exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 301 discussion

Actual exam question from CompTIA's CAS-004
Question #: 301
Topic #: 1
[All CAS-004 Questions]

A company processes sensitive cardholder information that is stored in an internal production database and accessed by internet-facing web servers. The company's Chief Information Security Officer (CISO) is concerned with the risks related to sensitive data exposure and wants to implement tokenization of sensitive information at the record level. The company implements a one-to-many mapping of primary credit card numbers to temporary credit card numbers.

Which of the following should the CISO consider in a tokenization system?

  • A. Data field watermarking
  • B. Field tagging
  • C. Single-use translation
  • D. Salted hashing
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
arbats
4 weeks ago
Selected Answer: C
This directly supports the CISO's goal of implementing tokenization with a one-to-many mapping of sensitive data, ensuring each token is temporary and reduces the impact of token exposure.
upvoted 1 times
...
23169fd
6 months ago
Selected Answer: C
Single-use translation: In tokenization, single-use translation refers to the practice of creating a unique token for each instance of a credit card number. This ensures that even if tokens are intercepted or exposed, they cannot be reused to retrieve the original sensitive information. This approach enhances security by ensuring that tokens are unique and not predictable
upvoted 1 times
...
e020fdc
11 months ago
Selected Answer: C
Key word is "unique." When you tokenize the data, you need to conceal what the real numbers are, but the tokens need to be unique. If you and I both have our credit cards in the database and are assigned the same token, how is the vendor to know which one to process when I buy something? A. Data field watermarking - A Watermark for data synchronization describes an object of a predefined format which provides a point of reference value for two systems/datasets attempting to establish delta/incremental synchronization; any object in the queried data source which was created, modified, or deleted after the watermark's value will be qualified as "above watermark" and should be returned to the client requesting data. B. Field tagging - Defines a field that the user selects as input for an analytic script. OR Field tags provide the possibility of adding metadata to the fields in your data model.
upvoted 1 times
e020fdc
11 months ago
C. Single-use translation - Credit card tokenization is a security protocol that protects sensitive data during online transactions. It works by replacing a cardholder's Primary Account Number (PAN) with a unique, randomly generated identifier, referred to as a token. Hence, cardholder data is never exposed during the payment process. D. Salted hashing - A cryptographic salt is made up of random bits added to each password instance before its hashing.
upvoted 1 times
...
...
DWtriple0
11 months ago
"Single-use translation" appears to be an answer without a clear definition. A google search for this exact term yields only references to this exam question. Can anyone enlighten us?
upvoted 1 times
...
Alizadeh
1 year, 4 months ago
Selected Answer: C
The correct answer is C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago