mediumMultiple Select
CISA Practice Question: Which TWO of the following are key controls for…
Which TWO of the following are key controls for ensuring data privacy during system development?
⚠ Common exam trap
Test-takers frequently confuse 'data masking' with 'anonymization' and overlook its role as a key privacy control, or mistakenly think that using real data in test environments is acceptable if it is 'just for testing,' ignoring regulatory and ethical requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypting stored data
Option B (Encrypting stored data) is correct because encryption at rest (e.g., AES-256) protects sensitive data from unauthorized disclosure even if storage media or backups are compromised, directly supporting data privacy during development. Option E (Data masking in test environments) is correct because masking, tokenization, or pseudonymization replaces real PII with realistic but fictitious values, allowing developers and testers to work without exposing actual customer data. Option A is wrong because using real customer data for testing violates privacy principles and regulations like GDPR or HIPAA; test data should be synthetic or masked. Option C is wrong because disabling audit logs removes accountability and traceability, which are essential privacy and security controls. Option D is wrong because unlimited developer access to production data violates least privilege and dramatically increases the risk of privacy breaches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using real customer data for testing
Why it's wrong here
Real customer data in test environments exposes personal information without production safeguards, breaching privacy-by-design. It is tempting because production data gives realistic test coverage, and masked or synthetic data is the correct substitute when realistic volumes are needed.
- ✓
Encrypting stored data
Why this is correct
Encrypting stored data directly satisfies the privacy requirement by rendering data unreadable without decryption keys, protecting confidentiality if storage media or backups are compromised. This control addresses data-at-rest exposure, a core privacy safeguard during development, ensuring sensitive personal information remains protected against unauthorised access throughout the system's lifecycle.
- ✗
Disabling audit logs during development
Why it's wrong here
Disabling audit logs removes the accountability trail needed to detect and investigate privacy breaches during development. It is tempting to reduce noise or overhead, and reduced-verbosity logging is correct when volume, not traceability, is the concern.
- ✗
Allowing developers unlimited access to production data
Why it's wrong here
Unrestricted production access lets developers view or alter live personal data, violating least privilege and segregation of duties. It is tempting for troubleshooting realism, and scoped, logged, just-in-time access is correct when production investigation is genuinely required.
- ✓
Data masking in test environments
Why this is correct
Data masking substitutes realistic personal identifiers with fictitious values in non-production datasets, so developers and testers can work without exposing live personal data. This directly satisfies the stem's privacy constraint by preventing unnecessary disclosure beyond the production boundary, supporting data minimisation and reducing breach impact during development and testing.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.