Courseiva
Cloud Data Security →mediumMultiple Choice

CCSP Cloud Data Security Practice Question

A cloud security team is implementing data loss prevention for a data lake that stores customer support logs. They need to redact credit card numbers from the logs before they are used for analytics. Which DLP de-identification technique should be applied?

⚠ Common exam trap

CCSP often tests the distinction between reversible pseudonymization (tokenization) and irreversible anonymization (masking) — candidates incorrectly choose tokenization because it sounds more 'secure,' but the question specifically asks for redaction of the number itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Masking

Masking is the correct DLP de-identification technique because it replaces sensitive values like credit card numbers with obfuscated characters (e.g., ****-****-****-1234) while preserving the format and length of the original data. This allows the support logs to remain usable for analytics and pattern matching without exposing the actual PAN data. Masking is irreversible or partially reversible depending on configuration, making it ideal for redaction before analytics processing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Date shifting

    Why it's wrong here

    Date shifting alters temporal values by a consistent offset, leaving credit card numbers intact and readable. It is tempting because it preserves analytical utility; it would be correct when the requirement is de-identifying dates in a dataset while retaining relative time intervals, not removing payment card data.

  • ✗

    Bucketing

    Why it's wrong here

    Bucketing replaces values with range categories, so a card number would be generalised rather than removed, and the digits could remain recoverable. It is tempting because it preserves analytical utility; it would be correct when the requirement is generalising continuous values such as ages or incomes into bands, not redacting payment card data.

  • ✓

    Masking

    Why this is correct

    Masking replaces detected credit card values with a placeholder character, such as a hash or asterisk, so the sensitive digits are irreversibly removed from the log records while the surrounding analytics fields remain intact and queryable.

  • ✗

    Tokenization

    Why it's wrong here

    Tokenization substitutes a surrogate value mapped to the original in a secured token vault, so the card number is recoverable and the sensitive data still exists. It is tempting because it preserves referential integrity; it would be correct when the requirement is reversible substitution for payment processing, not irreversible redaction.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.