mediumMultiple ChoiceObjective-mapped
CCSP Practice Question: A company uses a cloud-based database that…
A company uses a cloud-based database that contains personally identifiable information (PII). They need to allow developers to run queries against the database for testing purposes without exposing actual PII. Which technique should they use?
⚠ Common exam trap
ISC2 often tests the distinction between dynamic data masking and tokenization, where candidates mistakenly choose tokenization because they think a one-way hash is sufficient for testing, but they overlook that testing requires reversible or format-preserving transformations to maintain data utility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply dynamic data masking to the PII columns
Dynamic data masking (DDM) allows the database to return masked PII to developers in real time without altering the underlying stored data. This technique applies masking rules at query runtime, so developers can run functional tests against production-like data while sensitive values are obfuscated. It avoids the need for separate sanitized copies and preserves referential integrity for testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt the PII fields at rest
Why it's wrong here
Encryption doesn't allow plaintext queries without decrypting.
- ✗
Grant developers direct access to a copy of the production data
Why it's wrong here
This exposes actual PII.
- ✓
Apply dynamic data masking to the PII columns
Why this is correct
Masking provides realistic but fake data.
- ✗
Tokenize the PII fields with a one-way hash
Why it's wrong here
Tokenization may break relationships needed for testing.
Go deeper
Related to this question
About these practice questions
One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.