nerdexam
CompTIA

CS0-003 · Question #53

An organization has experienced a breach of customer transactions. Under the terms of PCI DSS, which of the following groups should the organization report the breach to?

The correct answer is D. Card issuer. Under the terms of PCI DSS, an organization that has experienced a breach of customer transactions should report the breach to the card issuer. The card issuer is the financial institution that issues the payment cards to the customers and that is responsible for authorizing…

Submitted by takeshi77· Mar 6, 2026Reporting and Communication

Question

An organization has experienced a breach of customer transactions. Under the terms of PCI DSS, which of the following groups should the organization report the breach to?

Options

  • APCI Security Standards Council
  • BLocal law enforcement
  • CFederal law enforcement
  • DCard issuer

How the community answered

(52 responses)
  • A
    2% (1)
  • C
    4% (2)
  • D
    94% (49)

Explanation

Under the terms of PCI DSS, an organization that has experienced a breach of customer transactions should report the breach to the card issuer. The card issuer is the financial institution that issues the payment cards to the customers and that is responsible for authorizing and processing the transactions. The card issuer may have specific reporting requirements and procedures for the organization to follow in the event of a breach. The organization should also notify other parties that may be affected by the breach, such as customers, law enforcement, or regulators, depending on the nature and scope of the breach.

Topics

#PCI DSS#data breach reporting#compliance

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice