312-50V12 · Question #281
Bill has been hired as a penetration tester and cyber security auditor for a major credit card company. Which information security standard is most applicable to his role?
The correct answer is D. PCI-DSS. This question asks to identify the most applicable information security standard for a penetration tester and cybersecurity auditor at a major credit card company. The correct answer is PCI-DSS, as it directly governs the protection of cardholder data.
Question
Options
- AFISMA
- BSarbanes-Oxley Act
- CHITECH
- DPCI-DSS
How the community answered
(39 responses)- A3% (1)
- B3% (1)
- C5% (2)
- D90% (35)
Why each option
This question asks to identify the most applicable information security standard for a penetration tester and cybersecurity auditor at a major credit card company. The correct answer is PCI-DSS, as it directly governs the protection of cardholder data.
FISMA (Federal Information Security Modernization Act) applies to US federal government agencies and their contractors, not a private credit card company.
The Sarbanes-Oxley Act (SOX) primarily focuses on financial reporting and corporate governance to prevent fraud for publicly traded companies, rather than being a specific information security standard for cardholder data.
HITECH (Health Information Technology for Economic and Clinical Health Act) is specific to the protection of Protected Health Information (PHI) in healthcare organizations, which is not applicable to a credit card company.
The Payment Card Industry Data Security Standard (PCI-DSS) is the definitive information security standard specifically designed to protect cardholder data for organizations that process, store, or transmit credit card information. For a major credit card company, adherence to PCI-DSS is mandatory, and penetration testing is a required control to ensure the security of cardholder data environments.
Concept tested: Information Security Standards Applicability
Source: https://www.pcisecuritystandards.org/pci_security/main
Topics
Community Discussion
No community discussion yet for this question.