ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization needs to copy its on-premises customer database that contains names, email addresses, and credit-card PANs into a public-cloud development subscription. Developers require data that looks and behaves like production values for functional testing, but compliance demands that the cloud copy never expose real customer identities and that the transformation be irreversible. Which data-obfuscation approach BEST satisfies these requirements?

  • Apply vault-based tokenization so developers can detokenize data on demand.

  • Replace sensitive columns with NULL values during extract to the cloud.

  • Substitute each sensitive field with realistic, format-preserving fictional values through static data masking before export.

  • Encrypt sensitive fields using format-preserving encryption keys stored on-premises for later decryption.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot