ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your SaaS-based HR platform must deliver a monthly export of employee records to an external analytics provider. Compliance requires that the provider cannot re-identify any employee, even if it enriches the file with public data, yet your internal support engineers must be able to recover the real identifiers during incident investigations. Which data-obfuscation technique should be applied to the dataset before it leaves the cloud environment?
Hash every identifier using SHA-256 before releasing the file
Apply static data masking to overwrite each identifier with fictional but realistic values
Introduce differential privacy noise into quasi-identifying attributes across the dataset
Replace identifiers with tokens managed in a secure, internal tokenization vault
Tokenization replaces sensitive fields with random tokens whose only meaningful mapping to the real data is stored in a protected token vault inside the organization. To outsiders the tokens are unlinkable to specific individuals, so the analytics provider cannot re-identify employees-even when combining the file with external data. Because the original values are kept in the vault, authorized support engineers can later reverse the process and retrieve the true identifiers when troubleshooting.
Static masking, one-way hashing, and differential privacy all break the link to the original values in a way that is effectively irreversible, so they fail to meet the requirement for later recovery of the real data.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is tokenization in data security?
Open an interactive chat with Bash
How does tokenization differ from encryption?
Open an interactive chat with Bash
Why is static masking not suitable in this context?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .