Courseiva
mediumMultiple Choice

CISA Practice Question: An e-commerce company stores customer payment…

An e-commerce company stores customer payment card data in a tokenized database. The tokenization system replaces credit card numbers with tokens, and the actual card numbers are stored in a separate, highly restricted vault. The company is audited for Payment Card Industry Data Security Standard (PCI DSS) compliance. During the audit, it is discovered that the tokenization system sometimes fails due to high load, causing the application to fall back to storing actual card numbers temporarily. This fallback mechanism was not documented or approved. The company also uses the same encryption key for the vault as for other non-sensitive data. The auditor identifies several non-compliances. Which of the following should the company prioritize to remediate?

⚠ Common exam trap

CISA often tests prioritization: candidates pick the technically interesting fix (separate encryption key) instead of the one that stops the actual data exposure (removing the fallback), confusing 'hardening' with 'root-cause remediation'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove the fallback mechanism and ensure the tokenization system has appropriate redundancy

The fallback mechanism that stores actual card numbers in cleartext (or in the tokenized DB) when tokenization fails is the most severe non-compliance because it defeats the entire purpose of tokenization and exposes PANs outside the restricted vault. Removing that fallback and adding redundancy to the tokenization system so it does not fail under load directly addresses the root cause of the data exposure. This is the priority remediation because it eliminates the uncontrolled storage of cardholder data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace the tokenization system with end-to-end encryption

    Why it's wrong here

    End-to-end encryption still leaves the fallback writing live card numbers into the application database, so the unauthorised storage of PANs persists. It is tempting because encryption protects data at rest, but it would be correct only where cardholder data must be rendered unreadable, not where it should never be retained.

  • ✓

    Remove the fallback mechanism and ensure the tokenization system has appropriate redundancy

    Why this is correct

    The undocumented fallback writes live card numbers to disk under load, defeating tokenisation entirely and breaching PCI DSS storage requirements. Removing it and adding redundancy so tokenisation survives peak load eliminates the root cause; key separation and documentation are secondary fixes.

  • ✗

    Use a separate encryption key for the vault

    Why it's wrong here

    A separate vault key addresses key segregation but leaves the fallback mechanism storing live card numbers in the application database, the more serious exposure. It is tempting because PCI DSS requires distinct keys per data environment, and it would be correct once the fallback itself has been removed.

  • ✗

    Increase the capacity of the tokenization server to handle peak loads

    Why it's wrong here

    Adding capacity reduces how often the tokenisation service fails, but the undocumented fallback that writes real card numbers remains in the code and can still trigger. It is tempting because load caused the failures, yet the correct remediation is removing the fallback rather than scaling the tokenisation tier.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.