CAS-004 Governance, Risk, and Compliance Practice Question
A software company is preparing to release a new payment feature that processes cardholder data. The security architect must ensure the feature design meets PCI DSS requirements for protecting stored data and for securing transmission over open, public networks. Which two design choices satisfy these requirements? (Choose two.)
⚠ Common exam trap
The trap here is assuming that a payment processor's PCI DSS certificate removes the need to encrypt cardholder data that the organization itself transmits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable TLS 1.2 or higher with strong cipher suites for all payment traffic traversing the internet
The two correct design choices are tokenization with a hardened token vault and strong TLS for data in transit. Tokenization reduces the value of stored data and can shrink the cardholder data environment, while TLS 1.2 or higher with strong ciphers protects data moving across open, public networks. Together they address both the storage and transmission requirements in the scenario without relying on a third party's compliance to cover the organization's own obligations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable audit logging for the payment feature to reduce storage of sensitive data
Why it's wrong here
PCI DSS requires audit trails to be maintained and protected to support detection, investigation, and forensic analysis. Disabling logging to reduce sensitive data storage removes critical accountability and would violate logging and monitoring requirements. Storage reduction should be achieved through data minimization techniques such as truncation or tokenization, not by eliminating the audit trail that proves access to cardholder data is tracked and reviewable.
- ✓
Enable TLS 1.2 or higher with strong cipher suites for all payment traffic traversing the internet
Why this is correct
PCI DSS requires strong cryptography and security protocols to safeguard cardholder data during transmission over open, public networks. TLS 1.2 or higher with strong cipher suites and proper certificate validation satisfies that requirement. This directly addresses the scenario's transmission concern and is a standard, auditable control for protecting data in transit between the customer browser, application, and payment processor.
- ✓
Replace the primary account number with a token in the application database and map it in a separate hardened token vault
Why this is correct
Tokenization replaces the primary account number with a surrogate value that has no exploitable value if the database is compromised, and it can significantly reduce the scope of the cardholder data environment. Keeping the mapping in a separate hardened vault with strict access controls aligns with PCI DSS objectives for rendering stored data unreadable and limiting access to cardholder data to those with a business need.
- ✗
Store the full primary account number encrypted with a documented key management process
Why it's wrong here
PCI DSS requires that the primary account number be rendered unreadable anywhere it is stored, and encryption with strong key management is one accepted method. However, storing the full number still expands the cardholder data environment and requires strict access controls and key custodianship. If the business does not need the full number, truncation or tokenization reduces risk and scope more effectively, so this choice is not the strongest design for the stated goal.
- ✗
Rely on the payment processor's PCI DSS compliance certificate and transmit card data without additional encryption
Why it's wrong here
A service provider's compliance does not transfer the merchant's or software company's own PCI DSS obligations. Cardholder data transmitted over open, public networks must still be protected with strong cryptography regardless of who processes it. Relying solely on a certificate and sending data in the clear would fail the transmission protection requirement and expose the data to interception, so this design is not acceptable.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.