Professional Cloud Security EngineerEnsuring data protectionMedium

A financial institution is implementing Google Cloud Data Loss Prevention (DLP) to scan and redact sensitive data in Cloud Storage. They need to ensure that when a DLP scan identifies a credit card number, it is automatically replaced with a tokenized value while maintaining referential integrity for analytics purposes. Which DLP transformation method should they use?

  1. ACryptoReplaceFfxFpe
  2. BRedaction
  3. CDe-identification
  4. DRecordTransformations
Show answer & explanation

Correct answer: A. CryptoReplaceFfxFpe

To maintain referential integrity while replacing sensitive data with a tokenized value, the CryptoReplaceFfxFpe transformation method is the most suitable. It uses format-preserving encryption to generate consistent, tokenized outputs for the same input values.

Why the other options are wrong

  • B. Redaction simply removes the sensitive data, which does not maintain referential integrity.
  • C. De-identification is a general term for various techniques to remove identifying information, but CryptoReplaceFfxFpe is the specific method for format-preserving tokenization.
  • D. RecordTransformations is a broader category for applying multiple transformations to structured data, not a specific transformation method for tokenization.

DLP CryptoReplaceFfxFpe

A Data Loss Prevention (DLP) transformation method that uses format-preserving encryption (FPE) to replace sensitive data with a tokenized value, maintaining the original data format and referential integrity.

  • Preserves original data format (e.g., number of digits for a credit card).
  • Generates consistent tokenized output for the same input.
  • Ideal for maintaining referential integrity in analytics.

Memory trick: DLP's magic wand: Redact, Tokenize, Mask, or Hash to protect your data's story.

More Ensuring data protection questions