TechKnowSurge
CompTIA Security+ 3.3 ISC2 CC 5.1 CompTIA Tech+ 6.1 NIST CSF PR.DS-01 NIST 800-53 SC-28
InteractiveSecurityFree

Pick the Protection

Match each situation to the confidentiality protection that fits it: access control, encryption, data masking, steganography, or deletion.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every card in this sort describes a piece of data that needs protecting, and the Confidentiality lesson gives three broad ways to do it: get rid of the data, lock it behind a gate so only the right people reach it, or hide it so that reaching it is not enough. The five bins are those three ideas made concrete. Access control is the gate — permissions, separate network segments, geographic restrictions, the AAA service deciding who gets in. Encryption, data masking and steganography are three different ways of hiding. Deletion is getting rid of it. The skill being practiced is reading a situation and asking what the actual problem is, because the situation, not how sensitive the data feels, decides the protection. The first trap is the line between access control and encryption, and it runs in both directions. Access control answers who can reach the data; encryption answers what someone sees once they have reached it anyway. A laptop left in a taxi, a backup tape on a delivery truck and card numbers crossing the internet are all situations where the data has already left your gate, so only encryption still helps. The interns with access to trade-secret designs are the reverse, and the value of the designs pulls people toward encryption. But the interns sign in through the ordinary system, so an encrypted folder would simply open for them. What is wrong is that they are allowed in, and the protection is taking that permission away. The second trap is deletion. It rarely feels like a security control, because deleting data sounds like giving something up. The lesson makes the opposite case: data you no longer hold cannot leak, and records kept long after their purpose has passed are a liability, not an asset. Ten-year-old records for former customers, contest entries from years ago and a security question nobody uses all belong in the Deletion bin, even though encryption would feel like the responsible choice. Compare them with the sales team's purchase history, which is also customer data but is used every week. Data that is still earning its value is kept and controlled, not deleted, and that asset-versus-liability judgment is the conversation the lesson says security teams and the rest of the business need to have. The third trap is masking versus encryption. Both hide the real values, but encrypted data is useless until someone decrypts it, while masked data stays usable because the real values have been swapped for stand-ins. Developers testing an application and an analytics firm studying patterns need data they can work with, not data they can't read. Steganography is the odd one out: it hides that a message exists at all, inside something that looks ordinary, rather than scrambling what the message says. The lesson also lists obfuscation, making data confusing or unintelligible, as a way to hide data. It has no bin here because at this level it overlaps with masking and encryption, and the module gives it a lesson of its own.

What you'll learn

Aligned to

CompTIA Security+
3.3 Compare and contrast concepts and strategies to protect data.
ISC2 CC
5.1 Understand data security
CompTIA Tech+
6.1 Summarize confidentiality, integrity, and availability concerns.
NIST CSF
PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected.
NIST 800-53
SC-28 Protection of Information at Rest

Key terms

Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key to prevent unauthorized access.
Data Masking
A method of protecting sensitive data by replacing it with realistic but fictitious data to prevent unauthorized access.
Steganography
The practice of concealing a message within another medium, such as an image or sentence, so its existence is hidden rather than its content scrambled.
Data Minimization
The practice of collecting and retaining only the sensitive data necessary for legitimate business purposes, reducing exposure and liability.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Authentication, Authorization, and Accounting
AAA
Authentication, Authorization, and Accounting is a security framework that controls network access by verifying user identity, determining permitted actions, and logging activity for auditing and billing purposes.
Sensitive Data
Information that must be protected from unauthorized access due to its private, confidential, or regulated nature, such as customer records or proprietary business plans.

Topics

Confidentiality Access Control Encryption Data Masking Steganography Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →