A company is looking for a solution to hide data stored in d - CompTIA CAS-005

Question

A company is looking for a solution to hide data stored in databases. The solution must meet the following requirements:

  • Be efficient at protecting the production environment
  • Not require any change to the application
  • Act at the presentation layer

Which of the following techniques should be used?

Answers
  1. correct
Explanation

The correct answer is A. Masking.

Data masking is a technique used to hide sensitive data while preserving the format and usability of the data for non-production environments. It is typically applied at the presentation layer, where the data is masked when it is presented to users or applications that do not need access to the actual sensitive data. This technique is non-intrusive and does not require changes to the application, as it can be applied directly to the database output or in middleware.

In this case, the requirements align well with data masking:

  • Efficient at protecting the production environment: Data masking is effective in protecting sensitive data in production environments without exposing it.
  • Does not require changes to the application: Masking can be applied without modifying the application itself.
  • Acts at the presentation layer: Data masking alters the data output at the presentation layer, so the actual data remains secure.

Why the other options are not correct:

  • Tokenization:

    • Tokenization replaces sensitive data with non-sensitive placeholders or tokens, which then map to the actual data in a secure database. While tokenization is a good solution for protecting sensitive data, it typically requires changes to the application and involves a more complex process of mapping and lookup for the tokenized values. This makes it less ideal if no changes to the application are allowed.
  • Algorithmic:

    • This term is unclear and not a standard data protection technique. If it refers to encryption or cryptography, such techniques generally require changes to the application and more complex management processes, which conflicts with the requirement of not requiring changes to the application. Also, cryptography operates at a different layer than the presentation layer.
  • Random substitution:

    • Random substitution is a data protection technique where actual data is substituted with random values. While this could be an option for protecting sensitive data, it is generally less efficient and practical in production environments where the data must maintain its structure and format. Additionally, it could lead to issues with the application using the data, making it less suitable when changes to the application are not allowed.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered