Pass the Isaca Isaca Certification CDPSE Questions and answers with CertsForce

Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which of the following is the GREATEST benefit of adopting data minimization practices?

Options:

A.

Storage and encryption costs are reduced.


B.

Data retention efficiency is enhanced.


C.

The associated threat surface is reduced.


D.

Compliance requirements are met.


Questions # 32:

Which of the following should be done FIRST to address privacy risk when migrating customer relationship management (CRM) data to a new system?

Options:

A.

Develop a data migration plan.


B.

Conduct a legitimate interest analysis (LIA).


C.

Perform a privacy impact assessment (PIA).


D.

Obtain consent from data subjects.


Questions # 33:

Which of the following BEST enables an organization to ensure consumer credit card numbers are accurately captured?

Options:

A.

Input reference controls


B.

Access controls


C.

Input validation controls


D.

Reconciliation controls


Questions # 34:

An organization is concerned with authorized individuals accessing sensitive personal customer information to use for unauthorized purposes. Which of the following technologies is the BEST choice to mitigate this risk?

Options:

A.

Email filtering system


B.

Intrusion monitoring


C.

Mobile device management (MDM)


D.

User behavior analytics


Questions # 35:

During the design of a role-based user access model for a new application, which of the following principles is MOST important to ensure data privacy is protected?

Options:

A.

Segregation of duties


B.

Unique user credentials


C.

Two-person rule


D.

Need-to-know basis


Questions # 36:

Which of the following scenarios poses the GREATEST risk to an organization from a privacy perspective?

Options:

A.

The organization lacks a hardware disposal policy.


B.

Emails are not consistently encrypted when sent internally.


C.

Privacy training is carried out by a service provider.


D.

The organization’s privacy policy has not been reviewed in over a year.


Questions # 37:

A new marketing application needs to use data from the organization’s customer database. Prior to the application using the data, which of the following should be done FIRST?

Options:

A.

Ensure the data loss prevention (DLP) tool is logging activity.


B.

De-identify all personal data in the database.


C.

Determine what data is required by the application.


D.

Renew the encryption key to include the application.


Questions # 38:

Which of the following should be done FIRST when developing an organization-wide strategy to address data privacy risk?

Options:

A.

Obtain executive support.


B.

Develop a data privacy policy.


C.

Gather privacy requirements from legal counsel.


D.

Create a comprehensive data inventory.


Questions # 39:

A multinational corporation is planning a big data initiative to help with critical business decisions. Which of the following is the BEST way to ensure personal data usage is standardized across the entire organization?

Options:

A.

De-identify all data.


B.

Develop a data dictionary.


C.

Encrypt all sensitive data.


D.

Perform data discovery.


Questions # 40:

Which of the following should be the FIRST consideration when selecting a data sanitization method?

Options:

A.

Risk tolerance


B.

Implementation cost


C.

Industry standards


D.

Storage type


Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions