Courseiva
Cloud Data Security →hardMultiple Choice

CCSP Cloud Data Security Practice Question

A multinational corporation uses a cloud-based data warehouse to store aggregated analytics data. The data includes anonymized user behavior logs that, when combined with a separate dataset of user identifiers, could re-identify individuals. The security team wants to implement a data masking technique that preserves the statistical properties of the data for analytics while preventing re-identification. Which technique BEST meets these requirements?

⚠ Common exam trap

Many exam-takers confuse data masking techniques that preserve format or referential integrity with those that preserve statistical properties, which is a unique characteristic of differential privacy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Differential privacy that adds controlled noise to query results or data values to protect individual privacy.

Differential privacy is the only technique that provides a formal privacy guarantee while allowing accurate statistical analysis. It works by injecting noise calibrated to the sensitivity of the data, ensuring that individual records cannot be distinguished. This preserves the overall distribution and correlations, which are essential for analytics. Other techniques either destroy statistical utility or provide weaker privacy guarantees that can be compromised through auxiliary data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data generalization that replaces specific values with broader categories, such as age ranges instead of exact ages.

    Why it's wrong here

    Generalization reduces data granularity to prevent re-identification, but it also reduces statistical precision. While it can preserve some broad patterns, it does not maintain the fine-grained statistical properties needed for advanced analytics. It is a form of k-anonymity that can still be vulnerable to re-identification if the generalized categories are too narrow or if multiple datasets are combined. It does not provide the same rigorous privacy guarantee as differential privacy.

  • ✓

    Differential privacy that adds controlled noise to query results or data values to protect individual privacy.

    Why this is correct

    Differential privacy adds mathematical noise to data or query results, ensuring that the inclusion or exclusion of any single individual does not significantly affect the output. This preserves aggregate statistical properties while preventing re-identification. It is specifically designed for analytics scenarios where utility must be maintained. Unlike masking or tokenization, it provides a quantifiable privacy guarantee, making it the best fit for this requirement.

  • ✗

    Format-preserving encryption that encrypts user identifiers while maintaining their original format.

    Why it's wrong here

    Format-preserving encryption encrypts data such that the output has the same format as the input, but the encrypted values are not statistically similar to the originals. It does not preserve statistical properties like distributions or correlations. It is useful for legacy systems that require specific formats, but it does not meet the requirement of maintaining statistical utility for analytics while preventing re-identification.

  • ✗

    Tokenization that replaces user identifiers with randomly generated tokens stored in a secure vault.

    Why it's wrong here

    Tokenization replaces sensitive data with non-sensitive tokens, but it does not preserve statistical properties of the original data. The tokens are random and cannot be used for analytics that require correlations or distributions. While it prevents re-identification, it fails the requirement to maintain statistical utility. Tokenization is better suited for preserving referential integrity without exposing the original values.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.