ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team must share user activity logs with a third-party analytics vendor. To reduce privacy risk while still allowing regulators to trace events back to individuals if necessary, the security architect proposes pseudonymizing the user IDs. Which requirement below best satisfies the definition of pseudonymization in this context?
Mask each user ID by showing only the last four characters to the analytics vendor.
Encrypt the entire log file with AES-256 and keep the encryption key in the same cloud account as the data.
Hash each user ID with a random salt and permanently delete the salt before sharing the data set.
Replace each user ID with a random unique token and store the mapping table in an encrypted repository accessible only to a small, authorized team.
Pseudonymization replaces direct identifiers with artificial identifiers while keeping the means to re-identify data subjects separate and protected. Storing the mapping table in an encrypted repository with very limited access preserves the ability to reverse the process when legally justified, yet prevents the analytics vendor from linking the data to real identities. Hashing and discarding the salt would make re-identification impossible, turning the data into anonymized form instead of pseudonymized. Encrypting the whole file without segregating the key offers confidentiality but not pseudonymization, because decryption automatically restores the identifiers. Simply masking part of the identifier leaves recognizable information exposed and is not considered pseudonymization under privacy regulations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is pseudonymization in data privacy?
Open an interactive chat with Bash
Why is hashing with a random salt not pseudonymization?
Open an interactive chat with Bash
How does encrypting data differ from pseudonymization?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .