1. Which statement best describes privacy engineering? It translates privacy goals into requirements, architecture, controls, evidence, ownership, and lifecycle decisions. It is only the process of writing privacy policies. It is identical to cybersecurity. It focuses only on encryption.
2. Why does strong security not automatically guarantee strong privacy? Security can protect data from unauthorized access while the organization may still collect, use, share, infer, or retain more data than is appropriate. Security controls never protect personal data. Privacy and security are unrelated. Privacy only applies when security controls fail.
3. What is the strongest purpose of a data inventory? To document what data exists, where it comes from, where it goes, who owns it, who accesses it, why it exists, and how it is governed. To list only database names. To record only data classifications. To replace risk assessments.
4. Which factor can make ordinary data more privacy-sensitive? Combining it with other data so individuals become easier to identify or infer information about. Changing the font used to display it. Moving it to a faster server. Compressing the file.
5. What is the strongest example of data minimization? Collecting only the fields needed for the current purpose and reducing precision, access, sharing, copies, inference, and retention where possible. Collecting everything and deleting unused data years later. Encrypting every field regardless of necessity. Keeping extra data for possible future use.
6. A scheduling partner needs four fields, but the integration sends eight. What is the strongest privacy-engineering response? Reduce the interface to the four fields supported by the approved scheduling purpose. Keep all eight because the connection is encrypted. Keep all eight because the supplier is approved. Keep all eight for possible future features.
7. What is purpose limitation? Keeping data use aligned with the approved purpose and reviewing materially different secondary uses separately. Using one broad purpose statement for every future data use. Preventing all secondary use under every circumstance. Limiting each product to one database.
8. Which statement about consent is strongest? Consent can support meaningful optional choice, but it does not replace minimization, purpose limitation, retention, security, or governance. Consent makes any data practice acceptable. Consent is always required for every necessary service function. Consent eliminates privacy risk.
9. Which design is most privacy-respecting for an optional feature? Keep the optional feature off by default and let the user enable it through a clear, accessible choice. Enable it automatically because users can disable it later. Hide the setting in several menus. Bundle it with unrelated required service features.
10. What does contextual integrity emphasize? Whether information flows fit the expected relationship among the data, purpose, recipient, people, and service context. Whether all data is encrypted. Whether every user makes the same privacy choice. Whether the system uses the same database technology.
11. What should a strong retention rule include? Purpose, retention period, trigger, end action, owner, exception path, and evidence. Only the number of days. Only the deletion date. Only the system name.
12. A project needs long-term aggregate trends but only short-term individual-level events. What is the strongest design? Keep approved aggregate trends longer and expire individual-level events after the bounded project need. Keep both forms for the same long period. Delete both immediately. Share the individual-level events with more teams.
13. Why should supplier-side deletion evidence matter? Because external copies remain part of the privacy lifecycle even after internal copies are removed. Because supplier contracts automatically prove deletion. Because internal deletion never matters. Because suppliers always retain data forever.
14. What is the strongest description of privacy risk? The possibility that a data practice could create adverse consequences for people or the organization through collection, use, access, sharing, inference, retention, expectations, or weak controls. Only the probability of a data breach. Only a legal penalty. Only a data classification label.
15. What is residual privacy risk? The privacy risk that remains after current controls and treatments are considered. The risk before controls are applied. A supplier contract. A data-classification level.
16. How should low evidence confidence affect a privacy assessment? It should increase visible uncertainty and prevent stronger conclusions than the evidence supports. It should automatically make the risk Low. It should automatically close the risk. It should remove the need for an owner.
17. Which statement best describes a Data Owner? The accountable role for major business decisions about data purpose, classification, sharing, retention, and governance. The person who physically administers the database. The person who writes every security control. The evidence custodian for every system.
18. Why can the Control Owner, Evidence Owner, Remediation Owner, and Risk Owner be different people? Because control effectiveness, evidence custody, corrective work, and business-risk accountability are distinct responsibilities. Because organizations should avoid clear accountability. Because privacy teams must own all four roles. Because evidence owners automatically approve residual risk.
19. What is privacy by design? Building privacy requirements into architecture, defaults, interfaces, access boundaries, lifecycle, evidence, and governance before problems become expensive to fix. Adding a privacy notice after launch. Encrypting every database and stopping there. Collecting broad data first and minimizing later.
20. Which architecture pattern best supports minimization for a supplier integration? A purpose-specific narrow interface schema that exposes only required fields. A full-record API protected by policy. A broad data export with encryption. A shared database containing all customer information.
21. What is strongest for privacy-related system logs and governance evidence? Record the metadata needed to prove control operation without unnecessarily copying sensitive content. Copy complete personal records into every log. Avoid all logs. Store sensitive logs in a public location.
22. Why is more user friction not automatically stronger security? Friction can create failure, exclusion, workarounds, and support burden without necessarily reducing the relevant risk. Security controls should never add any friction. Friction only affects privacy. Friction proves a user is authorized.
23. What is the strongest approach to accessibility in authentication or recovery? Provide equivalent governed paths that preserve necessary security while remaining usable by legitimate users with different needs. Treat accessibility as an informal bypass. Remove verification from accessible paths. Require one method for every user regardless of accessibility.
24. What should happen when a privacy issue has a remediation plan but no closure evidence yet? Keep the issue open until objective evidence shows the target state was reached. Mark it Closed because work has started. Mark it Closed because an owner was assigned. Remove it from the risk register.
25. What is the strongest purpose of the final Privacy Engineering Review? Integrate context, inventory, minimization, expectations, lifecycle, privacy risk, governance, architecture, tradeoffs, evidence, ownership, and recommendations into one decision-ready package. Produce one privacy score for the entire organization. Replace all earlier artifacts. List only the highest data classifications.