Certified Cloud Security Professional (CCSP)Cloud Data SecurityEasy

A financial institution is migrating highly sensitive customer records to a cloud data warehouse. To comply with privacy regulations and minimize the risk of data exposure in case of a breach, they decide to replace actual credit card numbers and personally identifiable information (PII) with unique, non-sensitive surrogate values. The original sensitive data needs to be recoverable for specific authorized processes. Which data security technique is being applied?

  1. AHashing
  2. BData Anonymization
  3. CData Masking
  4. DTokenization
Show answer & explanation

Correct answer: D. Tokenization

Tokenization replaces sensitive data with a randomly generated, non-sensitive token, while maintaining the ability to retrieve the original data through a secure vault. This fits the requirement of replacing sensitive data with surrogates while allowing recovery.

Why the other options are wrong

  • A. Hashing generates a fixed-size output that is irreversible, meaning the original data cannot be recovered from the hash.
  • B. Data anonymization aims to irreversibly remove PII, making the original data non-recoverable, which contradicts the requirement.
  • C. Data masking typically obscures data (e.g., partial redaction) and may not always allow full recovery, particularly for static masking.

Tokenization

A data security technique that replaces sensitive data with a unique, non-sensitive identifier (token) that has no extrinsic meaning or exploitable value, while the original data is stored securely elsewhere.

  • Replaces sensitive data with a token.
  • Original data is stored in a secure token vault.
  • Original data can be retrieved from the token.
  • Commonly used for credit card numbers and PII.

Memory trick: Masks hide, tokens replace, hashes seal, anonymize deletes.

More Cloud Data Security questions