200-201 Security Concepts Practice Question
A company processes credit card payments and must comply with a framework that mandates specific security controls for protecting cardholder data. Which compliance framework applies?
⚠ Common exam trap
200-201 often tests framework recognition — candidates confuse general security standards (ISO 27001) or privacy regulations (GDPR) with the cardholder-data-specific PCI DSS mandate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the framework specifically mandated for organizations that store, process, or transmit cardholder data. It defines 12 requirement categories covering network security, access control, encryption, monitoring, and policy. Any company processing credit card payments must comply with PCI DSS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ISO 27001
Why it's wrong here
ISO 27001 certifies an information security management system through risk-based control selection; it does not prescribe cardholder-data controls. It tempts as a recognised security standard. Card processing demands PCI DSS, which mandates specific requirements including protecting stored data and maintaining vulnerability management programmes.
- ✓
PCI DSS
Why this is correct
PCI DSS applies because the stem specifies credit card payments and cardholder data protection. It is the payment card industry standard that mandates controls such as encryption, access restriction and network monitoring for any entity storing, processing or transmitting cardholder data, directly satisfying the stated compliance requirement.
- ✗
GDPR
Why it's wrong here
GDPR protects personal data of EU residents and imposes breach notification and lawful-processing duties, not card-specific controls. It tempts because it also mandates security measures. Payment card handling requires PCI DSS, which prescribes concrete requirements such as encryption of stored cardholder data and network segmentation.
- ✗
HIPAA
Why it's wrong here
HIPAA governs protected health information held by healthcare providers and insurers, not payment card data. It tempts because both are US federal privacy regimes with mandated safeguards. Cardholder data demands PCI DSS, whose twelve requirements cover storage, transmission and access controls specific to card data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.