exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 208 discussion

Actual exam question from CompTIA's CS0-002
Question #: 208
Topic #: 1
[All CS0-002 Questions]

A company has contracted with a software development vendor to design a web portal for customers to access a medical records database. Which of the following should the security analyst recommend to BEST control the unauthorized disclosure of sensitive data when sharing the development database with the vendor?

  • A. Establish an NDA with the vendor.
  • B. Enable data masking of sensitive data tables in the database.
  • C. Set all database tables to read only.
  • D. Use a de-identified data process for the development database.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Comptia_Secret_Service
Highly Voted 2 years, 6 months ago
Selected Answer: B
This like the 3rd or 4th question where the answer is Data Masking lol.
upvoted 11 times
2Fish
2 years, 3 months ago
I am leaning on B as well, since Masking is considered a 'deidentification process" as well is tokenization. Many times de-identificaiton is used in research were industries would want to correlate certain data but not have certain patients information related to the data.
upvoted 1 times
...
SimonR2
1 year, 11 months ago
No, data masking is obfuscation and is typically used for credit card information not medical records.
upvoted 1 times
...
...
anhod1578
Most Recent 1 year, 3 months ago
Selected Answer: D
De-identified data: This process removes or replaces personally identifiable information (PII) from the data while preserving the overall structure and characteristics for development purposes. This significantly reduces the risk of exposing sensitive patient information to unauthorized individuals.
upvoted 1 times
...
TheStudiousPeepz
1 year, 7 months ago
Comptia Study Guide: "Data masking can also use techniques to preserve the original format of the field. Data masking is an irreversible deidentification technique."
upvoted 1 times
...
DonRonJon
1 year, 7 months ago
healthcare = de-identified
upvoted 2 times
...
[Removed]
1 year, 7 months ago
Selected Answer: D
Answer is clearly D based off CompTIA's own study guide Deidentification Controls Large datasets are often shared or sold between organizations and companies, especially within the healthcare industry. Where these datasets contain PII or PHI, steps can be taken to remove the personal or identifying information. These processes can also be used internally, so that one group within a company can receive data for analysis without unnecessary risks to privacy.
upvoted 3 times
...
SimonR2
1 year, 11 months ago
Data masking is more suitable for credit card numbers, not records relating to PHI and PII. Deidentification would allow the informaton to be shared with third parties as it cant be linked to any person. The US GOV has an entire article here about how to deidentify PHI data so it can be shared with third parties. Masking isn't mentioned once: https://www.hhs.gov/hipaa/for-professionals/privacy/special-topics/de-identification/index.html
upvoted 3 times
...
thenewpcgamer
2 years, 2 months ago
De-identified info would still retain PHI
upvoted 1 times
...
thenewpcgamer
2 years, 2 months ago
Selected Answer: B
B is a better and then D, because de-identified data process removes PII but retains PHI. This is suitable for sharing information between medical researchers but is unnecessary for a software developer.
upvoted 1 times
...
[Removed]
2 years, 2 months ago
Selected Answer: D
I believe the answer is D.. I know this question completely sucks and could be interchangeable but then I found this article. It specifically speaks to HIPPA information. https://mask-me.net/blog-news/back-to-basics-de-identification-vs-data-masking/
upvoted 2 times
...
[Removed]
2 years, 3 months ago
Selected Answer: D
We are dealing with medical information which until de-identified, is still protected by HIPPA. Data masking would work were we not dealing with medical data. So the only option is D. https://healthitsecurity.com/features/de-identification-of-phi-according-to-the-hipaa-privacy-rule
upvoted 1 times
...
absabs
2 years, 4 months ago
I think, masking is best answer, because software development will working with DB. If we are performing de-identified, developing process will wrongly.
upvoted 1 times
...
IanRogerStewart
2 years, 4 months ago
Selected Answer: B
Generally deidentification is where all PII is removed and data is merged to provide aggregrate info - would be hard to maintain the DB structure. There's some overlap between B & D here, but I think they want to see masking.
upvoted 3 times
...
prntscrn23
2 years, 6 months ago
Selected Answer: D
I'm choosing D. As I understand, de-identification is removing the identifiers of a person or patient based from from this scenario. Identifiers are patient names, address, their medical record info and so on. Removing these identifiers the medical facility can share the de-identified information to the vendor. Also, the medical facility complies with the compliance of HIPAA.
upvoted 3 times
...
cmllsu
2 years, 6 months ago
Selected Answer: D
Same question before with D as answer. It looks like the discussion for this was refreshed.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...