
Certified Data Privacy Solutions Engineer
Domain 2Objective 4
Threats and Vulnerabilities CDPSE Practice Questions (Page 3)
Part of the Privacy Risk Management and Compliance domain, which accounts for 18% of the CDPSE exam.
24questions here
5free pages
5concepts
18%of the exam
Questions 11–15
- 11
A privacy team has identified the following risks: (1) a critical vulnerability in a public-facing web application that could expose customer data, and (2) a low-likelihood phishing campaign targeting employees. Which risk should be prioritized for mitigation?
Select an answer first - 12
A company has identified that its customer support team uses shared login credentials for a CRM system containing personal data. Which of the following mitigation strategies would be most effective in reducing the risk of unauthorized access?
Select an answer first - 13
Which scenario BEST illustrates the analysis of the relationship between a threat and a vulnerability?
Select an answer first - 14
A privacy team has identified three risks: (1) a high-likelihood, medium-impact risk of phishing attacks, (2) a medium-likelihood, high-impact risk of a data breach due to unpatched servers, and (3) a low-likelihood, low-impact risk of unauthorized access to a test database. Which risk should be addressed first?
Select an answer first - 15
A government agency is transitioning to a cloud-based case management system. The agency handles sensitive citizen data and is subject to strict data residency requirements. The cloud provider offers regions in multiple countries, but the agency's legal team insists that data must remain within the country's borders. Which of the following is the most critical threat to consider during the transition?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CDPSE” is a trademark of its owner, used for identification only.