About this interactive
Every card here is a value that was copied from a production database into a development database, shown before and after it was masked. The job is to work backwards from the change to the technique that made it. That is the situation the lesson builds its whole scenario around: developers need data that behaves like the real thing, the development environment is less secure than production, so the real values have to be hidden while the data stays useful. The six bins are the six ways the lesson names to do that, and the question that sorts most cards is simply: where did the new value come from?
Answer that question and the bins separate cleanly. If the new value came from a separate, prepared source of realistic fakes — a database of mock addresses, a list of fake names — it is substitution. If the tool generated it on the spot, like a new day, month and year for a birth date, it is randomization. If it came from somewhere else in the same table, it is shuffling. If it is a scrambled string that no longer looks like the original, it is encryption or hashing. If it is gone, or replaced by one dummy value that every record shares, it is null values. And if part of it is covered with asterisks, it is character masking.
Three of the traps sit on that first question. The fake name "Maria Ortiz" and the invented hire date are both perfectly realistic, so realism cannot be what separates substitution from randomization — the source does. A name picked from a list is substitution even though it feels random, and a date the tool made up is randomization even though it looks real. The shuffled phone number pulls the other way: Ben has a new number, which looks like substitution, but it is Ana's real number from the same table. Shuffling never invents anything, which is exactly why it is worth noticing that every shuffled value is still somebody's real data, now sitting in the less secure environment.
The other two traps are about what a masked value looks like. A hashed name such as "9f86d081…" reads as random noise, but randomization gives back a value of the same kind — a date that still looks like a date — while a hash stops resembling the original at all, which is the drawback the lesson points out. And the phone number replaced by 000-000-0000 on every record is not masking and not substitution: one identical dummy value across all the records is the null values technique, just as the lesson describes it. Keep the encryption cards next to the asterisk cards, too — both hide a card number, but only the encrypted one can be turned back into the real value, and that reversibility is why the lesson calls encryption a weaker way to protect data copied out of production.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →