ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team plans to publish an internal customer dataset for public research. Direct identifiers (name, email, customer number) have been replaced with random identifiers, but fields for full birth date, 5-digit ZIP code, and gender remain. The privacy policy mandates the release be fully anonymous. What additional step best meets this requirement?
Require external researchers to sign a confidentiality agreement and access the data through a VPN gateway.
Replace each random identifier with a salted SHA-256 hash before distribution.
Aggregate or suppress quasi-identifiers like birth date and ZIP code until no individual can be uniquely singled out.
Encrypt the dataset with AES-256 before emailing it to the researchers.
To achieve full anonymity, the dataset must be rendered so that no individual can be re-identified, even when it is combined with other publicly available data. Birth date, ZIP code, and gender are quasi-identifiers that can uniquely single out many people. Generalizing (for example, using birth year instead of exact date or three-digit ZIP codes) or suppressing these attributes removes that residual linkage risk. Hashing the random identifier only obscures the surrogate key, while the quasi-identifiers still enable matching. Confidentiality agreements, VPNs, or encryption in transit protect the data during handling, but they do not change the fact that the data itself can still be re-identified once decrypted, so they do not satisfy the requirement for a fully anonymous release.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are quasi-identifiers in the context of data privacy?
Open an interactive chat with Bash
How does aggregating or suppressing quasi-identifiers enhance dataset anonymity?
Open an interactive chat with Bash
Why is hashing random identifiers insufficient for ensuring full anonymity in datasets?
Open an interactive chat with Bash
What are quasi-identifiers and why are they important in anonymization?
Open an interactive chat with Bash
How does aggregation or suppression of data improve anonymization?
Open an interactive chat with Bash
Why is hashing or encrypting identifiers insufficient for full anonymization?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .