Data Masking Explained: Obfuscation Techniques for the Security+ Exam
Data masking replaces sensitive values with realistic but false substitutes, so a system can be used without exposing the real data. The card number displays as •••• •••• •••• 4471; the test database contains plausible names that belong to nobody. The exam tests it against the neighbouring techniques, because they are easy to confuse and the differences matter. Static versus dynamic Static data masking permanently replaces values in a copy of the data. You extract production data, mask it, and load it into development or test. The real values never exist in that environment, so a breach of the test system exposes nothing. Use it for non-production environments, analytics datasets and anything shared with third parties. The key point is that it is irreversible in the copy — and that the copy is what people work with. Dynamic data masking leaves the stored data intact and masks it at query time based on who is asking. A support agent sees the last four digits; a fraud investigator...