
Certified Data Privacy Solutions Engineer
Domain 2Objective 4
Threats and Vulnerabilities CDPSE Practice Questions (Page 2)
Part of the Privacy Risk Management and Compliance domain, which accounts for 18% of the CDPSE exam.
24questions here
5free pages
5concepts
18%of the exam
Questions 6–10
- 6
A company has a policy that allows employees to use personal USB drives to transfer data. The privacy team has identified this as a risk because USB drives can be lost or stolen, leading to data breaches. Which of the following mitigation strategies would be most effective?
Select an answer first - 7
A multinational corporation stores employee HR data in a legacy on-premises system. The system has a known unpatched vulnerability that could allow remote code execution. The company also uses a modern cloud-based HR platform for new hires, which is fully patched. An attacker has been observed scanning the network for vulnerable systems. Which of the following best describes the risk exposure for the employee data?
Select an answer first - 8
Which of the following is an example of a vulnerability in a process that could compromise privacy?
Select an answer first - 9
Which of the following is an example of a mitigation strategy for a privacy threat?
Select an answer first - 10
A company has two privacy risks: (1) a high-likelihood, low-impact risk of unauthorized access to non-sensitive marketing data, and (2) a low-likelihood, high-impact risk of a data breach of sensitive customer financial data. The company has limited resources. Which risk should be prioritized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CDPSE” is a trademark of its owner, used for identification only.