CAS-004 Governance, Risk, and Compliance Practice Question
A security architect is designing a new cloud-based system that must comply with the Payment Card Industry Data Security Standard (PCI DSS). The architect needs to ensure that cardholder data is protected both at rest and in transit. Which TWO of the following controls are required by PCI DSS to protect cardholder data in this scenario? (Choose two.)
⚠ Common exam trap
The trap here is selecting general PCI DSS requirements like WAF or vulnerability scans, which are important but not the specific controls for protecting cardholder data at rest and in transit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Render primary account numbers (PAN) unreadable anywhere they are stored.
PCI DSS explicitly requires encrypting cardholder data during transmission over open, public networks (Requirement 4) and rendering stored PAN unreadable (Requirement 3). These two controls directly protect data in transit and at rest. WAF, physical access, and vulnerability scans are important but do not specifically fulfill the data protection requirements for those states.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restrict physical access to cardholder data storage systems.
Why it's wrong here
Physical access controls are covered under PCI DSS Requirement 9, but they are not the specific controls for protecting data at rest or in transit. The scenario focuses on cryptographic protections for data states, not physical security. While important, physical access restriction does not directly render data unreadable or secure transmission.
- ✓
Render primary account numbers (PAN) unreadable anywhere they are stored.
Why this is correct
PCI DSS Requirement 3 requires that stored cardholder data be rendered unreadable through encryption, truncation, tokenization, or hashing. This addresses data at rest and is essential for protecting stored PAN. The architect must ensure that any storage of cardholder data complies with this requirement to reduce the risk of compromise.
- ✗
Conduct quarterly external and internal vulnerability scans.
Why it's wrong here
PCI DSS Requirement 11 mandates quarterly vulnerability scans, but these are for identifying vulnerabilities, not for directly protecting cardholder data at rest or in transit. The stem asks for controls that protect the data itself, so scanning is not the correct answer. It is a detection and assessment activity, not a data protection mechanism.
- ✗
Implement a web application firewall (WAF) in front of all public-facing web servers.
Why it's wrong here
While PCI DSS Requirement 6.6 requires either a WAF or code review for public-facing web applications, it is not specifically about protecting cardholder data at rest or in transit. The stem asks for controls to protect data in those states, so WAF is not the correct choice here. It addresses application-layer attacks, not data encryption.
- ✓
Encrypt transmission of cardholder data across open, public networks.
Why this is correct
PCI DSS Requirement 4 mandates strong cryptography and security protocols to safeguard cardholder data during transmission over open, public networks. This directly addresses the need to protect data in transit and is a core requirement for any system handling cardholder data. Implementing TLS or IPSec ensures confidentiality and integrity during transmission.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.