CISSP Asset Security Practice Question
Which term describes the process of modifying data so that it cannot be attributed to a specific individual without additional information that is kept separately?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pseudonymisation
Pseudonymisation replaces identifying information with pseudonyms, allowing re-identification with additional data kept separately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anonymisation
Why it's wrong here
Anonymisation is a process that irreversibly transforms personal data so that the data subject can no longer be identified, either directly or indirectly, by any means and by anyone. This typically involves techniques like generalization, suppression, or perturbation, ensuring that re-identification is practically impossible, even with additional data. It aims for a permanent loss of identifiability, making it distinct from methods that retain a link.
- ✗
Differential privacy
Why it's wrong here
Differential privacy is a rigorous mathematical definition and set of techniques used to protect individual privacy in statistical databases by adding carefully calibrated noise to query results or aggregated data. Its primary goal is to ensure that the presence or absence of any single individual's data in a dataset does not significantly affect the outcome of an analysis, thereby preventing inferences about specific individuals. It focuses on protecting insights derived from data, not on modifying individual source records for de-identification.
- ✓
Pseudonymisation
Why this is correct
Pseudonymisation is a data management and de-identification technique where directly identifying fields within a data record are replaced with artificial identifiers, or pseudonyms. While the direct identifiers are removed, a separate 'key' or mapping table is maintained, allowing for the re-identification of the original data subject if necessary, typically under strict controls and for specific purposes. This process reduces the linkability of a dataset to an individual without completely destroying the possibility of re-identification, making it a reversible de-identification method.
- ✗
Encryption
Why it's wrong here
Encryption is a cryptographic technique that transforms data into an unreadable format (ciphertext) using an algorithm and a key, primarily to ensure confidentiality and data integrity during storage or transmission. While it renders data unintelligible without the correct decryption key, its purpose is secure protection, not to permanently or semi-permanently remove direct identifiers or reduce the linkability of data to an individual in a de-identified state. Encrypted data still contains the original personal information, just in a protected form, and is fully reversible with the key.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.