Professional Cloud Security EngineerEnsuring data protectionMedium
A financial institution is implementing Google Cloud Data Loss Prevention (DLP) to scan and redact sensitive data in Cloud Storage. They need to ensure that when a DLP scan identifies a credit card number, it is automatically replaced with a tokenized value while maintaining referential integrity for analytics purposes. Which DLP transformation method should they use?
- ACryptoReplaceFfxFpe
- BRedaction
- CDe-identification
- DRecordTransformations
Show answer & explanationAnswer & explanation
Correct answer: A. CryptoReplaceFfxFpe
To maintain referential integrity while replacing sensitive data with a tokenized value, the CryptoReplaceFfxFpe transformation method is the most suitable. It uses format-preserving encryption to generate consistent, tokenized outputs for the same input values.
Why the other options are wrong
- B. Redaction simply removes the sensitive data, which does not maintain referential integrity.
- C. De-identification is a general term for various techniques to remove identifying information, but CryptoReplaceFfxFpe is the specific method for format-preserving tokenization.
- D. RecordTransformations is a broader category for applying multiple transformations to structured data, not a specific transformation method for tokenization.
DLP CryptoReplaceFfxFpe
A Data Loss Prevention (DLP) transformation method that uses format-preserving encryption (FPE) to replace sensitive data with a tokenized value, maintaining the original data format and referential integrity.
- Preserves original data format (e.g., number of digits for a credit card).
- Generates consistent tokenized output for the same input.
- Ideal for maintaining referential integrity in analytics.
Memory trick: DLP's magic wand: Redact, Tokenize, Mask, or Hash to protect your data's story.