200-201 Security Policies and Procedures Practice Question
A financial institution must comply with PCI DSS requirements for handling cardholder data. A security administrator is asked to implement the control that directly addresses the requirement to protect stored cardholder data. Which technology should the administrator deploy to meet this specific PCI DSS requirement?
⚠ Common exam trap
Watch out — candidates often confuse general security controls that reduce scope or harden access with the specific PCI DSS requirement to render stored cardholder data unreadable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tokenization of the primary account number (PAN)
PCI DSS requires that stored cardholder data be rendered unreadable, and tokenization replaces the PAN with a non-sensitive surrogate, directly fulfilling that requirement. Other controls such as endpoint encryption, segmentation, and MFA are valuable but do not address the specific protection of stored cardholder data. Tokenization also reduces the scope of the cardholder data environment, which is a key compliance benefit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tokenization of the primary account number (PAN)
Why this is correct
PCI DSS Requirement 3 mandates protection of stored cardholder data. Tokenization replaces the PAN with a surrogate value, so the actual PAN is not stored in the cardholder data environment, directly satisfying the requirement. It reduces scope and is a recognized method for protecting stored cardholder data under PCI DSS.
- ✗
Full-disk encryption on all employee laptops
Why it's wrong here
Full-disk encryption protects data at rest on endpoints, but PCI DSS requires protecting stored cardholder data on systems that process or store it, such as databases and backups. Encrypting only employee laptops does not address the cardholder data environment where the data resides, so it fails to satisfy the specific requirement.
- ✗
Network segmentation between the DMZ and internal network
Why it's wrong here
Segmentation reduces the scope of the cardholder data environment and limits lateral movement, but it does not by itself protect stored cardholder data. The requirement specifically calls for rendering the PAN unreadable, which segmentation alone does not accomplish. It is a supporting control, not the direct control for stored data protection.
- ✗
Multifactor authentication for all administrative access
Why it's wrong here
Multifactor authentication addresses access control requirements, particularly for administrative and remote access, but it does not protect stored cardholder data. An attacker with valid credentials could still read the PAN if it is stored unencrypted. This control supports overall security but does not meet the specific PCI DSS requirement for protecting stored cardholder data.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.