Courseiva
Cloud Data Security →mediumMultiple Choice

CCSP Cloud Data Security Practice Question

A security team is setting up a DLP solution to scan cloud storage for credit card numbers. They want to automatically mask the detected credit card numbers so that only the last four digits are visible. Which DLP de-identification transform should they use?

⚠ Common exam trap

CCSP often tests the distinction between reversible de-identification (tokenization, pseudonymization) and irreversible display-oriented transforms (masking) — candidates pick tokenization because it sounds more secure when the question specifically asks for partial visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Masking

Masking replaces sensitive values with a redacted or partially obscured version — for credit card numbers, showing only the last four digits (e.g., **** **** **** 1234) while hiding the rest. It is a de-identification transform that preserves format and usability for display/analytics without exposing the full PAN. This matches the requirement exactly: detect and automatically mask so only the last four digits remain visible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pseudonymization

    Why it's wrong here

    Pseudonymization substitutes a consistent alias for the whole value, leaving no original digits exposed, so the last four cannot be shown. It is tempting because it preserves linkability across records, but that scenario requires reversible mapping, not partial masking that reveals a trailing portion.

  • ✗

    Bucketing

    Why it's wrong here

    Bucketing groups values into ranges or categories, so it cannot preserve the last four digits of a credit card number while masking the rest. It is tempting because bucketing is a recognised de-identification transform, and would be correct where numerical values need generalising into bands for statistical analysis.

  • ✗

    Tokenization

    Why it's wrong here

    Tokenization replaces the entire value with a surrogate token, so no digits remain visible; partial masking of the last four digits is not its output. It is tempting because it protects card data, but it suits retaining referential integrity across systems rather than displaying a truncated number.

  • ✓

    Masking

    Why this is correct

    Masking replaces characters within the detected credit card number, exposing only the final four digits while obscuring the rest. This directly satisfies the requirement that only the last four digits remain visible, unlike tokenization, which substitutes the entire value with an unrelated surrogate.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.