mediumMultiple Choice
CCSP Practice Question: A financial institution uses a cloud data…
A financial institution uses a cloud data warehouse to store transaction data. The data is classified into three tiers: public, internal, and confidential. The current architecture stores all data in a single dataset with column-level encryption for confidential fields. A recent internal penetration test revealed that an analyst with access to the data warehouse could query aggregated statistics that inadvertently revealed confidential individual transactions. The security team needs to implement a solution that prevents such data leakage while preserving analytical capabilities. Which solution BEST addresses this?
⚠ Common exam trap
ISC2 often tests the distinction between access control mechanisms (row-level security, masking, encryption) and privacy-preserving techniques (differential privacy), trapping candidates who confuse restricting direct data access with preventing inference from aggregated outputs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a differential privacy framework that adds noise to query results.
Differential privacy is the correct solution because it directly addresses the core issue: aggregated statistics can be reverse-engineered to infer individual records. By adding calibrated noise to query results, it ensures that the output of any query does not reveal whether a specific individual's data is present, thus preventing leakage from aggregate queries while still allowing analysts to derive meaningful trends and patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a differential privacy framework that adds noise to query results.
Why this is correct
Differential privacy injects calibrated statistical noise into query outputs, so aggregated results no longer disclose individual transactions. This directly closes the inference path the penetration test exploited while still permitting analytical queries, satisfying the requirement to preserve analytics.
- ✗
Implement row-level security to restrict each analyst to only view data related to their assigned region.
Why it's wrong here
Region-based row filtering limits which records an analyst sees but leaves confidential columns intact, so aggregates over their own region still reveal individual transactions. Row-level security is the right control for tenant or geography segregation, not for stopping inference across classification tiers.
- ✗
Use dynamic data masking to obscure confidential fields based on the user's clearance.
Why it's wrong here
Masking rewrites the confidential field values returned to lower-clearance users, yet aggregate functions such as SUM or AVG over masked columns still let an analyst infer individual transactions from the returned statistics. Dynamic masking suits hiding values in row-level lookups, not preventing inference from aggregates.
- ✗
Encrypt the entire dataset with a key that is only available to a privileged group.
Why it's wrong here
Whole-dataset encryption still decrypts to plaintext for any privileged query, so the analyst's aggregate queries continue exposing individual confidential transactions once decrypted. It is tempting because it protects data at rest, but it addresses storage compromise, not inference through authorised analytical access.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.