CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsHard
A company needs to provide a third-party software vendor with a full copy of its production customer database for testing in a separate, non-production environment. To protect sensitive fields such as Social Security numbers and credit card numbers while preserving the data's format and referential integrity for testing, the company permanently replaces the sensitive values with realistic but fictitious values in the copied dataset before delivery. Which technique is being used?
- AStatic data masking
- BLegal hold
- CDynamic data masking
- DRole-based access control
Show answer & explanationAnswer & explanation
Correct answer: A. Static data masking
Static data masking permanently replaces sensitive values in a copy of the data (typically for non-production use such as testing or development), so the masked values are fixed and there is no original sensitive data to unmask. Dynamic data masking, by contrast, masks data in real time at query execution while leaving the underlying stored data unchanged.
Why the other options are wrong
- B. Legal hold suspends deletion of records for litigation purposes, unrelated to masking data for testing.
- C. Dynamic masking alters data on the fly for specific users querying the live production database, not a permanently altered copy.
- D. RBAC controls who can access systems based on role, not how data values are transformed before delivery.
Static Data Masking
A technique that permanently replaces sensitive data with realistic but fictitious values in a copy of a dataset, typically for use in non-production environments like testing or development.
- Creates a separate masked copy, unlike dynamic masking of live data
- Preserves data format/referential integrity for testing
- No original sensitive value remains recoverable in the masked copy
Memory trick: Dynamic masks live at query time; Static masks a frozen copy forever