nerdexam
EC-Council

312-50V12 · Question #281

Bill has been hired as a penetration tester and cyber security auditor for a major credit card company. Which information security standard is most applicable to his role?

The correct answer is D. PCI-DSS. This question asks to identify the most applicable information security standard for a penetration tester and cybersecurity auditor at a major credit card company. The correct answer is PCI-DSS, as it directly governs the protection of cardholder data.

Submitted by weili_xi· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

Bill has been hired as a penetration tester and cyber security auditor for a major credit card company. Which information security standard is most applicable to his role?

Options

  • AFISMA
  • BSarbanes-Oxley Act
  • CHITECH
  • DPCI-DSS

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    5% (2)
  • D
    90% (35)

Why each option

This question asks to identify the most applicable information security standard for a penetration tester and cybersecurity auditor at a major credit card company. The correct answer is PCI-DSS, as it directly governs the protection of cardholder data.

AFISMA

FISMA (Federal Information Security Modernization Act) applies to US federal government agencies and their contractors, not a private credit card company.

BSarbanes-Oxley Act

The Sarbanes-Oxley Act (SOX) primarily focuses on financial reporting and corporate governance to prevent fraud for publicly traded companies, rather than being a specific information security standard for cardholder data.

CHITECH

HITECH (Health Information Technology for Economic and Clinical Health Act) is specific to the protection of Protected Health Information (PHI) in healthcare organizations, which is not applicable to a credit card company.

DPCI-DSSCorrect

The Payment Card Industry Data Security Standard (PCI-DSS) is the definitive information security standard specifically designed to protect cardholder data for organizations that process, store, or transmit credit card information. For a major credit card company, adherence to PCI-DSS is mandatory, and penetration testing is a required control to ensure the security of cardholder data environments.

Concept tested: Information Security Standards Applicability

Source: https://www.pcisecuritystandards.org/pci_security/main

Topics

#PCI-DSS#compliance standards#payment card security

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice