Courseiva
easyMultiple Choice

CCSP Practice Question: A development team is working with…

A development team is working with production-like data in a non-production cloud environment. To comply with data privacy regulations, sensitive fields must be obscured without being retrievable. Which technique should they apply?

⚠ Common exam trap

ISC2 often tests the distinction between reversible and irreversible data protection methods, and the trap here is that candidates confuse 'masking' (which can be reversible or irreversible) with 'encryption' or 'tokenization,' assuming any transformation that hides data is sufficient, without recognizing the critical requirement of non-retrievability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Irreversible masking

Irreversible masking (C) is correct because it transforms sensitive data into a non-reversible format, ensuring that the original values cannot be retrieved. This meets the requirement of obscuring production-like data in a non-production environment while complying with data privacy regulations that prohibit reversible transformations. Unlike encryption or tokenization, irreversible masking does not provide any decryption or mapping mechanism, making it suitable for scenarios where data must be permanently de-identified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Format-preserving encryption

    Why it's wrong here

    Format-preserving encryption is reversible: the ciphertext decrypts back to the original value, so the sensitive fields remain retrievable and fail the obscuring requirement. It suits scenarios needing realistic-looking data that authorised systems must later decrypt, such as tokenising card numbers while preserving format for legacy schemas.

  • ✗

    Reversible masking

    Why it's wrong here

    Reversible masking can be unmasked by anyone holding the mapping or key, so the obscured values remain retrievable, breaching the requirement. It suits scenarios needing later re-identification, such as test-data correlation, not irreversible obfuscation in non-production.

  • ✓

    Irreversible masking

    Why this is correct

    Irreversible masking permanently replaces sensitive values so the original data cannot be reconstructed, satisfying the non-retrievable requirement. Reversible techniques such as tokenisation or encryption preserve recoverability, which would breach the privacy constraint in this non-production environment.

  • ✗

    Tokenization

    Why it's wrong here

    Tokenization substitutes a token for the value, but the vault mapping allows detokenisation, so data stays retrievable. It is correct where authorised systems must later recover the original value, not where irreversible obscuring is mandated.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.