CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsHard

A company's production database must allow full, unmasked access to Social Security numbers for the compliance team, while call center representatives querying that same live database see only the last four digits of each SSN at the moment of query, with no change made to the actual stored values. Which technique satisfies this requirement?

  1. APseudonymization
  2. BDynamic data masking
  3. CStatic data masking
  4. DEncryption at rest
Show answer & explanation

Correct answer: B. Dynamic data masking

Dynamic data masking obscures sensitive data in real time based on the requesting user's role or privileges, without altering the underlying stored data, so different users can see different views of the same live record. Static masking permanently alters copies of data (e.g., for test environments), pseudonymization permanently replaces identifiers in a dataset, and encryption at rest protects data only while stored, not selectively by viewer.

Why the other options are wrong

  • A. Pseudonymization permanently substitutes identifiers with artificial values across the dataset, not a viewer-dependent real-time mask.
  • C. Static masking permanently replaces values in a copy of the data, typically for non-production environments.
  • D. Encryption at rest protects stored data from unauthorized access but doesn't provide role-based partial visibility at query time.

Dynamic Data Masking

A security technique that obscures sensitive data in real time as it is queried, based on the user's role or privilege level, without modifying the underlying stored data.

  • Applied at query/view time, not to the stored data itself
  • Different users can see different masked/unmasked views of the same record
  • Contrasts with static masking, which permanently alters a data copy (e.g., for test/dev)

Memory trick: Dynamic masking = a one-way mirror 🪞 showing different faces depending on who's looking

More Data Governance, Quality and Controls questions