Courseiva

200-201 Security Policies and Procedures Practice Question

A financial services firm must comply with regulations covering cardholder data. The security team is mapping its controls to the PCI DSS framework and wants to confirm that the framework's requirements are being met before an upcoming assessment. Which statement best describes what PCI DSS provides to the organization?

⚠ Common exam trap

Many exam-takers confuse a framework of control objectives with a prescriptive technical baseline, when PCI DSS deliberately states requirements while allowing each organization to choose how to implement them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A set of mandatory requirements and control objectives for organizations that store, process, or transmit cardholder data

PCI DSS is an industry-mandated framework of requirements and control objectives that applies to any organization handling cardholder data. It specifies outcomes, such as protecting stored data and encrypting transmission over open networks, but leaves specific technical implementation to the organization. It is enforced contractually through acquiring banks, not as advisory guidance or as government legislation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A set of mandatory requirements and control objectives for organizations that store, process, or transmit cardholder data

    Why this is correct

    PCI DSS is a mandatory framework of requirements and control objectives that applies to any entity storing, processing, or transmitting cardholder data. It defines what must be achieved, such as encrypting transmission of cardholder data over open networks, while leaving implementation choices to the organization. This matches the scenario's need to confirm compliance before an assessment.

  • ✗

    A voluntary advisory publication that suggests best practices but carries no compliance obligations for the merchant

    Why it's wrong here

    PCI DSS is not merely advisory; entities that handle cardholder data are contractually obligated through their acquiring bank relationships to comply. Non-compliance can result in fines, increased transaction fees, or loss of the ability to accept card payments. Describing it as voluntary would cause the firm to underinvest in controls and fail its upcoming assessment.

  • ✗

    A prescriptive technical configuration baseline that dictates exact settings for every operating system and application in the environment

    Why it's wrong here

    PCI DSS states control objectives and requirements, such as protecting stored cardholder data, but it does not prescribe exact operating system or application settings. Organizations select their own hardening baselines, for example from a vendor or a consensus benchmark, to satisfy those requirements. Claiming PCI DSS dictates every setting mischaracterizes the framework and would mislead the assessment scope.

  • ✗

    A legal statute enacted by a national government that replaces all contractual security obligations with statutory penalties

    Why it's wrong here

    PCI DSS is an industry framework developed by the payment card brands, enforced largely through contracts and acquirer agreements, not a government statute. While some jurisdictions reference it in law, it does not replace contractual obligations with statutory penalties. Treating it as legislation misstates its origin and the mechanism by which it is enforced against merchants.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.