CompTIA CySA+ CS0-003 (V3) Practice Question

A development team suggests that using data masking on all personally identifiable information (PII) is a sufficient replacement for encryption when transmitting that data between internal servers. Which of the following statements represents the most significant security flaw in this data handling strategy?

  • Regulatory standards, such as GDPR and CCPA, explicitly forbid the use of data masking for any type of PII.

  • Masked data is designed to be easily reversible, allowing an attacker to recover the original PII.

  • Encryption in transit is only required for data crossing public networks, not for internal server-to-server communication.

  • Data masking does not protect the communication channel from interception; therefore, encryption in transit is necessary to ensure confidentiality.

CompTIA CySA+ CS0-003 (V3)
Vulnerability Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot