exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 701 discussion

Actual exam question from Isaca's CRISC
Question #: 701
Topic #: 1
[All CRISC Questions]

A risk practitioner recently discovered that sensitive data from the production environment is required for testing purposes in non-production environments. Which

of the following is the BEST
recommendation to address this situation?

  • A. Mask data before being transferred to the test environment.
  • B. Implement equivalent security in the test environment.
  • C. Enable data encryption in the test environment.
  • D. Prevent the use of production data for test purposes.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
8e1c45b
9 months, 1 week ago
Selected Answer: A
Go with A
upvoted 1 times
...
SuperMax
1 year, 2 months ago
Selected Answer: A
A. Mask data before being transferred to the test environment. The best recommendation in this situation is to mask sensitive data before transferring it to the test environment. Data masking involves replacing sensitive information with realistic but fictional data that cannot be used to identify individuals or reveal confidential information. This approach allows for effective testing while safeguarding sensitive production data.
upvoted 1 times
SuperMax
1 year, 2 months ago
Option B, "Implement equivalent security in the test environment," can be challenging and expensive, as replicating the exact security measures of the production environment in the test environment can be complex and may not fully eliminate the risk of data exposure during testing. Option C, "Enable data encryption in the test environment," is important for securing data in transit, but it doesn't necessarily protect the data at rest in the test environment or ensure that the data used for testing doesn't expose sensitive information. Option D, "Prevent the use of production data for test purposes," might be ideal from a security perspective, but it's often not practical, as testing with realistic data is essential for quality assurance and system validation. Masking the data allows for effective testing while maintaining data privacy and security.
upvoted 1 times
...
...
Koulyo
1 year, 9 months ago
Mask or tokenize the data. I go with A. It’s prudent not to share production data with developer neither provide them with production security level. Need to know basis.
upvoted 1 times
...
CbtL
1 year, 9 months ago
Going with B. A "feels" like the ISACA answer, however dealing with a real life security standard for years that requires B causes me to choose B. The confusion is coming from Suchib's question, "if you need it can you mask it?".
upvoted 1 times
...
john_boogieman
1 year, 10 months ago
Selected Answer: A
As in another similar question rectified, it is best to: mask the data before transferring it to the test environment. Masking data involves replacing sensitive information with realistic but fictitious data that can be used for testing purposes. By masking the data, the organization can ensure that sensitive information is not exposed in non-production environments, reducing the risk of unauthorized access, data breaches, and other security incidents.
upvoted 2 times
...
john_boogieman
1 year, 11 months ago
Selected Answer: B
Keep it simple. If the data is necessary in the test environment, at least apply the same security measures as production (why are you going to mask if maybe in production there are not these measures?).
upvoted 1 times
...
Suchib
2 years ago
If we need to use the data, can we mask it?
upvoted 1 times
...
MartyMar
2 years, 2 months ago
I am going with using equivalent security measures. The question is saying you need to use Prod Data in the Test environment (if you didn't have to then of course you wouldn't use it in the test environment) Not to mention most places require you to get an Interm Authorization to Test (IATT) and this is approved by the AO it requires a test plan and how you intend on protecting that data.
upvoted 1 times
...
Raj1510
2 years, 12 months ago
first choose is not to use , but if require data masking is best possible solution. Generally testing environment not have all such security controls which are present in production. so support answer A
upvoted 2 times
...
Stefan07
3 years, 8 months ago
Answer is B
upvoted 1 times
...
Odenkyem
3 years, 8 months ago
I will go for : A. Mask data before being transferred to the test environment.
upvoted 1 times
...
hussmohsin
3 years, 11 months ago
You should mask the data answer is A, its cheaper and not all users in test will have authority to see production data.
upvoted 2 times
Ics2Pass
3 years, 10 months ago
You can't mask them as those data are required for testing purposes...
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...