CCSP Cloud Data Security Practice Question
A cloud security team is implementing data loss prevention for a data lake that stores customer support logs. They need to redact credit card numbers from the logs before they are used for analytics. Which DLP de-identification technique should be applied?
⚠ Common exam trap
CCSP often tests the distinction between reversible pseudonymization (tokenization) and irreversible anonymization (masking) — candidates incorrectly choose tokenization because it sounds more 'secure,' but the question specifically asks for redaction of the number itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Masking
Masking is the correct DLP de-identification technique because it replaces sensitive values like credit card numbers with obfuscated characters (e.g., ****-****-****-1234) while preserving the format and length of the original data. This allows the support logs to remain usable for analytics and pattern matching without exposing the actual PAN data. Masking is irreversible or partially reversible depending on configuration, making it ideal for redaction before analytics processing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Date shifting
Why it's wrong here
Date shifting alters temporal values by a consistent offset, leaving credit card numbers intact and readable. It is tempting because it preserves analytical utility; it would be correct when the requirement is de-identifying dates in a dataset while retaining relative time intervals, not removing payment card data.
- ✗
Bucketing
Why it's wrong here
Bucketing replaces values with range categories, so a card number would be generalised rather than removed, and the digits could remain recoverable. It is tempting because it preserves analytical utility; it would be correct when the requirement is generalising continuous values such as ages or incomes into bands, not redacting payment card data.
- ✓
Masking
Why this is correct
Masking replaces detected credit card values with a placeholder character, such as a hash or asterisk, so the sensitive digits are irreversibly removed from the log records while the surrounding analytics fields remain intact and queryable.
- ✗
Tokenization
Why it's wrong here
Tokenization substitutes a surrogate value mapped to the original in a secured token vault, so the card number is recoverable and the sensitive data still exists. It is tempting because it preserves referential integrity; it would be correct when the requirement is reversible substitution for payment processing, not irreversible redaction.
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.