nerdexam
EC-Council

512-50 · Question #402

When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?

The correct answer is C. What is the scope of the certification? See the full explanation below for the reasoning.

Question

When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?

Options

  • AHow many credit card records are stored?
  • BHow many servers do you have?
  • CWhat is the scope of the certification?
  • DWhat is the value of the assets at risk?

How the community answered

(31 responses)
  • A
    13% (4)
  • B
    6% (2)
  • C
    77% (24)
  • D
    3% (1)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice