nerdexam
EC-Council

712-50 · Question #264

Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small…

The correct answer is A. Lack of compliance to the Payment Card Industry (PCI) standards. PCI DSS (Payment Card Industry Data Security Standard) is the mandatory compliance framework specifically designed to protect cardholder data, and failure to comply with it is the primary driver of credit card fraud in retail environments - making A the most direct and specific…

Governance (Policy, Legal & Compliance)

Question

Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years. The organization has already been subject to a significant amount of credit card fraud. Which of the following is the MOST likely reason for this fraud?

Options

  • ALack of compliance to the Payment Card Industry (PCI) standards
  • BIneffective security awareness program
  • CSecurity practices not in alignment with ISO 27000 frameworks
  • DLack of technical controls when dealing with credit card data

How the community answered

(16 responses)
  • A
    75% (12)
  • B
    6% (1)
  • C
    13% (2)
  • D
    6% (1)

Explanation

PCI DSS (Payment Card Industry Data Security Standard) is the mandatory compliance framework specifically designed to protect cardholder data, and failure to comply with it is the primary driver of credit card fraud in retail environments - making A the most direct and specific answer for a merchant already experiencing fraud. Option B (security awareness) is a contributing factor but not the root cause; employees can be aware of threats yet still lack the technical safeguards PCI requires. Option C (ISO 27000) is a general information security management framework - it's not payment-specific, so misalignment with it wouldn't directly explain credit card fraud. Option D (lack of technical controls) is actually a consequence of PCI non-compliance rather than a separate root cause - PCI DSS mandates specific technical controls, so choosing D misidentifies the symptom as the cause.

Memory tip: Think "PCI = Payment Cards Internationally protected." Whenever a question involves credit card fraud at a merchant, PCI DSS is almost always the right framework - it's the only standard built exclusively for cardholder data protection.

Topics

#PCI DSS compliance#payment card security#compliance standards#credit card fraud

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice