CompTIA DataSys+ (DS0-001)Data and Database SecurityHard
A global e-commerce company is implementing a new payment processing system. Due to PCI DSS compliance requirements, sensitive credit card numbers (PANs) must be protected such that they are never stored in their original form within the company's internal databases, even for analytics. However, the system still needs to link transactions to specific payment methods and perform certain operations like refunds. Which data security technique allows for this functionality while keeping the original PANs out of scope?
- ATokenization
- BHomomorphic encryption
- CDatabase partitioning
- DColumn-level encryption
Show answer & explanationAnswer & explanation
Correct answer: A. Tokenization
Tokenization replaces sensitive data (like PANs) with a non-sensitive substitute (a token) that retains all necessary information without compromising security. The original PAN is stored securely in a separate, highly protected vault, and the token is used in the internal systems for processing, analytics, and linking transactions, significantly reducing the scope of PCI DSS compliance for internal databases.
Why the other options are wrong
- B. Homomorphic encryption allows computations on encrypted data without decrypting it, but it still involves storing the encrypted original data, not replacing it with a non-sensitive token for analytics.
- C. Database partitioning divides data into smaller, manageable pieces but doesn't inherently protect sensitive data or remove it from scope.
- D. Column-level encryption encrypts the PANs, but they are still present in the internal database in encrypted form, which doesn't fully remove them from PCI DSS scope.
Tokenization
A data security technique where sensitive data is replaced by a unique, non-sensitive identifier (token) that retains all essential information without compromising security.
- Original data is stored in a secure vault, while tokens are used internally.
- Significantly reduces the scope and cost of compliance (e.g., PCI DSS).
- Tokens are meaningless outside the tokenization system, protecting against breaches.
Memory trick: De-identification hides the true identity while keeping utility.