nerdexam
EC-Council

312-50V13 · Question #390

Bill has been hired as a penetration tester and cyber security auditor for a major credit card company. Which information security standard is most applicable to his role?

The correct answer is C. PCI-DSS. For a penetration tester and auditor at a credit card company, the Payment Card Industry Data Security Standard (PCI-DSS) is the most relevant information security standard as it governs the protection of cardholder data.

Submitted by miguelv· Mar 6, 2026Introduction to Ethical Hacking

Question

Bill has been hired as a penetration tester and cyber security auditor for a major credit card company. Which information security standard is most applicable to his role?

Options

  • AFISMA
  • BHITECH
  • CPCI-DSS
  • DSarbanes-OxleyAct

How the community answered

(18 responses)
  • B
    6% (1)
  • C
    89% (16)
  • D
    6% (1)

Why each option

For a penetration tester and auditor at a credit card company, the Payment Card Industry Data Security Standard (PCI-DSS) is the most relevant information security standard as it governs the protection of cardholder data.

AFISMA

FISMA (Federal Information Security Modernization Act) is a US law that requires federal agencies to develop, document, and implement information security programs.

BHITECH

HITECH (Health Information Technology for Economic and Clinical Health Act) is a US law that promotes the adoption and meaningful use of health information technology, primarily dealing with patient health information.

CPCI-DSSCorrect

PCI-DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. A penetration tester for a credit card company would specifically audit compliance with these regulations.

DSarbanes-OxleyAct

The Sarbanes-Oxley Act (SOX) is a US federal law that mandates certain practices in financial record keeping and reporting for public companies, focusing on financial integrity, not specifically credit card data security.

Concept tested: Compliance standards (PCI-DSS)

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#compliance#information security standards#penetration testing

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice