ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A financial institution must supply a production customer-transaction file to an external QA team for performance testing. After stripping names and account numbers, the firm worries about re-identification through remaining attributes. Which additional measure best mitigates the risk of data aggregation attacks that could reveal individual borrowers' identities?

  • Encrypt the dataset with AES-256 and share the decryption key through a secure channel.

  • Apply a CRC32 hash to each Social Security number before releasing the file.

  • Generalize and suppress quasi-identifiers until every record satisfies an agreed k-anonymity threshold.

  • Replace each customer name with a random GUID but leave age, ZIP code, and loan amount unchanged.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot