CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium
A software company wants developers to test application features using realistic data without exposing actual customer information. It replaces real names, addresses, and account numbers in a copy of the production database with fictitious but structurally consistent values, with no way to reverse the process back to the original data. Which technique is this?
- AData masking
- BEncryption at rest
- CTokenization
- DKey rotation
Show answer & explanationAnswer & explanation
Correct answer: A. Data masking
Data masking replaces sensitive data with fictitious but realistic values, typically in an irreversible manner, making it ideal for non-production environments like development and testing where real data protection is unnecessary but functional data formats are still needed.
Why the other options are wrong
- B. Encryption at rest protects stored data using reversible cryptographic algorithms and keys, not fictitious value substitution.
- C. Tokenization replaces sensitive values with reversible tokens mapped back to the original data via a secure vault, unlike the irreversible masking described.
- D. Key rotation refers to periodically changing encryption keys, unrelated to substituting data values.
Data Masking
A technique that replaces sensitive data with fictitious but structurally realistic values, typically irreversibly, to protect data used in non-production environments like testing and development.
- Often irreversible, unlike tokenization
- Preserves data format/structure for functional testing
- Commonly used in dev/test/QA environments
- Reduces exposure of real sensitive data outside production
Memory trick: 'Masking wears a costume' — data looks real but the true face is gone forever.