary to the requirement to address using a privacy framework to describe current and target outcomes, prioritize gaps, and integrate privacy risk with enterprise governance rather than treating the framework as a compliance checklist.
  • D. Treat alignment to a recognized privacy framework as evidence that applicable legal obligations are satisfied, under the proposed approach.: Option D addresses a neighboring concern rather than the primary one. Frameworks organize risk management but are not automatic legal safe harbors. The scenario turns on using a privacy framework to describe current and target outcomes, prioritize gaps, and integrate privacy risk with enterprise governance rather than treating the framework as a compliance checklist, which “Treat alignment to a recognized privacy framework as evidence that applicable legal obligations are satisfied” does not resolve.

Extra learning features

Why candidates miss this

The distractors ‘Choose privacy products and controls first, then map their capabilities to framework categories for reporting’ and ‘Standardize one technical implementation across subsidiaries and permit local variation only for documented legal exceptions’ are tempting because they represent common, albeit less effective, approaches to privacy. The decisive clue is the emphasis on using the framework to *describe* outcomes and prioritize gaps, not simply implementing controls. Likely wrong answer: Choose privacy products and controls first, then map their capabilities to framework categories for reporting. Review focus: NIST Privacy Framework Version 1.0

Interview question

Q: What is the difference between a privacy framework and a privacy policy? Strong answer: A privacy framework is a structured approach to managing privacy risks, while a privacy policy is a document that outlines an organization’s commitment to protecting personal information. The framework provides the governance and controls, while the policy details the specific rules and procedures.

  • framework vs policy
  • governance
  • controls
  • risk management
  • privacy commitment

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Objective/domain: Privacy Risk Management and Compliance (18%)

Source: NIST Privacy Framework Version 1.0

Question 2 A new facial-recognition pilot has strong executive sponsorship. The project team wants to select controls before documenting the business objective and processing design. The preferred action should be both risk-proportionate and operationally supportable. What should be prioritized next?

Answer choices

  1. A. Use the organization’s cybersecurity likelihood and impact matrix for privacy risks so both programs can be compared directly, under the stated decision criteria.
  2. B. Rate impact primarily through regulatory, litigation, and brand consequences to the organization, then note individual harms qualitatively, in context.
  3. C. Prioritize controls based on the highest technical vulnerability scores before separately documenting the underlying processing risk, as the selected response to the described condition.
  4. D. Frame the business objective and map the proposed data processing before prioritizing risks and selecting controls, under the described privacy risk management and compliance (18%) criteria.

Correct answer

Frame the business objective and map the proposed data processing before prioritizing risks and selecting controls, under the described privacy risk management and compliance (18%) criteria.

Objective/domain: Privacy Risk Management and Compliance (18%)

Source: NIST Privacy Risk Assessment Methodology (PRAM)

Question 3 A retailer buys demographic enrichment data quarterly, but no process evaluates source quality, age, or match confidence before the data affects customer segmentation. The controlling issue is the privacy effect of the actual processing, not whether an adjacent safeguard also has value. Which response MOST directly corrects the data-handling issue?

Answer choices

  1. A. Define data-quality criteria for external enrichment, including provenance, recency, match confidence, and remediation or rejection thresholds, for the stated implementation and support requirements.
  2. B. Validate format and required fields at ingestion, then rely on source-system owners to correct semantic inaccuracies later, for the stated requirement.
  3. C. Correct inaccurate values in the reporting layer first while a backlog is created to address upstream causes, for the described technical objective and its associated operational control requirements, for this task.
  4. D. Overwrite conflicting values with the highest-ranked reference source so downstream systems receive one consistent answer, for the described technical objective and its associated operational control requirements, within the defined security and accountability boundaries.

Correct answer

Define data-quality criteria for external enrichment, including provenance, recency, match confidence, and remediation or rejection thresholds, for the stated implementation and support requirements.

Objective/domain: Data Life Cycle Management (23%)

Source: Regulation (EU) 2016/679 (General Data Protection Regulation)

Question 4 A controller receives a portability request for data provided by the individual, but the analyst proposes sending an internal risk score and proprietary inference model output as well. Which decision BEST addresses the control and accountability gap?

Answer choices

  1. A. Use high-assurance identity proofing for every privacy request to minimize the chance of disclosure to an impostor, for the described technical objective and its associated operational control requirements.
  2. B. Search the authoritative system of record first and treat processor or archive searches as exception handling when the requester identifies a gap, for the specified implementation requirement.
  3. C. Correct the master record promptly and rely on normal synchronization schedules to update downstream systems, for the described technical objective and its associated operational control requirements, under this approach.
  4. D. Determine which data falls within the applicable portability right and provide that data in the required usable format without automatically including unrelated internal inferences.

Correct answer

Determine which data falls within the applicable portability right and provide that data in the required usable format without automatically including unrelated internal inferences.

Objective/domain: Privacy Governance (20%)

Source: Regulation (EU) 2016/679 (General Data Protection Regulation)

Question 5 Audit logs are editable by the same administrators whose privileged activity the logs are intended to record. Which design decision is MOST defensible?

Answer choices

  1. A. Collect detailed audit events but rely on incident-driven review instead of continuous alerting for privacy-relevant anomalies, for consideration.
  2. B. Permit privileged administrators to manage both the monitored service and its audit-retention configuration to simplify support, under this approach.
  3. C. Protect log integrity and restrict alteration so privileged activity remains independently auditable, for the described technical objective and its associated operational control requirements.
  4. D. Retain detailed logs on the same schedule as the primary business records so investigations have consistent historical coverage, for the stated scenario.

Correct answer

Protect log integrity and restrict alteration so privileged activity remains independently auditable, for the described technical objective and its associated operational control requirements.

