Data masking

Replacing sensitive values with realistic but fictitious or partly hidden ones, either permanently in a copy (static masking) or as data is queried or displayed (dynamic masking).

Data masking substitutes plausible values, or obscures part of a value, so that people and systems that do not need the real data can still work with data of the right shape. Static masking transforms a copy, commonly a production database cloned for testing or training, so the copy no longer holds the originals. Dynamic masking leaves the stored data untouched and changes what is returned at query or display time, for example a support screen that shows only the last four digits of a card number.

Masking sits among several de-identification techniques that are easily confused. Tokenisation swaps a value for a token that the tokenisation system, usually a protected vault, can map back to the original, so it is reversible by design. Pseudonymisation replaces identifiers but leaves the data re-linkable using separately held information. Anonymisation aims to make re-identification no longer reasonably possible. Static masking is usually intended to be irreversible. Dynamic masking protects only the view, not the stored value, so it offers little against someone who can read the underlying database directly.

Exam relevance: a scenario is likely to describe developers or testers who need realistic data without real customer records, which points towards static masking. Candidates are expected to separate masking from tokenisation and encryption by asking whether the original can be recovered.