easyMultiple ChoiceObjective-mapped
CRISC Practice Question: A retail company is planning to launch a mobile…
A retail company is planning to launch a mobile payment app. The risk team is identifying potential risks related to payment card industry (PCI) compliance. The app will process credit card numbers. The development team has implemented tokenization to replace card numbers with tokens, but the token vault is located on-premises. The network architect proposes exposing the token vault to the internet for mobile app access. The compliance officer is concerned about PCI DSS requirements. The risk manager needs to identify the highest risk related to this setup. What is the primary risk?
⚠ Common exam trap
The trap here is that candidates may focus on operational risks like latency or cost, but the CRISC exam emphasizes that PCI DSS compliance and data breach exposure are the highest risks when cardholder data or its mapping is exposed to the internet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exposure of the token vault to the internet may violate PCI DSS requirements and lead to a data breach.
The primary risk is that exposing the token vault to the internet directly violates PCI DSS Requirement 3.4, which mandates that stored cardholder data must be rendered unreadable. While tokenization replaces PANs with tokens, the vault itself contains the sensitive PAN-to-token mapping. Internet exposure of this vault creates an attack surface for unauthorized access, potentially leading to a massive data breach and non-compliance penalties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Potential loss of tokens due to hardware failure.
Why it's wrong here
Hardware failure is a minor risk compared to security exposure.
- ✓
Exposure of the token vault to the internet may violate PCI DSS requirements and lead to a data breach.
Why this is correct
Direct exposure to internet is a major security and compliance risk.
- ✗
Increased latency due to tokenization.
Why it's wrong here
Latency is a performance issue, not a security risk.
- ✗
High cost of tokenization infrastructure.
Why it's wrong here
Cost is a financial concern, not the primary risk.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.