Courseiva

CRISC Information Technology and Security Practice Question

A global retailer is migrating its point-of-sale (POS) transaction processing to a public cloud provider. The risk practitioner must ensure that the organization's payment card data remains compliant with PCI DSS. Which of the following is the MOST appropriate control to implement FIRST?

⚠ Common exam trap

The trap here is assuming that encryption or a WAF is always the first control, when in fact you cannot protect data you have not yet located and classified.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a data discovery and classification exercise to identify all cardholder data locations.

The first step in any cloud migration involving cardholder data is to discover and classify that data to define the PCI DSS scope. Without knowing where the data resides, the organization cannot accurately apply encryption, firewalls, or contractual controls. Data discovery ensures that all subsequent risk treatments are targeted and complete, forming the foundation for compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a web application firewall (WAF) in front of the cloud-based POS application.

    Why it's wrong here

    A WAF helps protect web applications from attacks, but it does not address the fundamental need to understand where cardholder data resides. Deploying a WAF without first scoping the data environment could leave unmonitored data stores exposed and fail to satisfy PCI DSS requirements for data discovery and segmentation.

  • ✗

    Require the cloud provider to sign a PCI DSS attestation of compliance (AOC).

    Why it's wrong here

    A cloud provider's AOC is important for shared responsibility, but it does not replace the organization's own obligation to identify and protect its cardholder data. The retailer remains accountable for determining where its data is stored and processed; relying solely on the provider's attestation would create a dangerous compliance gap.

  • ✗

    Encrypt all cardholder data at rest and in transit using strong cryptography.

    Why it's wrong here

    Encryption is a crucial PCI DSS requirement, but it is not the first control to implement. Without knowing where cardholder data resides and how it flows in the cloud, encryption may be applied to the wrong assets or miss critical data stores. The initial step must be to establish data visibility and scope, which underpins all subsequent controls.

  • ✓

    Conduct a data discovery and classification exercise to identify all cardholder data locations.

    Why this is correct

    Before any controls can be effectively applied, the organization must know where cardholder data is stored, processed, and transmitted in the cloud environment. Data discovery and classification define the scope of PCI DSS compliance and ensure that subsequent controls are applied to the correct assets, preventing gaps or unnecessary effort.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.