Soru

Zorluk: OrtaData Governance, Classification, and Privacy Controls

A municipal smart-grid utility provider plans to share residential electricity consumption logs with an external research agency for energy forecasting analysis. To satisfy data privacy regulations, the dataset must prevent researchers from identifying individual customer accounts. However, the researchers must remain able to link distinct records belonging to the same household across separate quarterly files using a consistent, non-reversible surrogate key. Which of the following privacy-enhancing techniques should the security team implement?

  1. PseudonymizationCevap
  2. B
    Data Anonymization
  3. C
    Data Masking
  4. D
    Data Custodianship

Cevap

Pseudonymization is the correct privacy-enhancing technique because it replaces direct identifiers with consistent surrogate keys, allowing data correlation across distinct datasets while protecting individual privacy.
Pseudonymization replaces direct personal identifiers with pseudonyms or surrogate keys. This technique enables analysts to link disparate datasets belonging to the same entity over time without having access to the real-world identity of the customer.

Adım Adım Çözüm

1
Analyze the operational requirements stated in the scenario.
The utility provider requires two main features: protecting customer identity and allowing longitudinal linkage across multiple datasets using a consistent surrogate identifier.
Identifying specific technical requirements determines which technical privacy control applies.
2
Evaluate privacy-enhancing technology types against the requirements.
Pseudonymization replaces direct identifiers (e.g., account numbers) with consistent pseudonym keys. Anonymization destroys all linkage capabilities, data masking is aimed at obfuscation rather than relational tracking, and data custodianship is a management role.
Matching technical capabilities to requirements ensures compliance and functional utility.
3
Select the control that preserves data correlation without exposing PII.
Pseudonymization satisfies all constraints.
Pseudonymized data allows external analysts to join quarterly datasets by matching surrogate IDs without revealing direct identities.

Anahtar Kavram

Pseudonymization vs Anonymization and Privacy Controls
Bu soruyu puanla