nerdexam
IsacaIsaca

CDPSE · Question #28

CDPSE Question #28: Real Exam Question with Answer & Explanation

The correct answer is B: The identifier must be kept separate and distinct from the data it protects.. Pseudonymization is a technique that replaces direct identifiers in a data set with pseudonyms or artificial identifiers that do not reveal the identity of the data subjects. Pseudonymization reduces the linkability of the data set with the original identity of the data subjects

Privacy Architecture

Question

When using pseudonymization to prevent unauthorized access to personal data, which of the following is the MOST important consideration to ensure the data is adequately protected?

Options

  • AThe data must be protected by multi-factor authentication.
  • BThe identifier must be kept separate and distinct from the data it protects.
  • CThe key must be a combination of alpha and numeric characters.
  • DThe data must be stored in locations protected by data loss prevention (DLP) technology.

Explanation

Pseudonymization is a technique that replaces direct identifiers in a data set with pseudonyms or artificial identifiers that do not reveal the identity of the data subjects. Pseudonymization reduces the linkability of the data set with the original identity of the data subjects and thus enhances the privacy and security of the data. However, pseudonymization is not irreversible and the original identity can be re-established if the pseudonym or key is compromised. Therefore, it is important to keep the identifier separate and distinct from the data it protects and to apply additional security measures to safeguard the identifier. The other options are not relevant to pseudonymization.

Topics

#Pseudonymization#Data protection#De-identification#Security controls

Community Discussion

No community discussion yet for this question.

Full CDPSE PracticeBrowse All CDPSE Questions