Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Data Privacy Solutions Engineer

Domain 1Objective 6

Vendor and Supply Chain Management CDPSE Practice Questions (Page 5)

Part of the Privacy Governance domain, which accounts for 20% of the CDPSE exam.

32questions here
7free pages
8concepts
20%of the exam

Questions 21–25

  1. 21expert · hard

    A company's vendor, a data analytics provider, suffers a breach that exposes personal data of the company's customers. The vendor's contract requires notification within 24 hours, but the vendor notifies the company after 72 hours. The company's own regulatory deadline for notifying authorities is 72 hours from becoming aware of the breach. What is the most appropriate action for the company?

    Select an answer first
  2. 22foundation · easy

    What is the purpose of a data processing agreement (DPA) between an organization and a vendor?

    Select an answer first
  3. 23application · medium

    A company is conducting due diligence on a potential vendor that will process employee health data for a wellness program. The vendor has provided its privacy policy and a list of sub-processors. What additional information should the company request to complete the due diligence?

    Select an answer first
  4. 24application · medium

    An organization has an ongoing monitoring program for its vendors. During a quarterly review, the organization discovers that a vendor has not updated its privacy policy to reflect new data processing activities. What should the organization do?

    Select an answer first
  5. 25foundation · easy

    What is the purpose of ongoing vendor monitoring?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CDPSE” is a trademark of its owner, used for identification only.