ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

Your team plans to publish an internal customer dataset for public research. Direct identifiers (name, email, customer number) have been replaced with random identifiers, but fields for full birth date, 5-digit ZIP code, and gender remain. The privacy policy mandates the release be fully anonymous. What additional step best meets this requirement?

  • Require external researchers to sign a confidentiality agreement and access the data through a VPN gateway.

  • Replace each random identifier with a salted SHA-256 hash before distribution.

  • Aggregate or suppress quasi-identifiers like birth date and ZIP code until no individual can be uniquely singled out.

  • Encrypt the dataset with AES-256 before emailing it to the researchers.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot