Courseiva
Cloud Data Security →mediumMultiple Select

CCSP Cloud Data Security Practice Question

A cloud security team is evaluating DLP techniques to protect sensitive data in a cloud data warehouse. They want to replace sensitive values with realistic but fictitious data for non-production environments while preserving referential integrity. Which TWO de-identification techniques are suitable?

⚠ Common exam trap

The trap is selecting masking because it is the most commonly mentioned de-identification technique — but masking does not preserve referential integrity, whereas pseudonymization and tokenization do through consistent mapping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pseudonymization

Pseudonymization (A) is correct because it replaces sensitive values with consistent artificial identifiers, so the same input always maps to the same pseudonym, which preserves referential integrity across tables and joins in non-production environments. Tokenization (D) is also correct because it substitutes sensitive data with non-sensitive tokens stored in a secure token vault, and the deterministic token-to-value mapping maintains referential integrity while providing realistic fictitious values. Bucketing (B) only generalizes values into ranges and does not produce realistic fictitious replacements or preserve exact referential links. Masking (C) typically obscures or redacts values, often irreversibly and without guaranteeing consistent cross-table substitution, so it does not reliably preserve referential integrity. Date shifting (E) only alters date values by a consistent offset and applies solely to date fields, not to general sensitive data replacement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Pseudonymization

    Why this is correct

    Pseudonymization swaps identifiers for consistent replacement values, so the same input always maps to the same output. That determinism preserves referential integrity across related tables while producing realistic fictitious data, exactly matching the non-production requirement without exposing genuine customer values.

  • ✗

    Bucketing

    Why it's wrong here

    Bucketing replaces exact values with ranges or categories, so distinct records can collapse into the same bucket and original values are not recoverable as realistic fictitious entries. It is tempting because it reduces re-identification risk while keeping data usable for analysis, which suits statistical reporting rather than referential integrity.

  • ✗

    Masking

    Why it's wrong here

    Masking obscures characters, typically producing values that are not realistic or format-preserving, and it often breaks the join keys that referential integrity depends on. It is tempting because it hides sensitive fields from unauthorised viewers, which is its real purpose — display-time redaction rather than substituting consistent fictitious records.

  • ✓

    Tokenization

    Why this is correct

    Tokenization replaces sensitive values with surrogate tokens held in a secure vault, and the same input yields the same token. This determinism maintains referential integrity across joined datasets, while the vault mapping keeps original values out of non-production environments, satisfying the realistic-fictitious-data requirement.

  • ✗

    Date shifting

    Why it's wrong here

    Date shifting alters temporal values by a consistent offset, preserving chronology but not substituting realistic fictitious identities, so it cannot replace names or identifiers while maintaining referential integrity across tables. It is tempting because it is a genuine de-identification technique for preserving date relationships in analytics and testing scenarios.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.