Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 55 discussion

Actual exam question from ISC's CISSP
Question #: 55
Topic #: 1
[All CISSP Questions]

What is the BEST approach to anonymizing personally identifiable information (PII) in a test environment?

  • A. Swapping data
  • B. Randomizing data
  • C. Encoding data
  • D. Encrypting data
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
somkiatr
Highly Voted 1 year, 11 months ago
Selected Answer: A
Should be A. Techniques of Data Anonymization 1. Data masking 2. Pseudonymization 3. Generalization 4. Data swapping 5. Data perturbation 6. Synthetic data Reference : https://corporatefinanceinstitute.com/resources/business-intelligence/data-anonymization/
upvoted 11 times
deeden
3 months, 3 weeks ago
I think this question equates Randomizing data to masking, such as replacing values with random meaningless characters (e.g., # , / $) which is a stronger anonymization option than just shuffling values around. I know, it's weird right. lol
upvoted 2 times
...
...
DERCHEF2009
Highly Voted 2 years, 2 months ago
Selected Answer: B
B is much better
upvoted 6 times
stickerbush1970
2 years, 2 months ago
anonymizing - remove identifying particulars or details, how is B doing this?
upvoted 4 times
CharlesL
2 years, 1 month ago
How do you get the testing result in from encrypted content?
upvoted 3 times
...
...
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
...
Verm12
Most Recent 2 months, 3 weeks ago
Selected Answer: B
OSG states "Randomized masking can be an effective method of anonymizing data" pg 203
upvoted 2 times
...
Ezebuike
3 months, 1 week ago
I am not sure if an encrepted data casn be used in a test environment. But I will go for option B
upvoted 1 times
...
JohnBentass
5 months, 1 week ago
Selected Answer: A
A. Swapping data Data swapping involves exchanging values between different records in a dataset, which helps preserve the confidentiality of individual data entries while maintaining the overall statistical distribution and relationships within the data. This technique is more effective than some other common anonymization methods: Randomizing data alters values with random, mock data but doesn't maintain the exact statistical distribution, which can compromise data utility for complex datasets. Data swapping, on the other hand, provides a straightforward way to anonymize PII while preserving data integrity and statistical accuracy appropriate for testing needs. It enables realistic datasets for software development and testing without exposing sensitive information
upvoted 1 times
...
Jenkins3mol
6 months, 3 weeks ago
Selected Answer: B
B. Randomizing data: Randomizing data is a common approach to anonymization. It involves replacing original data values with randomly generated values that do not correspond to any real individuals. This ensures that the data cannot be traced back to its original source while still maintaining its structural and statistical properties for testing.
upvoted 1 times
...
dm808
8 months ago
Selected Answer: B
Only option B refers to anonymization. A. Swapping Data- Pseudonymization B. Randomizing Data- Anonymization C. Encoding Data- Tokenization D. Encrypting Data- Tokenization
upvoted 1 times
...
GuardianAngel
9 months, 2 weeks ago
Answer: B. Randomizing data A test environment might including needing to test analytics, computations, reports, dashboards - basically processes that have to be tested with unencrypted data. Randomizing data involves replacing PII with randomly generated values while maintaining the statistical properties of the original data. This ensures that the computations and analytics performed on the anonymized data yield accurate results and reflect the real-world scenarios. Swapping data involves replacing PII with other data. Swapping data may introduce biases or alter the statistical properties needed for accurate analytics and computations. Encoding data transforms data into a different representation using encoding schemes. Encrypting data is not be the best choice for this scenario as encryption aims to protect data rather than anonymize it.
upvoted 2 times
...
study22024
10 months ago
Randomized masking can be an effective method of anonymizing data pg279 cissp study guide
upvoted 2 times
...
YesPlease
11 months, 2 weeks ago
Selected Answer: B
Answer B) Encrypting the data does not remove Pii...it just prevents anyone that stole the data from reading it without the proper credentials. However, someone with proper rights...like a DBA can see the Pii data without a problem. Also, Page 202-204 in CISSP study guide clear states randomization as the best option to anonymize data in a way that it will even make GDPR a non-issue.
upvoted 2 times
...
homeysl
1 year, 1 month ago
Selected Answer: A
A is my answer
upvoted 1 times
...
Sledge_Hammer
1 year, 2 months ago
The correct Answer is A. There are also some well-known techniques to be applied in a structured database for anonymization: Masking: removing, encrypting, or obscuring the private identifiers Pseudonymization: Replace the private identifiers with pseudonyms or false values Generalization: Replacing a specific identifier value with a more general one Swapping: Shuffling the attribute values of the dataset so that they are different from the original one Perturbation: Changing the data by introducing random noises or using random methods
upvoted 3 times
...
Dann108
1 year, 2 months ago
It is randomization. Even if you remove not only encrypt personal data, in some cases it is still not anonymized. The ideal answer would be "Randomized masking".
upvoted 1 times
...
Vince_F_Fang
1 year, 2 months ago
Selected Answer: B
The encryption effect is not very good, isn't it? Unlike the strict protection of data in production environments, application developers can access test environment data, so it is easy to decrypt data
upvoted 1 times
...
Bach1968
1 year, 4 months ago
Selected Answer: B
While encryption can provide additional security and protection for PII, it does not inherently remove the identifying elements or guarantee anonymity. Encrypted data can still be linked back to individuals if the encryption keys are available or if other data points are present that can be used for identification. In a test environment, where the goal is to use realistic but anonymized data, randomizing or modifying the PII values to render them unidentifiable is a more suitable approach. Randomizing data ensures that the original PII values are replaced with fictional or random data, reducing the risk of re-identification while still allowing for meaningful testing scenarios. Therefore, while encryption can be a valuable security measure, it may not be the most appropriate method for anonymizing PII in a test environment where the focus is on data de-identification and realistic testing.
upvoted 3 times
...
vorozco
1 year, 5 months ago
Selected Answer: D
A. Swapping data ---> An explicit data anonymization technique B. Randomizing data ---> Falls under data perturbation C. Encoding data ---> N/A D. Encrypting data ---> Falls under data masking I think some are choosing option A because it's and explicit data anonymization technique, but it's not the BEST and there are two other possible options. I'm going with option D. The second resource below triggered something I read for a previous exam about masking (encrypting) PII and tools that can auto-detect values that look like PII to prevent accidentally missing it. https://satoricyber.com/data-masking/data-anonymization-use-cases-and-6-common-techniques/ https://www.dot-anonymizer.com/resources/blog-en/protecting-your-pii-data-in-testing/
upvoted 2 times
...
Tygrond87
1 year, 6 months ago
Randomizing data is the BEST approach to anonymizing personally identifiable information (PII) in a test environment. This involves replacing the original PII with randomized values while preserving the format and structure of the data. Randomization ensures that the PII is no longer linked to an individual, thus protecting their privacy. Swapping data, encoding, and encrypting data may not fully anonymize the PII or may be reversible, leading to privacy breaches. - chat gpt
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...