TechKnowSurge
CompTIA Security+ 1.4 CompTIA Security+ 3.3 NIST 800-53 PM-25 NIST 800-53 SI-19
InteractiveSecurityFree

Name That Mask

Work backwards from masked values to the technique that produced them: substitution, shuffling, randomization, encryption or hashing, null values, or character masking.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every card here is a value that was copied from a production database into a development database, shown before and after it was masked. The job is to work backwards from the change to the technique that made it. That is the situation the lesson builds its whole scenario around: developers need data that behaves like the real thing, the development environment is less secure than production, so the real values have to be hidden while the data stays useful. The six bins are the six ways the lesson names to do that, and the question that sorts most cards is simply: where did the new value come from? Answer that question and the bins separate cleanly. If the new value came from a separate, prepared source of realistic fakes — a database of mock addresses, a list of fake names — it is substitution. If the tool generated it on the spot, like a new day, month and year for a birth date, it is randomization. If it came from somewhere else in the same table, it is shuffling. If it is a scrambled string that no longer looks like the original, it is encryption or hashing. If it is gone, or replaced by one dummy value that every record shares, it is null values. And if part of it is covered with asterisks, it is character masking. Three of the traps sit on that first question. The fake name "Maria Ortiz" and the invented hire date are both perfectly realistic, so realism cannot be what separates substitution from randomization — the source does. A name picked from a list is substitution even though it feels random, and a date the tool made up is randomization even though it looks real. The shuffled phone number pulls the other way: Ben has a new number, which looks like substitution, but it is Ana's real number from the same table. Shuffling never invents anything, which is exactly why it is worth noticing that every shuffled value is still somebody's real data, now sitting in the less secure environment. The other two traps are about what a masked value looks like. A hashed name such as "9f86d081…" reads as random noise, but randomization gives back a value of the same kind — a date that still looks like a date — while a hash stops resembling the original at all, which is the drawback the lesson points out. And the phone number replaced by 000-000-0000 on every record is not masking and not substitution: one identical dummy value across all the records is the null values technique, just as the lesson describes it. Keep the encryption cards next to the asterisk cards, too — both hide a card number, but only the encrypted one can be turned back into the real value, and that reversibility is why the lesson calls encryption a weaker way to protect data copied out of production.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
3.3 Compare and contrast concepts and strategies to protect data.
NIST 800-53
PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
SI-19 De-Identification

Key terms

Data Masking
A method of protecting sensitive data by replacing it with realistic but fictitious data to prevent unauthorized access.
Shuffling
A data masking technique that rearranges existing data values across records so that values no longer correspond to the correct individual.
Randomization
A data masking technique that replaces real data values with randomly generated values to prevent identification.
Null Masking
A data masking technique that removes or replaces sensitive field values with null or dummy values so the data cannot be read or used.
Masking
A data obfuscation technique that hides portions of sensitive data, such as displaying only the last four digits of a credit card number.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key to prevent unauthorized access.
Hash Function
A mathematical algorithm that converts input data of any size into a fixed-size output value used to verify data integrity.
De-identification
The process of removing or obscuring personally identifiable information from a dataset so that individuals cannot be identified.
Personally Identifiable Information
PII
Personally Identifiable Information is any data that can be used alone or in combination to identify, contact, or locate an individual, requiring protection under privacy laws and organizational security policies.
Production
The live environment where software and services are actively running and accessed by real end users.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →