nerdexam
(ISC)2

CISSP · Question #1335

While classifying credit card data related to Payment Card Industry Data Security Standards (PCI-DSS), which of the following is a PRIMARY security requirement?

The correct answer is C. Encryption of data. PCI-DSS mandates encryption as a core requirement to protect cardholder data, making it the primary security control when classifying credit card data.

Submitted by alyssa_d· Mar 5, 2026Security and Risk Management

Question

While classifying credit card data related to Payment Card Industry Data Security Standards (PCI-DSS), which of the following is a PRIMARY security requirement?

Options

  • AProcessor agreements with card holders
  • BThree-year retention of data
  • CEncryption of data
  • DSpecific card disposal methodology

How the community answered

(40 responses)
  • A
    3% (1)
  • C
    95% (38)
  • D
    3% (1)

Why each option

PCI-DSS mandates encryption as a core requirement to protect cardholder data, making it the primary security control when classifying credit card data.

AProcessor agreements with card holders

Processor agreements with cardholders are a contractual or business relationship concern, not a primary PCI-DSS technical security requirement for protecting cardholder data.

BThree-year retention of data

PCI-DSS does not mandate a three-year data retention period; in fact, it encourages minimizing data retention and prohibits storing sensitive authentication data after authorization.

CEncryption of dataCorrect

PCI-DSS Requirement 3 explicitly mandates the protection of stored cardholder data through strong cryptography, and Requirement 4 requires encryption of cardholder data transmitted across open or public networks. Encryption is a foundational control ensuring that even if data is compromised, it remains unreadable and unusable to unauthorized parties, making it the primary security requirement for PCI-DSS compliance.

DSpecific card disposal methodology

While PCI-DSS does address secure disposal of media containing cardholder data (Requirement 9), specific card disposal methodology is a physical security sub-requirement, not the primary security requirement when classifying credit card data.

Concept tested: PCI-DSS primary security requirements for cardholder data

Source: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf

Topics

#PCI-DSS#Credit card data#Data encryption#Regulatory compliance

Community Discussion

No community discussion yet for this question.

Full CISSP Practice