nerdexam
Isaca

CRISC · Question #554

An organization needs to send files to a business partner to perform a quality control audit on the organization's record-keeping processes. The files include personal information on…

The correct answer is A. Obfuscate the customers' personal information. Obfuscating personal information is the best recommendation to mitigate privacy risk when sharing data with a third party, as it reduces the identifiability of the data while potentially retaining its utility for the task.

Submitted by kwame.gh· Apr 18, 2026Risk Response and Reporting

Question

An organization needs to send files to a business partner to perform a quality control audit on the organization's record-keeping processes. The files include personal information on theorganization's customers. Which of the following is the BEST recommendation to mitigate privacy risk?

Options

  • AObfuscate the customers' personal information.
  • BRequire the business partner to delete personal information following the audit.
  • CUse a secure channel to transmit the files.
  • DEnsure the contract includes provisions for sharing personal information.

How the community answered

(41 responses)
  • A
    56% (23)
  • B
    27% (11)
  • C
    12% (5)
  • D
    5% (2)

Why each option

Obfuscating personal information is the best recommendation to mitigate privacy risk when sharing data with a third party, as it reduces the identifiability of the data while potentially retaining its utility for the task.

AObfuscate the customers' personal information.Correct

Obfuscating or anonymizing personal information directly mitigates privacy risk by making the data less identifiable to the business partner, reducing the potential impact of unauthorized access or misuse while still allowing for process auditing.

BRequire the business partner to delete personal information following the audit.

Requiring data deletion addresses data retention policies but does not mitigate the privacy risk associated with the identifiable information being processed *during* the audit.

CUse a secure channel to transmit the files.

Using a secure channel protects the data during transmission but does not mitigate the privacy risk once the business partner has received and is processing the identifiable personal information.

DEnsure the contract includes provisions for sharing personal information.

Contractual provisions establish legal obligations but do not technically reduce the inherent privacy risk of sharing identifiable personal information itself; they primarily define responsibilities and liabilities.

Concept tested: Privacy risk mitigation (data obfuscation)

Source: https://learn.microsoft.com/en-us/azure/architecture/guide/security/data-masking

Topics

#Privacy risk mitigation#Data obfuscation#Third-party data sharing#Data minimization

Community Discussion

No community discussion yet for this question.

Full CRISC Practice