About the Exam

The CDPSE exam is ISACA’s certification exam for privacy professionals and technical practitioners who implement privacy by design. It covers privacy governance, privacy risk management and compliance, data life cycle management, and privacy engineering. Passing demonstrates expertise in applying privacy-by-design principles to existing and future systems, networks, and applications and in building comprehensive privacy solutions.

Exam Topics

  • Privacy Governance20%
  • Privacy Risk Management and Compliance18%
  • Data Life Cycle Management23%
  • Privacy Engineering39%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated August 12, 2026 at 11:44 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Privacy Governance

Which key organizational stakeholder should be accountable for approving the results of a privacy impact assessment (PIA)?

Explanation

The data owner is accountable for the data’s use, associated privacy risks, and acceptance of the assessment’s recommended controls. This role therefore has the authority to approve the outcome of a privacy impact assessment.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Privacy Governance

Among the following, who should be primarily accountable for developing an organization’s privacy management strategy?

Explanation

The chief privacy officer (CPO) is the executive primarily responsible for establishing and leading the organization’s privacy management strategy and privacy program. Steering committees provide oversight and coordination, while data and security leaders have separate primary mandates.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Privacy Engineering

Which of the following MOST effectively protects against the use of a network sniffer?

Explanation

Transport-layer encryption encrypts data while it traverses the network, so captured packets cannot be read without the required cryptographic keys.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Data Life Cycle Management

Which of the following data-lake zones requires sensitive data to be encrypted or tokenized?

Explanation

The raw zone stores source data in its original form, so it can contain sensitive information before later validation and transformation. Sensitive content in that zone must be protected through encryption, tokenization, or comparable controls. AWS guidance likewise describes masking sensitive rows or columns before ingestion into a raw layer and encrypting the raw-layer bucket.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Privacy Risk Management and Compliance

Within a business continuity plan (BCP), which of the following is the MOST important consideration for ensuring the ability to restore the availability of, and access to, personal data following a data privacy incident?

Explanation

Offline backups provide an independent recovery source that remains available if the affected environment or connected backups are disrupted or compromised. Recovery objectives define recovery targets, but do not themselves enable restoration. GDPR Article 32 requires the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home