ExamGecko
Question list
Search
Search

Question 288 - CISM discussion

Report
Export

Which risk is introduced when using only sanitized data for the testing of applications?

A.
Data loss may occur during the testing phase.
Answers
A.
Data loss may occur during the testing phase.
B.
Data disclosure may occur during the migration event
Answers
B.
Data disclosure may occur during the migration event
C.
Unexpected outcomes may arise in production
Answers
C.
Unexpected outcomes may arise in production
D.
Breaches of compliance obligations will occur.
Answers
D.
Breaches of compliance obligations will occur.
Suggested answer: C

Explanation:

Unexpected outcomes may arise in production when using only sanitized data for the testing of applications. Sanitized data is data that has been purposely and permanently deleted or modified to prevent unauthorized access or misuse. Sanitized data may not reflect the real characteristics, patterns, or behaviors of the original data, and thus may not be suitable for testing applications that rely on data quality and accuracy. According to NIST, data sanitization methods can affect the usability of data for testing purposes1. The other options are not risks introduced by using sanitized data for testing applications, but rather risks that can be mitigated by using sanitized data. Data loss, data disclosure, and breaches of compliance obligations are possible consequences of using unsanitized data that contains sensitive or confidential information.

Reference: 2: What is Data Sanitization? | Data Erasure Methods | Imperva 3: Data sanitization techniques: Standards, practices, legislation 1: Data sanitization -- Wikipedia

asked 01/10/2024
Aur ROULIC
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first