nerdexam
EC-Council

512-50 · Question #291

Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small…

The correct answer is A. Lack of compliance to the Payment Card Industry (PCI) standards. See the full explanation below for the reasoning.

Question

Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years. The organization has already been subject to a significant amount of credit card fraud. Which of the following is the MOST likely reason for this fraud?

Options

  • ALack of compliance to the Payment Card Industry (PCI) standards
  • BIneffective security awareness program
  • CSecurity practices not in alignment with ISO 27000 frameworks
  • DLack of technical controls when dealing with credit card data

How the community answered

(15 responses)
  • A
    80% (12)
  • B
    7% (1)
  • D
    13% (2)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice