nerdexam
EC-Council

712-50 · Question #32

When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?

The correct answer is C. What is the scope of the certification? PCI-DSS certification is only meaningful within its defined scope - the specific systems, networks, and processes that were actually assessed. Organizations routinely limit scope to a small cardholder data environment (CDE) while leaving the rest of their infrastructure…

Governance (Policy, Legal & Compliance)

Question

When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?

Options

  • AHow many credit card records are stored?
  • BHow many servers do you have?
  • CWhat is the scope of the certification?
  • DWhat is the value of the assets at risk?

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    16% (3)
  • C
    68% (13)
  • D
    5% (1)

Explanation

PCI-DSS certification is only meaningful within its defined scope - the specific systems, networks, and processes that were actually assessed. Organizations routinely limit scope to a small cardholder data environment (CDE) while leaving the rest of their infrastructure untouched, so asking "what is the scope?" immediately reveals whether the certification covers the systems you actually care about or just a narrow, isolated slice.

Options A and D (number of records and asset value) speak to risk magnitude, not security effectiveness - knowing how much is at stake tells you nothing about whether controls are actually working. Option B (number of servers) is similarly irrelevant; a thousand servers or five servers says nothing about whether any of them are properly secured or even within scope.

Memory tip: Think of PCI-DSS scope like a warranty - a car warranty that only covers the radio doesn't protect the engine. Always ask what's actually covered before trusting the certificate.

Topics

#PCI-DSS Compliance#Compliance Scope#Security Assessment#Certification Limitations

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice