ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium

An organization is migrating its on-premises customer database, containing PII, to a public cloud environment. Before the migration, a data governance committee determines that certain fields, such as customer names and email addresses, must be obfuscated or replaced with fictitious data for all non-production environments (development, testing, QA). Which data security control is being applied here?

  1. AData encryption in transit
  2. BData loss prevention (DLP)
  3. CData masking
  4. DTokenization
Show answer & explanation

Correct answer: C. Data masking

Data masking (or data obfuscation) is the process of hiding original data with modified content. It creates a structurally similar but inauthentic version of data that can be used for purposes like testing or training in non-production environments, where real sensitive data is not required, thus protecting PII while maintaining data utility.

Why the other options are wrong

  • A. Encryption in transit protects data while it's moving, not while it's at rest or being used in non-production environments.
  • B. DLP aims to prevent sensitive data from leaving authorized boundaries, but data masking actively transforms the data for safe use in non-production environments.
  • D. Tokenization replaces sensitive data with a unique, non-sensitive identifier (token), typically used for payment card data in production, not for creating realistic test data.

Data Masking

A technique used to create a structurally similar but inauthentic version of sensitive data, used primarily in non-production environments (e.g., development, testing) to protect real PII while maintaining data utility.

  • Replaces sensitive data with fictitious data.
  • Preserves data format and type for application compatibility.
  • Used to protect PII in non-production environments.

Memory trick: Mask for tests, Encrypt for rest.

More Asset Security questions