easyMultiple Choice
CCSP Practice Question: A development team is working with…
A development team is working with production-like data in a non-production cloud environment. To comply with data privacy regulations, sensitive fields must be obscured without being retrievable. Which technique should they apply?
⚠ Common exam trap
ISC2 often tests the distinction between reversible and irreversible data protection methods, and the trap here is that candidates confuse 'masking' (which can be reversible or irreversible) with 'encryption' or 'tokenization,' assuming any transformation that hides data is sufficient, without recognizing the critical requirement of non-retrievability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Irreversible masking
Irreversible masking (C) is correct because it transforms sensitive data into a non-reversible format, ensuring that the original values cannot be retrieved. This meets the requirement of obscuring production-like data in a non-production environment while complying with data privacy regulations that prohibit reversible transformations. Unlike encryption or tokenization, irreversible masking does not provide any decryption or mapping mechanism, making it suitable for scenarios where data must be permanently de-identified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Format-preserving encryption
Why it's wrong here
Format-preserving encryption is reversible: the ciphertext decrypts back to the original value, so the sensitive fields remain retrievable and fail the obscuring requirement. It suits scenarios needing realistic-looking data that authorised systems must later decrypt, such as tokenising card numbers while preserving format for legacy schemas.
- ✗
Reversible masking
Why it's wrong here
Reversible masking can be unmasked by anyone holding the mapping or key, so the obscured values remain retrievable, breaching the requirement. It suits scenarios needing later re-identification, such as test-data correlation, not irreversible obfuscation in non-production.
- ✓
Irreversible masking
Why this is correct
Irreversible masking permanently replaces sensitive values so the original data cannot be reconstructed, satisfying the non-retrievable requirement. Reversible techniques such as tokenisation or encryption preserve recoverability, which would breach the privacy constraint in this non-production environment.
- ✗
Tokenization
Why it's wrong here
Tokenization substitutes a token for the value, but the vault mapping allows detokenisation, so data stays retrievable. It is correct where authorised systems must later recover the original value, not where irreversible obscuring is mandated.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.