Courseiva

200-201 Security Policies and Procedures Practice Question

A financial institution must comply with PCI DSS requirements for handling cardholder data. A security administrator is asked to implement the control that directly addresses the requirement to protect stored cardholder data. Which technology should the administrator deploy to meet this specific PCI DSS requirement?

⚠ Common exam trap

Watch out — candidates often confuse general security controls that reduce scope or harden access with the specific PCI DSS requirement to render stored cardholder data unreadable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tokenization of the primary account number (PAN)

PCI DSS requires that stored cardholder data be rendered unreadable, and tokenization replaces the PAN with a non-sensitive surrogate, directly fulfilling that requirement. Other controls such as endpoint encryption, segmentation, and MFA are valuable but do not address the specific protection of stored cardholder data. Tokenization also reduces the scope of the cardholder data environment, which is a key compliance benefit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tokenization of the primary account number (PAN)

    Why this is correct

    PCI DSS Requirement 3 mandates protection of stored cardholder data. Tokenization replaces the PAN with a surrogate value, so the actual PAN is not stored in the cardholder data environment, directly satisfying the requirement. It reduces scope and is a recognized method for protecting stored cardholder data under PCI DSS.

  • ✗

    Full-disk encryption on all employee laptops

    Why it's wrong here

    Full-disk encryption protects data at rest on endpoints, but PCI DSS requires protecting stored cardholder data on systems that process or store it, such as databases and backups. Encrypting only employee laptops does not address the cardholder data environment where the data resides, so it fails to satisfy the specific requirement.

  • ✗

    Network segmentation between the DMZ and internal network

    Why it's wrong here

    Segmentation reduces the scope of the cardholder data environment and limits lateral movement, but it does not by itself protect stored cardholder data. The requirement specifically calls for rendering the PAN unreadable, which segmentation alone does not accomplish. It is a supporting control, not the direct control for stored data protection.

  • ✗

    Multifactor authentication for all administrative access

    Why it's wrong here

    Multifactor authentication addresses access control requirements, particularly for administrative and remote access, but it does not protect stored cardholder data. An attacker with valid credentials could still read the PAN if it is stored unencrypted. This control supports overall security but does not meet the specific PCI DSS requirement for protecting stored cardholder data.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.