Courseiva
hardMultiple Choice

CISA Practice Question: A company stores sensitive customer data in a…

A company stores sensitive customer data in a database. To comply with privacy regulations, the data must be anonymized for analytics. Which technique provides the strongest anonymization while preserving data utility?

⚠ Common exam trap

Test-takers frequently confuse pseudonymization (e.g., tokenization) with anonymization, or assume that simply removing direct identifiers is sufficient, failing to recognize that re-identification via quasi-identifiers is a well-known attack vector in privacy regulations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Differential privacy with calibrated noise.

Differential privacy with calibrated noise is the strongest anonymization technique because it provides a formal mathematical guarantee that the output of a query does not reveal whether any specific individual's data was included. By adding carefully calibrated noise to query results, it preserves statistical utility for analytics while ensuring that re-identification is provably infeasible, meeting strict privacy regulations like GDPR or CCPA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Differential privacy with calibrated noise.

    Why this is correct

    Differential privacy adds calibrated statistical noise, giving each individual plausible deniability while aggregate query results remain accurate. This provides mathematically provable anonymisation that k-anonymity and masking lack, satisfying the requirement for strong anonymisation with preserved analytical utility.

  • ✗

    Tokenization with a reversible mapping.

    Why it's wrong here

    Tokenisation with a reversible mapping retains a lookup table, so the original values remain recoverable and the data is pseudonymised, not anonymised. It is tempting because tokenisation preserves referential integrity for analytics, and would be correct where reversible substitution is required for payment processing rather than irreversible anonymisation.

  • ✗

    Removing direct identifiers like names and SSNs.

    Why it's wrong here

    Removing direct identifiers leaves quasi-identifiers such as postcode, birth date and gender, permitting re-identification through linkage attacks, so anonymisation is incomplete. It is tempting because it is simple and retains full analytical utility, and would be correct only where no external dataset could be joined to the records.

  • ✗

    Data masking with static substitution.

    Why it's wrong here

    Static substitution masking replaces values with consistent fictitious ones, but the mapping is retained and patterns persist, so re-identification remains feasible. It is tempting because masked data still supports testing and reporting, and would be correct for non-production environments rather than regulatory anonymisation for analytics.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.