EC-Council
512-50 · Question #291
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small…
The correct answer is A. Lack of compliance to the Payment Card Industry (PCI) standards. See the full explanation below for the reasoning.
Question
Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years. The organization has already been subject to a significant amount of credit card fraud. Which of the following is the MOST likely reason for this fraud?
Options
- ALack of compliance to the Payment Card Industry (PCI) standards
- BIneffective security awareness program
- CSecurity practices not in alignment with ISO 27000 frameworks
- DLack of technical controls when dealing with credit card data
How the community answered
(15 responses)- A80% (12)
- B7% (1)
- D13% (2)
Community Discussion
No community discussion yet for this question.