CompTIA Security+ (SY0-701)Security ArchitectureMedium

A hospital wants to let its analytics team query patient records to study treatment trends without exposing actual names or Social Security numbers, while still allowing the analysts to see realistic-looking but fictional values in those fields. Which technique BEST meets this need?

  1. ADigital signing
  2. BAccess control lists
  3. CData masking
  4. DFull disk encryption
Show answer & explanation

Correct answer: C. Data masking

Data masking replaces sensitive values with realistic but fictitious data, preserving the format and usability of the dataset for analysis while protecting the original sensitive values.

Why the other options are wrong

  • A. Digital signing verifies data integrity and origin, not confidentiality of field values.
  • B. ACLs control who can access a resource but do not alter the sensitive values themselves.
  • D. Full disk encryption protects data if a disk is stolen but does not hide values from authorized query access.

Data Masking

A technique that replaces sensitive data with realistic but fictitious values, preserving format for testing/analytics while protecting confidentiality.

  • Common in non-production/test environments
  • Static masking permanently alters copies; dynamic masking alters on-the-fly
  • Differs from tokenization, which uses reversible token mapping

Memory trick: Masking hides the face, tokenization swaps the ID.

More Security Architecture questions