CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium
A data analyst needs to work with a production database containing sensitive customer information for development and testing purposes. To comply with privacy regulations and prevent exposure of real customer data, the analyst requires a dataset that retains the structural characteristics and data types of the original but contains fictitious values. Which data security technique should be used?
- AData anonymization
- BData masking
- CData encryption
- DData tokenization
Show answer & explanationAnswer & explanation
Correct answer: B. Data masking
Data masking replaces sensitive data with structurally similar but inauthentic data, making it suitable for non-production environments like development and testing while maintaining data utility and complying with privacy regulations.
Why the other options are wrong
- A. Data anonymization removes or modifies identifying information to prevent re-identification, often used for analytics, but masking is more specific for creating realistic test data.
- C. Data encryption protects data confidentiality but requires decryption for use, which might expose original data in a test environment.
- D. Data tokenization replaces sensitive data with a non-sensitive 'token' for specific use cases, but the original data is still retrievable.
Data Masking
The process of obscuring specific sensitive data elements within a dataset, replacing them with realistic but fictitious data.
- Used primarily for non-production environments (development, testing, training).
- Maintains data format, structure, and integrity for application functionality.
- Prevents exposure of real sensitive data while allowing realistic testing.
Memory trick: Masks hide the truth, but keep the face.