mediumMultiple Choice
CISA Practice Question: Is implementing a data masking solution for a…
An organization is implementing a data masking solution for a non-production database. Which of the following is the MOST important requirement?
⚠ Common exam trap
A common mix-up: candidates confuse data masking with encryption or hashing, assuming irreversibility or encryption are the top priorities, but the CISA exam emphasizes that the primary goal in a non-production environment is usability and data integrity, not cryptographic security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Masked data should maintain referential integrity.
In a non-production database, data masking must preserve referential integrity to ensure that relationships between tables (e.g., foreign keys) remain valid after masking. Without referential integrity, application logic that relies on these relationships would break, making the non-production environment unusable for testing or development. This is the most critical requirement because masked data must still function correctly within the database schema.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Masked data should maintain referential integrity.
Why this is correct
Masked values must preserve the relationships between primary and foreign keys across tables; otherwise joins in the non-production database break and testing becomes invalid. Maintaining referential integrity ensures the masked dataset remains structurally consistent and usable.
- ✗
Masked data should be encrypted.
Why it's wrong here
Encryption protects masked values at rest but does not guarantee the masking itself preserves referential integrity or prevents re-identification; the priority is that masked values remain consistent and non-reversible across related tables. It is tempting because encryption is a familiar data-protection control, and it would be relevant if the concern were storage-level confidentiality rather than masking adequacy.
- ✗
Masked data should be irreversible.
Why it's wrong here
Irreversibility prevents reconstruction of original values, but the primary requirement is that masked data preserves referential integrity and realistic formats so non-production testing remains valid. It is tempting because non-reversibility sounds like the strongest privacy guarantee, and it would be the priority if the masked data were being released outside the organisation.
- ✗
Masked data should be randomized across all columns.
Why it's wrong here
Randomising every column destroys referential integrity and cross-column consistency, so joins and application logic break in the non-production database. Randomisation suits standalone synthetic test data generation, not masking a copy of production. The governing requirement is that masked values preserve the format and relationships needed for valid testing.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.