Courseiva
hardMultiple Choice

CCSP Practice Question: A healthcare organization wants to perform…

A healthcare organization wants to perform analytics on encrypted patient data without decrypting it first, to maintain privacy. Which cryptographic technique supports this use case?

⚠ Common exam trap

ISC2 often tests the distinction between 'processing on encrypted data' and 'protecting data at rest or in transit'—candidates mistakenly choose FPE or tokenization because they see 'encrypted' or 'token' and assume it supports analytics, but neither allows computation without decryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Homomorphic encryption

Homomorphic encryption allows computations to be performed directly on ciphertext, producing an encrypted result that, when decrypted, matches the result of operations performed on the plaintext. This enables the healthcare organization to run analytics on encrypted patient data without ever exposing the underlying sensitive information, thus preserving privacy throughout the processing lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Homomorphic encryption

    Why this is correct

    Homomorphic encryption permits computation directly on ciphertext, so analytics produce encrypted results that decrypt to match operations on the plaintext. This satisfies the healthcare constraint of processing patient data while it remains encrypted, preserving privacy since plaintext is never exposed to the analytics platform.

  • ✗

    Tokenization

    Why it's wrong here

    Tokenization replaces values with surrogate tokens held in a separate vault, so analytics operate on opaque references rather than the encrypted data itself; the original values must be retrieved to compute. It is tempting because it reduces PCI scope, and it would be correct for protecting stored cardholder data, not for computing over ciphertext.

  • ✗

    Format-preserving encryption (FPE)

    Why it's wrong here

    Format-preserving encryption produces ciphertext in the same format as the plaintext, but ordinary FPE still requires decryption before computation, so analytics cannot run on the encrypted values directly. It is tempting because it keeps database schemas and field lengths intact, and it would be correct for legacy systems needing fixed-format encrypted fields.

  • ✗

    Cryptographic hashing

    Why it's wrong here

    Hashing is one-way and destroys the plaintext, so analytics requiring the original values cannot run on the output; it only supports integrity checks and lookups. It is tempting because hashed data is unreadable, but the correct technique preserves computable ciphertext. Hashing would suit password storage or deduplication, not encrypted computation.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.