Objective/domain: Privacy Engineering (39%)

Source: NIST SP 800-92: Guide to Computer Security Log Management

Question 6 A privacy review finds that an internal API returns every customer attribute even when consuming services use only three fields. No one is challenging the underlying business objective; the decision concerns the privacy control needed to support it. Which recommendation is MOST defensible under the stated facts?

Answer choices

  1. A. Use the existing cyber threat model and add personal-data assets so privacy and security teams can maintain one threat register, for the described technical objective and its associated operational control requirements, in context.
  2. B. Prioritize privacy vulnerabilities using exploitability and technical exposure, then assess individual consequences during remediation planning, within the documented scope, ownership, and validation boundaries.
  3. C. Identify overbroad API disclosure as a data-minimization and access-control weakness and redesign the response around purpose-necessary fields, within the documented operational, security, ownership, and validation requirements.
  4. D. Reduce the privacy-risk rating when strong encryption and access controls make unauthorized disclosure unlikely, as the selected response to the described condition.

Correct answer

Identify overbroad API disclosure as a data-minimization and access-control weakness and redesign the response around purpose-necessary fields, within the documented operational, security, ownership, and validation requirements.

Objective/domain: Privacy Risk Management and Compliance (18%)

Source: NIST Privacy Risk Assessment Methodology (PRAM)

Question 7 A processor receives a controller instruction to disclose personal data to a new affiliate for analytics that is not described in the processing agreement. What is the MOST appropriate treatment of the data?

Answer choices

  1. A. Encrypt the transfer end to end while sending the recipient the full available record to simplify reconciliation, for the specified implementation requirement.
  2. B. Use a standard transfer or processing template without validating whether its mechanism and clauses match the actual jurisdictions and roles, in the described situation.
  3. C. Use a strong confidentiality agreement and security schedule as the primary control while leaving processing purposes and return/deletion terms general, as the selected response to the described condition.
  4. D. Do not follow the expanded disclosure until the controller validates the new purpose, recipient, contractual authorization, and any required safeguards, under the stated decision criteria.

Correct answer

Do not follow the expanded disclosure until the controller validates the new purpose, recipient, contractual authorization, and any required safeguards, under the stated decision criteria.

Objective/domain: Data Life Cycle Management (23%)

Source: Regulation (EU) 2016/679 (General Data Protection Regulation)

Question 8 A smart-building project needs occupancy trends but does not need to identify individual employees to optimize HVAC schedules. Internal assurance will review the rationale, so the decision needs a clear and supportable privacy basis. Which option BEST supports an auditable privacy decision?

Answer choices

  1. A. Design the collection around aggregate or otherwise disassociated occupancy signals instead of persistent employee-level tracking, within the defined security and accountability boundaries.
  2. B. Expand the privacy notice to describe the optional processing in more detail while retaining the same default behavior, for consideration.
  3. C. Obtain a single onboarding consent covering all optional purposes and retain it as the user’s preference until withdrawal, within this context.
  4. D. Strengthen encryption and access controls while leaving the purpose, collection scope, and default settings unchanged, within the documented operational, security, ownership, and validation requirements.

Correct answer

Design the collection around aggregate or otherwise disassociated occupancy signals instead of persistent employee-level tracking, within the defined security and accountability boundaries.

Objective/domain: Privacy Governance (20%)

Source: Regulation (EU) 2016/679 (General Data Protection Regulation)

Question 9 A privacy engineer finds production datasets in analyst-owned cloud accounts that are not registered in the corporate asset inventory. The organization wants a control it can operate consistently and demonstrate during review. Which option BEST aligns the system with privacy engineering principles?

Answer choices

  1. A. Bring the shadow cloud assets into governance, identify the data and owner, and remediate or remove unauthorized copies, under organization-wide implementation-governance requirements.
  2. B. Use annual owner questionnaires as the authoritative inventory and reconcile only high-risk findings with technical discovery, in context.
  3. C. Exclude ephemeral compute from the personal-data asset inventory when no persistent volume is attached, within the documented operational, security, ownership, and validation requirements.
  4. D. Track deployed models and model owners but keep training-data lineage in the separate data-governance catalog, within the described operational context.

Correct answer

Bring the shadow cloud assets into governance, identify the data and owner, and remediate or remove unauthorized copies, under organization-wide implementation-governance requirements.

Objective/domain: Privacy Engineering (39%)

Source: NIST Privacy Framework Version 1.0

Question 10 Training completion remains at 99%, but privacy incidents caused by unnecessary data collection have increased for three consecutive quarters. No unstated safeguards or legal exceptions should be assumed. Which decision BEST addresses the assessment or compliance gap?

Answer choices

  1. A. Report a single enterprise average for each KPI and investigate material outliers outside the executive dashboard, for the described technical objective.
  2. B. Pair completion data with behavior and outcome metrics, investigate the adverse trend, and adjust training or controls based on root cause, under this approach.
  3. C. Track program outcomes against historical trends without explicit thresholds because risk tolerance changes over time, as the selected approach for the stated technical and business outcome.
  4. D. Use confirmed regulatory findings as the primary lagging outcome measure and treat internal control indicators as operational detail, as the proposed privacy risk management and compliance (18%) approach.

Correct answer

Pair completion data with behavior and outcome metrics, investigate the adverse trend, and adjust training or controls based on root cause, under this approach.

Objective/domain: Privacy Risk Management and Compliance (18%)

Source: NIST Privacy Framework Version 1.0

Where to go after the daily web set

How are ISACA CDPSE questions generated?

dotCreds builds ISACA CDPSE practice questions from public exam objectives and ISACA exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start ISACA CDPSE practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.