nerdexam
EC-Council

312-50V9 · Question #173

Which of the following guidelines or standards is associated with the credit card industry?

The correct answer is D. Payment Card Industry Data Security Standards (PCI DSS). PCI DSS is the security standard specifically created by the payment card industry to protect cardholder data across all entities that store, process, or transmit credit card information.

Introduction to Ethical Hacking

Question

Which of the following guidelines or standards is associated with the credit card industry?

Options

  • AControl Objectives for Information and Related Technology (COBIT)
  • BSarbanes-Oxley Act (SOX)
  • CHealth Insurance Portability and Accountability Act (HIPAA)
  • DPayment Card Industry Data Security Standards (PCI DSS)

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    7% (3)
  • D
    89% (41)

Why each option

PCI DSS is the security standard specifically created by the payment card industry to protect cardholder data across all entities that store, process, or transmit credit card information.

AControl Objectives for Information and Related Technology (COBIT)

COBIT is an IT governance and management framework developed by ISACA that applies broadly across industries and is not specific to payment card security.

BSarbanes-Oxley Act (SOX)

SOX is a U.S. federal law focused on financial reporting accuracy and corporate governance for publicly traded companies, with no specific payment card data requirements.

CHealth Insurance Portability and Accountability Act (HIPAA)

HIPAA is a U.S. federal law that governs the privacy and security of protected health information in the healthcare industry, not payment card data.

DPayment Card Industry Data Security Standards (PCI DSS)Correct

PCI DSS was developed by the Payment Card Industry Security Standards Council - founded by major card brands including Visa, Mastercard, and American Express - to establish a baseline of security controls for protecting cardholder data. It applies to any organization that stores, processes, or transmits payment card data, making it the only option directly tied to the credit card industry. Compliance is enforced contractually by card brands and acquiring banks.

Concept tested: PCI DSS applicability to payment card industry

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#credit card security#industry standards#regulatory compliance

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice