CDPSE Privacy Enhancing Technologies MCQs (Multiple-Choice Questions)

Practice CDPSE Privacy Enhancing Technologies MCQs to test your knowledge of privacy-enhancing technologies, privacy-preserving computation, anonymization, pseudonymization, differential privacy, homomorphic encryption, secure multiparty computation, trusted execution environments, federated learning, and zero-knowledge proofs. These questions are useful for privacy professionals, security practitioners, data engineers, IT professionals, and candidates preparing for the CDPSE certification. The set includes both foundational and practical questions covering modern privacy-enhancing technologies.

CDPSE Privacy Enhancing Technologies MCQs

These CDPSE Privacy Enhancing Technologies multiple-choice questions cover important concepts such as privacy by design, data minimization, anonymization, pseudonymization, differential privacy, privacy budgets, homomorphic encryption, fully homomorphic encryption, secure multiparty computation, private set intersection, private information retrieval, zero-knowledge proofs, trusted execution environments, federated learning, synthetic data, privacy-preserving analytics, privacy risks, data utility, and PET selection. This set combines conceptual, technical, and scenario-based questions to help test your understanding of Privacy Enhancing Technologies in privacy engineering.

CDPSE Privacy Enhancing Technologies MCQs cover the technologies used to reduce privacy risks while allowing organizations to process, analyze, share, or derive value from data. Each question includes an answer and explanation.

List of CDPSE Privacy Enhancing Technologies MCQs

The following CDPSE Privacy Enhancing Technologies multiple-choice questions cover privacy-preserving computation, cryptographic PETs, data transformation techniques, distributed privacy architectures, risk management, and practical privacy engineering scenarios.

1. What is the primary purpose of Privacy Enhancing Technologies (PETs)?

  1. Increase the amount of personal data collected
  2. Protect privacy while enabling legitimate data processing or use
  3. Eliminate all cybersecurity controls
  4. Replace privacy governance programs

Answer: B) Protect privacy while enabling legitimate data processing or use

Explanation:

PETs are technologies and technical approaches designed to reduce privacy risks while preserving useful data processing capabilities.

2. Which CDPSE exam domain explicitly includes Privacy Enhancing Technologies?

  1. Privacy Governance
  2. Privacy Architecture
  3. Privacy Engineering
  4. Privacy Operations

Answer: C) Privacy Engineering

Explanation:

Privacy Enhancing Technologies are included under Privacy Controls within the Privacy Engineering domain of the CDPSE exam content outline.

3. Which principle is strongly supported by PETs that reduce the identifiability of individuals?

  1. Data minimization
  2. Unlimited retention
  3. Maximum disclosure
  4. Unrestricted collection

Answer: A) Data minimization

Explanation:

Techniques such as differential privacy and synthetic data can reduce exposure of information about individuals and support privacy objectives such as data minimization.

4. Which technique replaces identifying information with a different identifier while retaining a linkage mechanism?

  1. Pseudonymization
  2. Data destruction
  3. Homomorphic encryption
  4. Secure deletion

Answer: A) Pseudonymization

Explanation:

Pseudonymization replaces direct identifiers with pseudonyms or tokens. Depending on the implementation, additional information may still allow the data to be linked back to an individual.

5. What is the key distinction between anonymization and pseudonymization?

  1. Pseudonymization generally preserves the possibility of re-identification through additional information, while anonymization aims to prevent identification
  2. Anonymization always uses encryption while pseudonymization never does
  3. Pseudonymization permanently destroys all identifiers
  4. There is no difference

Answer: A) Pseudonymization generally preserves the possibility of re-identification through additional information, while anonymization aims to prevent identification

Explanation:

Pseudonymized information can often be linked back to an individual when additional information is available. Anonymization aims to remove or sufficiently reduce the ability to identify individuals.

6. What is differential privacy primarily designed to protect?

  1. The privacy of individuals whose information contributes to a dataset or computation
  2. The physical security of servers
  3. The availability of a database
  4. The confidentiality of encryption keys only

Answer: A) The privacy of individuals whose information contributes to a dataset or computation

Explanation:

Differential privacy provides a mathematical framework for limiting what can be learned about an individual's participation or contribution from released results.

7. Which parameter is commonly associated with the privacy budget in differential privacy?

  1. epsilon (ε)
  2. lambda (λ)
  3. theta (θ)
  4. gamma (γ)

Answer: A) epsilon (ε)

Explanation:

The parameter epsilon, commonly written as ε, is used to quantify privacy loss in many differential privacy mechanisms. Its value affects the privacy-utility trade-off.

8. What generally happens as epsilon becomes smaller in a differential privacy mechanism, assuming other parameters are comparable?

  1. Stronger privacy protection is generally provided
  2. No noise is ever required
  3. Privacy protection always becomes weaker
  4. The dataset automatically becomes encrypted

Answer: A) Stronger privacy protection is generally provided

Explanation:

A smaller epsilon generally represents a tighter privacy guarantee, although the resulting utility can decrease because stronger privacy protection often requires more noise or randomness.

9. What is the privacy-utility trade-off in differential privacy?

  1. Increasing privacy protection can reduce the accuracy or utility of released results
  2. Privacy protection always increases data accuracy
  3. Higher privacy always removes the need for statistical analysis
  4. Utility and privacy are completely unrelated

Answer: A) Increasing privacy protection can reduce the accuracy or utility of released results

Explanation:

Differential privacy commonly introduces controlled randomness or noise. More stringent privacy requirements can make statistical results less precise.

10. What is the main difference between local and central differential privacy?

  1. Local differential privacy adds privacy protection before data reaches the central collector, while central mechanisms typically protect data during or before release by a trusted curator
  2. Local differential privacy always uses encryption while central differential privacy never does
  3. Central differential privacy requires every user to publish raw data
  4. There is no architectural difference

Answer: A) Local differential privacy adds privacy protection before data reaches the central collector, while central mechanisms typically protect data during or before release by a trusted curator

Explanation:

In local differential privacy, users perturb their information before sending it to a collector. In a central model, a trusted entity generally has access to the underlying data and applies a privacy mechanism to the computation or released result.

11. What is homomorphic encryption?

  1. Encryption that permits certain computations to be performed directly on ciphertext
  2. Encryption that permanently destroys plaintext
  3. A hashing algorithm used only for passwords
  4. A method for deleting encrypted files

Answer: A) Encryption that permits certain computations to be performed directly on ciphertext

Explanation:

Homomorphic encryption allows computations to be performed on encrypted data. The resulting ciphertext can be decrypted to obtain a result corresponding to the computation on the plaintext.

12. What does Fully Homomorphic Encryption (FHE) generally allow?

  1. Arbitrary computational functions to be evaluated over encrypted data within the scheme's supported capabilities
  2. Only password hashing
  3. Only data compression
  4. Only digital signatures

Answer: A) Arbitrary computational functions to be evaluated over encrypted data within the scheme's supported capabilities

Explanation:

FHE is designed to support general computation over encrypted data without requiring the data to be decrypted during the computation.

13. Which type of homomorphic encryption supports only a restricted class of operations?

  1. Partial Homomorphic Encryption
  2. Fully Homomorphic Encryption
  3. General-purpose plaintext encryption
  4. Zero-knowledge encryption

Answer: A) Partial Homomorphic Encryption

Explanation:

Partial homomorphic encryption supports a particular operation, such as addition or multiplication, rather than the general computation capabilities associated with FHE.

14. What is a major advantage of homomorphic encryption?

  1. It can enable computation while sensitive input data remains encrypted
  2. It removes all computational overhead
  3. It guarantees anonymous users
  4. It eliminates the need for cryptographic keys

Answer: A) It can enable computation while sensitive input data remains encrypted

Explanation:

HE extends encryption protection into computation, making it possible to outsource certain computations without exposing the plaintext data to the computing service.

15. What is a common limitation of Fully Homomorphic Encryption?

  1. Computational and implementation overhead can be significant
  2. It cannot encrypt data
  3. It always requires plaintext processing in the cloud
  4. It cannot perform mathematical operations

Answer: A) Computational and implementation overhead can be significant

Explanation:

FHE can require substantially more computation and specialized cryptographic expertise compared with conventional plaintext processing.

16. What is Secure Multi-Party Computation (SMPC)?

  1. A technique that allows multiple parties to jointly compute a function without directly revealing their private inputs to one another
  2. A method for storing data in one public database
  3. A password-management protocol
  4. A form of network compression

Answer: A) A technique that allows multiple parties to jointly compute a function without directly revealing their private inputs to one another

Explanation:

SMPC enables parties to compute a result from their combined private inputs while limiting disclosure of those inputs during the protocol.

17. Which scenario is a strong use case for SMPC?

  1. Several organizations need to calculate a combined statistic without sharing their raw datasets
  2. A company wants to publish an unencrypted customer database
  3. A user wants to compress a video file
  4. A developer wants to increase CPU frequency

Answer: A) Several organizations need to calculate a combined statistic without sharing their raw datasets

Explanation:

SMPC is useful when multiple parties need to derive a result from combined data while keeping their individual inputs private.

18. What is Private Set Intersection (PSI) designed to determine?

  1. The common elements between datasets held by different parties without revealing the complete datasets
  2. The encryption key of another party
  3. The size of a database server
  4. The password of a user

Answer: A) The common elements between datasets held by different parties without revealing the complete datasets

Explanation:

PSI allows parties to determine which elements they have in common while limiting disclosure of elements outside the intersection.

19. Which business scenario is well suited to Private Set Intersection?

  1. Two organizations want to identify overlapping customers without exchanging their complete customer lists
  2. A company wants to publicly release its customer database
  3. A server administrator wants to upgrade RAM
  4. A developer wants to compile source code

Answer: A) Two organizations want to identify overlapping customers without exchanging their complete customer lists

Explanation:

PSI is particularly useful when parties need to discover shared records or identifiers without revealing the complete underlying datasets to each other.

20. What is a Zero-Knowledge Proof (ZKP)?

  1. A cryptographic protocol that can prove a statement without revealing the underlying secret or witness
  2. A database backup technique
  3. A compression algorithm
  4. A method for removing encryption

Answer: A) A cryptographic protocol that can prove a statement without revealing the underlying secret or witness

Explanation:

ZKPs allow a prover to demonstrate that a statement is true or that it possesses certain knowledge without revealing the secret information itself.

21. Which scenario best demonstrates a zero-knowledge proof?

  1. Proving that a user satisfies a required condition without revealing unnecessary personal information
  2. Publishing the user's complete identity document
  3. Sending a password in plaintext
  4. Sharing an entire customer database

Answer: A) Proving that a user satisfies a required condition without revealing unnecessary personal information

Explanation:

A ZKP can allow verification of a property or statement without exposing the underlying secret information used to establish that property.

22. What is a Trusted Execution Environment (TEE)?

  1. A hardware-supported isolated environment designed to protect code and data during execution
  2. A public cloud storage bucket
  3. A database replication method
  4. A network compression protocol

Answer: A) A hardware-supported isolated environment designed to protect code and data during execution

Explanation:

A TEE provides an isolated execution environment intended to protect sensitive code and data from unauthorized access by other software running on the system.

23. Which type of data protection does a TEE primarily help address?

  1. Protection of sensitive data while it is being processed
  2. Only data deletion
  3. Only physical document storage
  4. Only network bandwidth optimization

Answer: A) Protection of sensitive data while it is being processed

Explanation:

TEEs can provide an isolated environment for processing sensitive information, helping protect data in use from unauthorized access by the surrounding operating environment.

24. What is a potential security concern associated with TEEs?

  1. Side-channel attacks
  2. Unlimited storage
  3. Excessive plaintext disclosure by definition
  4. Inability to execute code

Answer: A) Side-channel attacks

Explanation:

Although TEEs provide isolation, implementation vulnerabilities and side-channel attacks can potentially reveal sensitive information. TEE security therefore depends on the hardware, firmware, software, and threat model.

25. What is Federated Learning?

  1. A machine-learning architecture in which multiple participants train a shared model using locally held data
  2. A method that always transfers all training data to one server
  3. A database encryption algorithm
  4. A technique for deleting model parameters

Answer: A) A machine-learning architecture in which multiple participants train a shared model using locally held data

Explanation:

Federated learning keeps training data at participating devices or organizations while model updates or related information are exchanged for collaborative training.

26. Does federated learning by itself guarantee complete privacy of training data?

  1. No, model updates or other information can potentially leak sensitive information
  2. Yes, it mathematically guarantees zero leakage
  3. Yes, because encryption is impossible to attack
  4. No, because it requires publishing raw datasets

Answer: A) No, model updates or other information can potentially leak sensitive information

Explanation:

Federated learning reduces the need to centrally collect raw training data, but model updates can still reveal information. Additional PETs such as secure aggregation, differential privacy, or cryptographic techniques may be used.

27. What is secure aggregation in federated learning intended to achieve?

  1. Allow a server to obtain an aggregate of participant updates without seeing each individual update in plaintext
  2. Publish every participant's model update
  3. Delete the global model after every training round
  4. Move all training data to the server

Answer: A) Allow a server to obtain an aggregate of participant updates without seeing each individual update in plaintext

Explanation:

Secure aggregation is designed to prevent the coordinating server from directly inspecting individual participant updates while still allowing it to obtain the required aggregate.

28. What is synthetic data?

  1. Artificially generated data designed to reproduce useful characteristics of real data
  2. Encrypted copies of original records
  3. Deleted database records
  4. Raw data copied from another organization

Answer: A) Artificially generated data designed to reproduce useful characteristics of real data

Explanation:

Synthetic data is generated rather than directly collected from the original individuals. It can be useful for testing, development, analytics, and other scenarios when appropriately generated and evaluated.

29. Does synthetic data automatically guarantee privacy?

  1. No, privacy depends on how the synthetic data is generated and whether information about real individuals can be inferred or reproduced
  2. Yes, all synthetic datasets are automatically anonymous
  3. Yes, synthetic data never reflects real data patterns
  4. No, because synthetic data cannot be used for analytics

Answer: A) No, privacy depends on how the synthetic data is generated and whether information about real individuals can be inferred or reproduced

Explanation:

Poorly generated synthetic data can retain or reproduce sensitive information. Privacy evaluation is therefore necessary rather than assuming that synthetic generation automatically removes all privacy risk.

30. Which PET is most directly associated with adding controlled statistical noise to protect individual contributions?

  1. Differential privacy
  2. Homomorphic encryption
  3. Trusted execution environment
  4. Private information retrieval

Answer: A) Differential privacy

Explanation:

Differential privacy commonly uses carefully calibrated randomness or noise to limit the information that released results reveal about individual data contributions.

31. Which PET is most appropriate when a cloud provider must perform computations on sensitive data without receiving the plaintext?

  1. Homomorphic encryption
  2. Plaintext database replication
  3. Public data publication
  4. Simple file compression

Answer: A) Homomorphic encryption

Explanation:

Homomorphic encryption is designed to support computations on ciphertext, making it suitable for scenarios where a computing service should not have access to plaintext input data.

32. Which PET is particularly appropriate when several mutually distrustful organizations need to compute a joint function?

  1. Secure Multi-Party Computation
  2. Simple pseudonymization
  3. Static data masking only
  4. Traditional compression

Answer: A) Secure Multi-Party Computation

Explanation:

SMPC is designed for collaborative computation in which multiple parties contribute private inputs without directly revealing those inputs to one another.

33. Which PET can prove possession of specific information without revealing the information itself?

  1. Zero-Knowledge Proof
  2. Federated Learning
  3. Data aggregation
  4. Tokenization

Answer: A) Zero-Knowledge Proof

Explanation:

ZKPs are specifically designed to establish the truth of a statement or knowledge of a secret without revealing the secret itself.

34. What is Private Information Retrieval (PIR) designed to protect?

  1. The privacy of a client's query when retrieving information from a database
  2. The physical security of a database server
  3. The accuracy of a machine-learning model
  4. The lifespan of a storage device

Answer: A) The privacy of a client's query when retrieving information from a database

Explanation:

PIR protocols allow a client to retrieve information from a database while limiting the database operator's ability to determine which item was requested.

