350-201(NEW-127Q) · Question #20
The organization that provides payment processing services is working on contracts with multiple banks. The organization has four branches with public and internal networks and two data centers…
The correct answer is A. Encrypt cardholder data using industry-accepted algorithms (truncated, tokenized, or hashed). B. Restrict physical access to cardholder data, use surveillance or electronic access controls to monitor entry and exit points of physical locations. A and B are correct because they directly address PCI DSS requirements for protecting cardholder data: encrypting stored data using approved methods (Requirement 3) and securing physical access to cardholder data environments with surveillance and access controls (Requirement…
Question
Options
- AEncrypt cardholder data using industry-accepted algorithms (truncated, tokenized, or hashed).
- BRestrict physical access to cardholder data, use surveillance or electronic access controls to monitor entry and exit points of physical locations.
- CStore the magnetic strips and chip-sensitive data for auditing purposes and document the storage locations with strict access control and executive approvals.
- DDocument the process model used for data protection and implement a common approach for everyone in an organization.
- EAssign responsibilities, agree on objectives with executive management to measure performance, and draw interrelationships with other processes.
How the community answered
(31 responses)- A77% (24)
- C3% (1)
- D6% (2)
- E13% (4)
Explanation
A and B are correct because they directly address PCI DSS requirements for protecting cardholder data: encrypting stored data using approved methods (Requirement 3) and securing physical access to cardholder data environments with surveillance and access controls (Requirement 9) are foundational CISO-level controls in any payment processing organization.
C is wrong - and critically dangerous to choose. PCI DSS explicitly prohibits storing sensitive authentication data (magnetic stripe or chip data) after authorization, even for auditing. Recommending this storage would be a direct compliance violation, not a safeguard.
D is wrong because documenting a process model is a procedural/governance activity, not a targeted data security recommendation. It is too abstract to qualify as one of the two priority actions a CISO must take to protect sensitive data.
E is wrong because assigning responsibilities and setting executive objectives describes IT governance frameworks (like COBIT) rather than specific PCI DSS data protection controls - it belongs in a governance charter, not a data security recommendation.
Memory tip: Think "Protect the Data, Protect the Door" - A = digital protection (encrypt/tokenize/hash), B = physical protection (locks, cameras, access logs). A CISO's first two moves are always technical controls and physical controls, not policies or org charts.
Topics
Community Discussion
No community discussion yet for this question.