CompTIA Security+ (SY0-701)Security OperationsMedium
A development team needs realistic customer records to test a new application in a QA environment. To prevent exposure of actual PII while preserving the data's format and usability for testing, which technique should be used?
- AData classification
- BData masking
- CFull disk encryption
- DDiscretionary access control lists
Show answer & explanationAnswer & explanation
Correct answer: B. Data masking
Data masking replaces sensitive values with realistic but fictitious data, preserving format and referential integrity so applications function normally in test environments without exposing real PII.
Why the other options are wrong
- A. Classification labels data sensitivity but does not itself protect or obscure the actual values.
- C. Encryption protects data at rest but would render the data unreadable/unusable for functional testing unless decrypted.
- D. ACLs control who can access data but do not alter or obscure the sensitive values themselves.
Data Masking
A technique that obscures or substitutes sensitive data with realistic fictitious values while preserving format, commonly used in non-production environments.
- Preserves data format/usability for testing
- Different from encryption (data remains 'readable' but fake)
- Static masking creates a permanently altered copy
- Dynamic masking obscures data on-the-fly at query time
Memory trick: Masking wears a disguise — same shape, fake face