shieldCISSP Practice Domain 2 — Asset Security Q59 of 120

Which technique substitutes sensitive values with non-sensitive surrogates that map back via a separate vault?

A CISSP practice question covering Domain 2: Asset Security. Try answering before reading the explanation below.

Show options & answer
A
Hashing
B
Encryption
C
Tokenization
✓ Correct answer
D
Masking
Why "Tokenization" is the right answer

Tokenization replaces sensitive data with tokens that reference a vault. Hashing is one-way. Encryption is reversible with the key but the ciphertext still travels with the data. Masking partially obscures (e.g., showing only last 4 digits).

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →