CRISC Information Technology and Security Practice Question
A retail organization is migrating its point-of-sale (POS) processing to a cloud-hosted payment platform. The risk practitioner must select an encryption approach that protects cardholder data while it is actively being processed in memory by the payment application. Which of the following is the MOST appropriate control for this scenario?
⚠ Common exam trap
The trap here is assuming that any strong encryption control, such as TLS or database encryption, automatically covers data in every state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement confidential computing using hardware-based trusted execution environments (TEEs) for the payment workload.
Cardholder data exists in three states, and each requires a different control: in transit, at rest, and in use. The scenario specifies active in-memory processing, which only confidential computing with hardware trusted execution environments addresses, because the enclave keeps memory encrypted and isolated from privileged software. Transport encryption and at-rest encryption leave the processing window exposed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement confidential computing using hardware-based trusted execution environments (TEEs) for the payment workload.
Why this is correct
Confidential computing isolates the payment workload inside a hardware-backed trusted execution environment so that memory contents remain encrypted and inaccessible to the hypervisor, host OS, or cloud operator even while the application actively processes them. This directly satisfies the requirement to protect cardholder data in use, which transport and at-rest encryption cannot achieve.
- ✗
Encrypt the payment database tablespaces using transparent data encryption (TDE).
Why it's wrong here
Transparent data encryption protects cardholder data at rest on storage media, guarding against file-level or backup theft. It does nothing for data that has already been decrypted and loaded into the application's process memory. Because the question targets data in use, at-rest encryption is the wrong layer of protection.
- ✗
Enable TLS 1.3 for all connections between the POS terminals and the cloud payment platform.
Why it's wrong here
TLS 1.3 secures data in transit between endpoints, but once the payload is decrypted inside the cloud payment application, the cardholder data sits unprotected in memory. The scenario explicitly requires protection during active processing, so a transport-layer control does not address the exposure that matters here.
- ✗
Store all cardholder data in a tokenized vault and replace PANs with surrogate values in the payment application.
Why it's wrong here
Tokenization reduces the value of stolen data by replacing the primary account number with a surrogate, but the application still processes the token and any associated sensitive fields in cleartext memory. It shrinks the compliance scope rather than protecting data during processing, so it does not meet the stated requirement.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.