35. Which statement best describes tokenization?

  1. Replacing sensitive values with tokens that can be mapped back under controlled conditions
  2. Adding random noise to every statistical query
  3. Computing arbitrary functions over ciphertext
  4. Training a machine-learning model on local devices

Answer: A) Replacing sensitive values with tokens that can be mapped back under controlled conditions

Explanation:

Tokenization substitutes sensitive values with tokens. A separate mechanism or system may retain the mapping needed to recover the original values when authorized.

36. Which statement about encryption and PETs is most accurate?

  1. Traditional encryption primarily protects data at rest or in transit, while some PETs additionally address privacy during computation or collaborative analysis
  2. Encryption automatically makes all data anonymous
  3. Encryption eliminates the need for access controls
  4. Encryption and PETs are completely unrelated

Answer: A) Traditional encryption primarily protects data at rest or in transit, while some PETs additionally address privacy during computation or collaborative analysis

Explanation:

Conventional encryption is essential for protecting data at rest and in transit. Technologies such as FHE, SMPC, and TEEs can extend privacy protections into data processing scenarios.

37. Why should privacy professionals perform a threat-model analysis before selecting a PET?

  1. Different PETs protect against different threats and introduce different assumptions, costs, and leakage risks
  2. All PETs provide identical guarantees
  3. Threat modeling is only relevant to physical security
  4. PET selection never depends on the use case

Answer: A) Different PETs protect against different threats and introduce different assumptions, costs, and leakage risks

Explanation:

PET selection should consider adversaries, trust assumptions, data flows, attack surfaces, performance requirements, and the privacy properties required by the specific use case.

38. An organization wants to calculate the overlap between two customer databases without exchanging the complete databases. Which PET is most suitable?

  1. Private Set Intersection
  2. Fully Homomorphic Encryption for every database operation
  3. Public data publication
  4. Plaintext database merging

Answer: A) Private Set Intersection

Explanation:

PSI is specifically designed for finding common elements between datasets while limiting disclosure of the remaining elements.

39. A hospital wants researchers to calculate statistics across patient datasets held by multiple institutions without exchanging raw records. Which approach is most directly applicable?

  1. Secure Multi-Party Computation
  2. Public database replication
  3. Unencrypted FTP transfer
  4. Manual spreadsheet consolidation

Answer: A) Secure Multi-Party Computation

Explanation:

SMPC can enable multiple organizations to jointly compute statistics or other functions while keeping their individual input datasets private during the computation.

40. A company wants analysts to access aggregate statistics while limiting the possibility of learning whether a particular individual contributed to the dataset. Which technique is most appropriate?

  1. Differential privacy
  2. Plaintext export
  3. Database duplication
  4. Standard compression

Answer: A) Differential privacy

Explanation:

Differential privacy provides a mathematical privacy guarantee designed to limit the effect that any one individual's data has on released results.

41. An organization needs to run a sensitive machine-learning inference workload on a cloud platform while keeping the input encrypted during computation. Which technology is a strong candidate?

  1. Fully Homomorphic Encryption
  2. Plaintext database export
  3. Basic anonymization alone
  4. Cookie management

Answer: A) Fully Homomorphic Encryption

Explanation:

FHE supports general-purpose computation over encrypted data and can therefore be considered for privacy-preserving inference where the cloud service should not receive plaintext inputs.

42. A financial institution wants to prove that a transaction satisfies a specific condition without revealing the transaction details. Which PET is most suitable?

  1. Zero-Knowledge Proof
  2. Permutation feature importance
  3. Data compression
  4. Simple hashing without a verification protocol

Answer: A) Zero-Knowledge Proof

Explanation:

A ZKP can be designed to prove that a statement or condition is true without revealing the underlying secret information used to establish the proof.

43. Which statement about PETs and data utility is correct?

  1. PETs can introduce trade-offs involving privacy, accuracy, performance, usability, and cost
  2. PETs always increase data accuracy
  3. PETs eliminate all processing overhead
  4. PETs guarantee that every dataset can be safely shared

Answer: A) PETs can introduce trade-offs involving privacy, accuracy, performance, usability, and cost

Explanation:

Different PETs have different technical characteristics. Differential privacy can affect statistical accuracy, while cryptographic approaches such as FHE and SMPC can introduce computational or communication overhead.

44. Which statement about combining PETs is most accurate?

  1. Multiple PETs can be combined when their privacy properties complement each other and the resulting system is properly evaluated
  2. Only one PET can ever be used in a system
  3. Combining PETs automatically guarantees perfect privacy
  4. Combining PETs always eliminates all performance overhead

Answer: A) Multiple PETs can be combined when their privacy properties complement each other and the resulting system is properly evaluated

Explanation:

Organizations may combine techniques such as federated learning, secure aggregation, differential privacy, or cryptographic computation to address different parts of a privacy threat model.

45. Which factor should be considered when selecting between differential privacy and homomorphic encryption?

  1. The privacy objective, computation requirements, threat model, data utility, and performance constraints
  2. Only the programming language
  3. Only the database size
  4. Only the number of employees

Answer: A) The privacy objective, computation requirements, threat model, data utility, and performance constraints

Explanation:

Differential privacy and homomorphic encryption solve different privacy problems. PET selection should be based on the required privacy properties, adversary model, workload, performance, and acceptable utility trade-offs.

46. A company uses federated learning but discovers that individual model updates may reveal information about participants. What is the best next step?

  1. Assess the leakage and consider additional protections such as secure aggregation or differential privacy
  2. Assume that federated learning guarantees complete privacy
  3. Publish all model updates publicly
  4. Move all raw training data to a central server

Answer: A) Assess the leakage and consider additional protections such as secure aggregation or differential privacy

Explanation:

Keeping raw data local does not eliminate all privacy risks. Model updates can leak information, so the architecture should be evaluated against realistic threats and additional PETs considered where appropriate.

47. An organization generates synthetic healthcare records for software testing. What should the privacy team verify before releasing the synthetic dataset?

  1. Whether the generated records could disclose or reproduce sensitive information about real individuals
  2. Only whether the file opens in Excel
  3. Only whether the dataset has more rows than the original
  4. Whether every synthetic record exactly matches a real patient

Answer: A) Whether the generated records could disclose or reproduce sensitive information about real individuals

Explanation:

Synthetic data should be assessed for privacy leakage, memorization, re-identification risks, and utility. The fact that data is artificially generated does not by itself establish that it is privacy-safe.

48. A privacy engineer needs a PET for two companies to jointly calculate a fraud-detection statistic without revealing their individual transaction records. Which solution best matches the requirement?

  1. Secure Multi-Party Computation
  2. Public data publication
  3. Simple file encryption followed by plaintext sharing
  4. Traditional database replication

Answer: A) Secure Multi-Party Computation

Explanation:

SMPC is designed for collaborative computation over private inputs. It can allow organizations to derive a joint result without directly disclosing their underlying transaction records to each other.

49. A privacy team is designing a system where sensitive data must be processed by an untrusted cloud provider. The team wants to minimize plaintext exposure during computation. Which combination is most technically relevant to evaluate?

  1. Homomorphic encryption, trusted execution environments, and other privacy-preserving computation techniques
  2. Only browser cookies
  3. Only data compression
  4. Only database indexing

Answer: A) Homomorphic encryption, trusted execution environments, and other privacy-preserving computation techniques

Explanation:

HE and TEEs provide different approaches to protecting sensitive data during processing. The appropriate choice depends on the threat model, trust assumptions, workload, performance requirements, and implementation risks.

50. An organization wants to deploy a privacy-preserving analytics platform using multiple PETs. The system will combine federated learning, secure aggregation, differential privacy, and encrypted communication. What is the most important CDPSE privacy-engineering approach?

  1. Assume that using multiple PETs automatically guarantees privacy
  2. Evaluate the complete architecture against the threat model, privacy requirements, leakage risks, utility, and operational constraints
  3. Focus only on the encryption algorithm and ignore data flows
  4. Select PETs based only on which technology is newest

Answer: B) Evaluate the complete architecture against the threat model, privacy requirements, leakage risks, utility, and operational constraints

Explanation:

Effective privacy engineering requires evaluating PETs as part of the complete system rather than treating any individual technology as a universal privacy solution. The organization should identify threats, define privacy requirements, assess possible leakage, validate the effectiveness of each control, and consider performance and operational constraints before deployment.

Comments and Discussions!

Load comments ↻



Copyright © 2026 www.includehelp.com. All rights reserved.