Which technique substitutes sensitive values with non-sensitive surrogates that map back via a separate vault?
A CISSP practice question covering Domain 2: Asset Security. Try answering before reading the explanation below.
Show options & answer
Why "Tokenization" is the right answer
Tokenization replaces sensitive data with tokens that reference a vault. Hashing is one-way. Encryption is reversible with the key but the ciphertext still travels with the data. Masking partially obscures (e.g., showing only last 4 digits).
Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.