Courseiva
hardMultiple ChoiceObjective-mapped

CCSP Practice Question: Is migrating a legacy application to the cloud…

An organization is migrating a legacy application to the cloud and must comply with PCI DSS. The application currently logs credit card numbers in plaintext. Which data security control should be implemented FIRST?

⚠ Common exam trap

ISC2 often tests the principle that security controls must be preceded by a discovery and classification phase, trapping candidates who jump to a technical solution like encryption or tokenization without first understanding the full scope of data exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform data discovery and classification

Before any remediation can be applied, the organization must first perform data discovery and classification to locate where all credit card numbers (PANs) are stored, including logs, databases, and backups. PCI DSS Requirement 3.1 mandates that cardholder data be identified and classified before implementing controls like tokenization or encryption. Without discovery, subsequent controls may miss critical data stores, leaving plaintext PANs exposed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement tokenization for credit card numbers

    Why it's wrong here

    Tokenization is a control but should follow discovery and classification.

  • Deploy a data loss prevention (DLP) solution

    Why it's wrong here

    DLP is a detective control, not the first step.

  • Encrypt the database at rest

    Why it's wrong here

    Encryption is a control but should follow classification.

  • Perform data discovery and classification

    Why this is correct

    First step is to find and classify sensitive data to understand scope.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.