CompTIA Security+ (SY0-701)Security ArchitectureMedium

A payment processor wants to reduce the scope of PCI DSS compliance by ensuring that actual credit card numbers are never stored in its application databases, while still allowing customer service representatives to reference past transactions by a substitute value. Which technique BEST achieves this?

  1. AData masking that displays only the last four digits on screen
  2. BTokenization, replacing card numbers with non-sensitive tokens
  3. CHashing the card numbers with SHA-256 before storage
  4. DEncrypting the database with a symmetric key stored on the same server
Show answer & explanation

Correct answer: B. Tokenization, replacing card numbers with non-sensitive tokens

Tokenization substitutes the sensitive card number with a non-sensitive token that has no exploitable value outside the tokenization system, allowing the application to reference transactions without ever storing the real card number, which significantly reduces PCI DSS scope.

Why the other options are wrong

  • A. Masking only changes what's displayed on screen; the full number is still stored in the database.
  • C. Hashing is one-way and irreversible, making it unsuitable for referencing or reconstructing the original transaction data.
  • D. Encrypting the database still stores the card data (just encrypted) and keeping the key alongside it undermines protection and does not reduce scope.

Tokenization

A data protection technique that replaces sensitive data with a non-sensitive placeholder (token) that maps back to the original value only within a secure tokenization vault.

  • Reduces compliance scope (e.g., PCI DSS) by removing sensitive data from most systems
  • Tokens have no mathematical relationship to the original data, unlike encryption
  • Different from masking, which only obscures display, not storage

Memory trick: 'Swap the real card for a claim ticket — the ticket means nothing outside the vault.'

More Security Architecture questions