CCSP Cloud Data Security Practice Question
A security team is setting up a DLP solution to scan cloud storage for credit card numbers. They want to automatically mask the detected credit card numbers so that only the last four digits are visible. Which DLP de-identification transform should they use?
⚠ Common exam trap
CCSP often tests the distinction between reversible de-identification (tokenization, pseudonymization) and irreversible display-oriented transforms (masking) — candidates pick tokenization because it sounds more secure when the question specifically asks for partial visibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Masking
Masking replaces sensitive values with a redacted or partially obscured version — for credit card numbers, showing only the last four digits (e.g., **** **** **** 1234) while hiding the rest. It is a de-identification transform that preserves format and usability for display/analytics without exposing the full PAN. This matches the requirement exactly: detect and automatically mask so only the last four digits remain visible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pseudonymization
Why it's wrong here
Pseudonymization substitutes a consistent alias for the whole value, leaving no original digits exposed, so the last four cannot be shown. It is tempting because it preserves linkability across records, but that scenario requires reversible mapping, not partial masking that reveals a trailing portion.
- ✗
Bucketing
Why it's wrong here
Bucketing groups values into ranges or categories, so it cannot preserve the last four digits of a credit card number while masking the rest. It is tempting because bucketing is a recognised de-identification transform, and would be correct where numerical values need generalising into bands for statistical analysis.
- ✗
Tokenization
Why it's wrong here
Tokenization replaces the entire value with a surrogate token, so no digits remain visible; partial masking of the last four digits is not its output. It is tempting because it protects card data, but it suits retaining referential integrity across systems rather than displaying a truncated number.
- ✓
Masking
Why this is correct
Masking replaces characters within the detected credit card number, exposing only the final four digits while obscuring the rest. This directly satisfies the requirement that only the last four digits remain visible, unlike tokenization, which substitutes the entire value with an unrelated surrogate.
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.