Courseiva
Cloud Data Security →hardMultiple Select

CCSP Cloud Data Security Practice Question

A cloud data architect is designing a tokenization solution for a payment processing platform hosted in a public cloud. The platform must store primary account numbers (PANs) while minimizing PCI DSS scope and preventing raw PAN exposure in application logs and analytics pipelines. Which TWO design elements are most critical to achieve these goals? (Choose two.)

⚠ Common exam trap

The trap here is treating tokenization as simply encrypting data, when the essential design is early substitution plus isolation of the token-to-PAN mapping from the systems that process tokens.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a format-preserving token that replaces the PAN with a value of similar length and character set, stored in a separate token vault with strict access controls.

Tokenization at the point of capture and a format-preserving token stored in an isolated vault are the two critical elements. Early tokenization keeps raw PANs out of logs, queues, and analytics, while format preservation allows existing systems to process tokens without redesign. The vault separation ensures that even if downstream systems are compromised, the original PANs remain protected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a format-preserving token that replaces the PAN with a value of similar length and character set, stored in a separate token vault with strict access controls.

    Why this is correct

    A format-preserving token maintains the data format so existing applications and databases can process it without schema changes, while the token vault isolates the mapping to the original PAN. Strict access controls on the vault limit exposure and reduce PCI DSS scope because most systems handle only tokens. This design directly minimizes raw PAN propagation into logs and analytics.

  • ✓

    Apply the tokenization at the point of data capture, before the PAN enters application logs, message queues, or analytics pipelines.

    Why this is correct

    Tokenizing at the point of capture prevents the raw PAN from ever entering downstream systems, which is essential for minimizing PCI DSS scope and avoiding exposure in logs and analytics. Once tokenized early, subsequent processing, storage, and analysis operate only on tokens. This control is a foundational element of a defensible tokenization architecture.

  • ✗

    Ensure the tokenization service is deployed in the same network subnet as the analytics platform to reduce latency for token lookups.

    Why it's wrong here

    Co-locating the tokenization service with analytics increases the attack surface and may expose the token vault to analytics workloads that should never access raw PANs. Latency optimization is secondary to scope reduction and data isolation. Best practice is to segment the token vault from analytics and enforce strict network and identity controls, so this design element undermines the security objective.

  • ✗

    Use reversible encryption with a shared symmetric key for the PAN and store the key in the application configuration file for operational simplicity.

    Why it's wrong here

    Reversible encryption with a key in a configuration file is insecure because anyone with application access can decrypt PANs, and the key may leak through source control or backups. This approach does not reduce PCI DSS scope as effectively as tokenization and fails to prevent raw PAN exposure in logs. It also violates key management best practices by placing the key outside a secure store.

  • ✗

    Store the token-to-PAN mapping in the same database as the tokenized transaction records to simplify joins and reporting.

    Why it's wrong here

    Storing the mapping alongside tokenized records defeats the purpose of tokenization because a single compromise exposes both tokens and the original PANs. PCI DSS scope would expand to include the transaction database, and analytics queries could inadvertently access raw values. The mapping should reside in a hardened, isolated token vault with separate access controls.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.