
Updated CDPSE Dumps Questions Are Available [2023] For Passing ISACA Exam
Free UPDATED ISACA CDPSE Certification Exam Dumps is Online
The ISACA CDPSE exam is a computer-based exam consisting of 100 multiple-choice questions. Candidates have four hours to complete the exam. The exam covers four domains: Data Privacy Governance, Data Privacy Architecture, Data Privacy Operations, and Data Privacy Solutions.
NEW QUESTION # 62
Which of the following is the BEST method to ensure the security of encryption keys when transferring data containing personal information between cloud applications?
- A. Digital signature
- B. Symmetric encryption
- C. Whole disk encryption
- D. Asymmetric encryption
Answer: B
NEW QUESTION # 63
Which of the following processes BEST enables an organization to maintain the quality of personal data?
- A. Implementing routine automatic validation
- B. Maintaining hashes to detect changes in data
- C. Encrypting personal data at rest
- D. Updating the data quality standard through periodic review
Answer: D
NEW QUESTION # 64
Which of the following is the PRIMARY consideration to ensure control of remote access is aligned to the privacy policy?
- A. Access is logged on the virtual private network (VPN).
- B. Active remote access is monitored.
- C. Multi-factor authentication is enabled.
- D. Access is only granted to authorized users.
Answer: D
NEW QUESTION # 65
A global organization is planning to implement a customer relationship management (CRM) system to be used in offices based in multiple countries. Which of the following is the MOST important data protection consideration for this project?
- A. National data privacy legislative and regulatory requirements in each relevant jurisdiction
- B. Identity and access management mechanisms to restrict access based on need to know
- C. Encryption algorithms for securing customer personal data at rest and in transit
- D. Industry best practice related to information security standards in each relevant jurisdiction
Answer: B
NEW QUESTION # 66
Which of the following is the GREATEST concern for an organization subject to cross-border data transfer regulations when using a cloud service provider to store and process data?
- A. The service provider has denied the organization's request for right to audit.
- B. Personal data stored on the cloud has not been anonymized.
- C. The extent of the service provider's access to data has not been established.
- D. The data is stored in a region with different data protection requirements.
Answer: D
NEW QUESTION # 67
Which of the following should be done FIRST when developing an organization-wide strategy to address data privacy risk?
- A. Obtain executive support.
- B. Gather privacy requirements from legal counsel.
- C. Develop a data privacy policy.
- D. Create a comprehensive data inventory.
Answer: D
NEW QUESTION # 68
Which of the following techniques mitigates design flaws in the application development process that may contribute to potential leakage of personal data?
- A. User acceptance testing (UAT)
- B. Patch management
- C. Software hardening
- D. Web application firewall (WAF)
Answer: A
NEW QUESTION # 69
Which of the following MUST be available to facilitate a robust data breach management response?
- A. Lessons learned from prior data breach responses
- B. An inventory of previously impacted individuals
- C. An inventory of affected individuals and systems
- D. Best practices to obfuscate data for processing and storage
Answer: A
NEW QUESTION # 70
Which of the following should be the FIRST consideration when conducting a privacy impact assessment (PIA)?
- A. The organizational security risk profile
- B. The systems in which privacy-related data is stored
- C. The applicable privacy legislation
- D. The quantity of information within the scope of the assessment
Answer: B
NEW QUESTION # 71
To ensure effective management of an organization's data privacy policy, senior leadership MUST define:
- A. roles and responsibilities of the person with oversights.
- B. training and testing requirements for employees handling personal data.
- C. metrics and outcomes recommended by external agencies.
- D. the scope and responsibilities of the data owner.
Answer: A
NEW QUESTION # 72
Which of the following BEST enables an IT privacy practitioner to ensure appropriate protection for personal data collected that is required to provide necessary services?
- A. Implementing strong access controls on a need-to-know basis
- B. Understanding the data flows within the organization
- C. Anonymizing privacy data during collection and recording
- D. Encrypting the data throughout its life cycle
Answer: B
NEW QUESTION # 73
When choosing data sources to be used within a big data architecture, which of the following data attributes MUST be considered to ensure data is not aggregated?
- A. Reliability
- B. Consistency
- C. Granularity
- D. Accuracy
Answer: C
NEW QUESTION # 74
Which of the following is MOST important to ensure when developing a business case for the procurement of a new IT system that will process and store personal information?
- A. The system architecture is clearly defined.
- B. Security controls are clearly defined.
- C. A risk assessment has been completed.
- D. Data protection requirements are included.
Answer: D
NEW QUESTION # 75
Which of the following BEST represents privacy threat modeling methodology?
- A. Reliably estimating a threat actor's ability to exploit privacy vulnerabilities
- B. Systematically eliciting and mitigating privacy threats in a software architecture
- C. Replicating privacy scenarios that reflect representative software usage
- D. Mitigating inherent risks and threats associated with privacy control weaknesses
Answer: D
NEW QUESTION # 76
What is the BEST way for an organization to maintain the effectiveness of its privacy breach incident response plan?
- A. Conduct annual data privacy tabletop exercises.
- B. Hire a third party to perform a review of data privacy processes.
- C. Require security management to validate data privacy security practices.
- D. Involve the privacy office in an organizational review of the incident response plan.
Answer: C
Explanation:
Because many privacy incidents are also security incidents, the development of a privacy incident response plan should be performed in close cooperation with the security manager to avoid duplication of effort and to utilize existing response plan resources and practices.
NEW QUESTION # 77
Which of the following is the BEST way to validate that privacy practices align to the published enterprise privacy management program?
- A. Conduct an audit.
- B. Report performance metrics.
- C. Perform a control self-assessment (CSA).
- D. Conduct a benchmarking analysis.
Answer: D
NEW QUESTION # 78
An organization want to develop an application programming interface (API) to seamlessly exchange personal data with an application hosted by a third-party service provider. What should be the FIRST step when developing an application link?
- A. Data normalization
- B. Data hashing
- C. Data mapping
- D. Data tagging
Answer: C
NEW QUESTION # 79
Which of the following is the BEST way to protect personal data in the custody of a third party?
- A. Add privacy-related controls to the vendor audit plan.
- B. Have corporate counsel monitor privacy compliance.
- C. Require the third party to provide periodic documentation of its privacy management program.
- D. Include requirements to comply with the organization's privacy policies in the contract.
Answer: D
Explanation:
In GDPR parlance, organizations that use third-party service providers are often, but not always, considered data controllers, which are entities that determine the purposes and means of the processing of personal data, which can include directing third parties to process personal data on their behalf. The third parties that process data for data controllers are known as data processors.
NEW QUESTION # 80
Which of the following is the BEST way to hide sensitive personal data that is in use in a data lake?
- A. Data truncation
- B. Data encryption
- C. Data masking
- D. Data minimization
Answer: C
NEW QUESTION # 81
In which of the following should the data record retention period be defined and established?
- A. Data record model
- B. Data quality standard
- C. Data recovery procedures
- D. Data management plan
Answer: D
NEW QUESTION # 82
Which of the following hard drive sanitation methods provides an organization with the GREATEST level of assurance that data has been permanently erased?
- A. Factory resetting the drive
- B. Degaussing the drive
- C. Reformatting the drive
- D. Crypto-shredding the drive
Answer: B
NEW QUESTION # 83
Which of the following is the BEST way to limit the organization's potential exposure in the event of consumer data loss while maintaining the traceability of the data?
- A. De-identify the data.
- B. Require a digital signature.
- C. Encrypt the data at rest.
- D. Use a unique hashing algorithm.
Answer: B
NEW QUESTION # 84
Which of the following is a responsibility of the audit function in helping an organization address privacy compliance requirements?
- A. Establishing employee privacy rights and consent
- B. Validating the privacy framework
- C. Managing privacy notices provided to customers
- D. Approving privacy impact assessments (PIAs)
Answer: A
NEW QUESTION # 85
......
ISACA Exam 2023 CDPSE Dumps Updated Questions: https://www.getvalidtest.com/CDPSE-exam.html
Get The Most Updated CDPSE Dumps To Isaca Certification Certification: https://drive.google.com/open?id=1qIL_jrd_9dufj6qBfK8-9lBeoOq8xw2Y