CCSP Cloud Data Security Practice Question
A multinational corporation is using a cloud-based data warehouse to analyze customer data. The data includes personally identifiable information (PII) from various countries. The security team needs to ensure that data is anonymized before analysis to comply with privacy regulations. Which technique should they use?
⚠ Common exam trap
The trap here is equating de-identification techniques like masking or tokenization with true anonymization, which requires irreversibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Generalization and suppression
Generalization and suppression are anonymization techniques that reduce data granularity and remove identifiers, making re-identification difficult. Tokenization and masking are reversible or not fully anonymizing, and encryption does not anonymize. These techniques help comply with privacy regulations by ensuring data cannot be linked to individuals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tokenization
Why it's wrong here
Tokenization replaces sensitive data with tokens that can be mapped back to the original data via a tokenization system. While it protects data, it is reversible and thus not true anonymization. The scenario requires anonymization for compliance, which typically implies irreversibility.
- ✗
Data masking
Why it's wrong here
Data masking obscures data by replacing it with fictitious but realistic values. It can be reversible or irreversible depending on implementation, but often it is used for testing and may not guarantee anonymization. The scenario specifically requires anonymization, which is a stronger form of de-identification.
- ✗
Encryption with customer-managed keys
Why it's wrong here
Encryption protects data confidentiality but does not anonymize it; the data can be decrypted with the key. For analysis, the data would need to be decrypted, exposing PII. This does not meet the requirement for anonymization before analysis.
- ✓
Generalization and suppression
Why this is correct
Generalization replaces specific values with broader categories, and suppression removes certain data fields. These techniques are core to anonymization frameworks like k-anonymity, making it difficult to re-identify individuals. They align with privacy regulations that require anonymization for data analysis.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.