
Certified Data Privacy Solutions Engineer
Domain 4Objective 2
Security and Access Controls CDPSE Practice Questions (Page 2)
Part of the Privacy Engineering domain, which accounts for 39% of the CDPSE exam.
48questions here
10free pages
16concepts
39%of the exam
Questions 6–10
- 6
Which activity is a key component of the secure SDLC phase that involves verifying that security and privacy controls work as intended?
Select an answer first - 7
A multinational corporation is implementing a new IAM system. The security team wants to ensure that every user's identity is verified, that users can only access resources based on their role, and that all access attempts are recorded for audit. Which combination of IAM components directly addresses these three requirements?
Select an answer first - 8
What is the primary difference between an intrusion detection system (IDS) and an intrusion prevention system (IPS)?
Select an answer first - 9
Which secure communication protocol is commonly used to provide encrypted remote command-line access to servers?
Select an answer first - 10
A financial services firm is designing a new customer-facing application that will allow users to view account balances and initiate transfers. The privacy engineer is leading a threat modeling exercise. The team has identified that a user could potentially view another user's account details by manipulating the URL parameters. Which threat modeling technique would best help the team systematically identify and document this and similar risks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CDPSE” is a trademark of its owner, used for identification only.