10/01/2024
BERIKUT CONTOH LATIHAN SOAL CDPSE ISACA (SOAL DAN KUNCI JAWABAN)
Penyusun : Hery Purnama, SE.,MM.,
MCP, PMP, ITILF, CISA, CISM, CGEIT, CRISC, CDPSE, COBIT, TOGAF, CTFL, CBAP
1. In the United States, which of the following best describes a subject’s own PII elements that the subject is required to protect?
⚪ All PII as described by the US Data Protection Act
⚪ Social Security number, bank account numbers, credit card numbers
⚪ Bank account numbers, credit card numbers
⚫ None
2. At which point in the SDLC should a PIA be performed?
⚪ Before requirements are developed
⚫ After requirements are developed
⚪ After implementation
⚪ Before QA testing
3. For reasons unknown, an organization’s executive management refuses to deliberate or make a decision regarding a particular privacy risk that the chief privacy officer has identified. What risk treatment is being carried out in this situation?
⚪ Risk ignorance
⚪ Risk transfer
⚪ Risk avoidance
⚫ Risk acceptance
4. A data architect is developing a visual model that shows how information is transmitted among systems. What kind of a visual model has the data architect created?
⚫ Data flow diagram
⚪ Data architecture
⚪ Entity-relationship diagram
⚪ Network diagram
5. Which of the following methods is used to develop a machine-readable web services definition?
⚪ Schema
⚪ WWWC
⚫ WSDL
⚪ APID
6. A typical VPN solution will protect endpoints from which of the following threats?
⚪ Buffer overflow
⚪ Credential stuffing
⚪ Ping of death
⚫ Network eavesdropping
7. An organization has been donating EOL laptop computers to local schools for years. In the past, the organization would degauss laptop HDDs to remove sensitive information. Now that laptops contain SSDs instead of HDDs, which of the following methods remains effective for removing sensitive data?
⚫ Secure erasure
⚪ Degaussing
⚪ SSD removal
⚪ Reformatting
8. Infrastructure as a service refers to:
⚫ Leasing operating systems from a service provider
⚪ Outsourcing application management to a service provider
⚪ Outsourcing operating system management to a service provider
⚪ Leasing computing hardware for use in a colocation facility
9. A cybercriminal group stole PII from a telephone company’s customer database and used the information obtained to open unsecured credit accounts in the names of the telephone company customers. What crime(s) has the cybercriminal group committed?
⚪ Toll fraud
⚪ Data theft
⚫ Data theft and identity theft
⚪ Identity theft
10. Which of the following is the best SLA for deploying critical security patches in a production environment that processes personal information?
⚪ 30 days
⚪ 24 hours
⚪ 7 hours
⚫ 7 days
11. What is the main purpose of a data classification program?
⚪ Determine how long the most sensitive data has been stored.
⚪ Discover where the most sensitive data is being stored.
⚪ Enable automatic tagging of sensitive information.
⚫ Enable the workforce to recognize and protect data accordingly.
12. An organization defines the roles “owner” and “steward” with regard to decisions about its databases containing personal information. Which of the following is NOT an appropriate responsibility for the role of owner?
⚪ Review of access roles
⚫ Physical database design
⚪ Approval of access requests
⚪ Logical database design
13. Which of the following personnel is responsible for the accuracy of customer PII in an organization’s database?
⚫ Business unit leader
⚪ Database administrator
⚪ Chief privacy officer
⚪ Application developer
14. A data privacy officer in a financial services organization is developing a data classification policy. What audience in the organization should be informed of the new policy once it is completed?
⚫ All workers
⚪ Database administrators
⚪ Customer-facing workers
⚪ IT workers
15. A document that describes steps to be performed within a privacy program is known as a:
⚪ Charter
⚫ Procedure
⚪ Process
⚪ Privacy policy
16. Despite statements to the contrary in its external privacy statement, an organization intends to sell its customer list to a data brokerage. Which principle of privacy is likely to be violated if this transaction is completed?
⚫ Data use limitation
⚪ Data leakage
⚪ Data sovereignty
⚪ Data minimization
17. All of the following are important considerations in an application data migration EXCEPT:
⚪ Availability of sufficient storage space on the destination system
⚪ Proper transformation of data values when they are expressed in different ways
⚪ Understanding any differences in meaning between similar source and destination fields
⚫ Understanding any differences in the DML between the source and destination systems
18. A service provider that stores and processes sensitive information for corporate customers employs an annual SOC 2 Type 2 audit. What additional information is needed so that recipients of the SOC 2 audit reports understand whether privacy is addressed during the audit?
⚫ Whether the SOC 2 audit includes the Privacy principle
⚪ Whether the SOC 2 audit report is up-to-date
⚪ Whether exceptions were encountered during the audit
⚪ Whether the recipient has permission to read the SOC 2 audit report
19. An organization has a transaction processing application that contains a very large database with a low transaction rate. Which of the following is the best option for providing the ability to recover the database to an earlier point in time?
⚪ Export to flat file
⚪ Backup to magnetic tape
⚫ Snapshots
⚪ Checksums
20. An online and storefront retail organization has an extensive transaction history spanning many years that shows all of the purchases that customers have made. Potential uses of this transaction data include all of the following EXCEPT:
⚫ Machine learning to identify privacy violations
⚪ Data analytics to improve inventory management
⚪ Data analytics techniques to monetize the data and increase future sales
⚪ AI techniques to set more competitive prices
sumber :
BERIKUT CONTOH LATIHAN SOAL CDPSE ISACA (SOAL DAN KUNCI JAWABAN) Penyusun : Hery Purnama, SE.,MM., MCP, PMP, ITILF, CISA, CISM, CGEIT, CRI...