QuestionQ24

Security Engineering

A company wants to modify its process to comply with privacy requirements after an incident involving PII data in a development environment. In order to perform functionality tests, the QA team still needs to use valid data in the specified format. Which of the following best addresses the risk without impacting the development life cycle?

Explanation

Tokenization (data masking/pseudonymization) replaces actual PII with format-preserving tokens that maintain field length, data type, and referential integrity. QA teams get realistic test data that exercises all code paths while removing exposure to actual personal information. Encryption leaves decryptable PII in the environment; truncation breaks data formats and test fidelity; synthetic LLM-generated data may not preserve cross-table consistency or business constraints.

Community Discussion

No comments yet. Be the first to start the discussion!