CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium

A software company wants developers to test application features using realistic data without exposing actual customer information. It replaces real names, addresses, and account numbers in a copy of the production database with fictitious but structurally consistent values, with no way to reverse the process back to the original data. Which technique is this?

  1. AData masking
  2. BEncryption at rest
  3. CTokenization
  4. DKey rotation
Show answer & explanation

Correct answer: A. Data masking

Data masking replaces sensitive data with fictitious but realistic values, typically in an irreversible manner, making it ideal for non-production environments like development and testing where real data protection is unnecessary but functional data formats are still needed.

Why the other options are wrong

  • B. Encryption at rest protects stored data using reversible cryptographic algorithms and keys, not fictitious value substitution.
  • C. Tokenization replaces sensitive values with reversible tokens mapped back to the original data via a secure vault, unlike the irreversible masking described.
  • D. Key rotation refers to periodically changing encryption keys, unrelated to substituting data values.

Data Masking

A technique that replaces sensitive data with fictitious but structurally realistic values, typically irreversibly, to protect data used in non-production environments like testing and development.

  • Often irreversible, unlike tokenization
  • Preserves data format/structure for functional testing
  • Commonly used in dev/test/QA environments
  • Reduces exposure of real sensitive data outside production

Memory trick: 'Masking wears a costume' — data looks real but the true face is gone forever.

More Governance, Risk, Compliance and Security questions