Q: 7
A healthcare organization needs to share patient data with a research institution for a study. The organization must ensure that the shared data does not reveal any personally identifiable information (PII) while still allowing the research institution to conduct meaningful analysis. Which data obfuscation technique should the healthcare organization implement to meet this requirement?
Options
Discussion
Option C
C. had something like this in a mock and RBAC was the right call.
C . Allowing users to self-assign (A) is the classic trap here, seen it pop up a lot on practice sets.
C
I don't think it's D. C is the answer, shared admin accounts are a classic trap here.
Pretty sure C is right for authorization in cloud, RBAC is what all the guides push.
C is the way to go here. Official study guides and most sample tests hammer RBAC as the best approach for mapping access to user roles in cloud. It ties right into least privilege and auditability, so I'm pretty sure this is what exam wants. Agree or any other sources say different?
C is what I'd pick too. Practice exams and the official guide both really stress RBAC for this scenario.
C all the way. RBAC lines up with least privilege and you can assign access based on job roles without overexposing anything. Letting users pick their own permissions or using shared accounts is a security headache. Pretty sure C is right here, but happy to hear other views.
C , saw similar in exam reports and RBAC is always pushed for authorization on cloud. Anyone pick something else?
Be respectful. No spam.