hardMultiple ChoiceObjective-mapped
CCSP Practice Question: Is migrating a legacy application to the cloud…
An organization is migrating a legacy application to the cloud and must comply with PCI DSS. The application currently logs credit card numbers in plaintext. Which data security control should be implemented FIRST?
⚠ Common exam trap
ISC2 often tests the principle that security controls must be preceded by a discovery and classification phase, trapping candidates who jump to a technical solution like encryption or tokenization without first understanding the full scope of data exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform data discovery and classification
Before any remediation can be applied, the organization must first perform data discovery and classification to locate where all credit card numbers (PANs) are stored, including logs, databases, and backups. PCI DSS Requirement 3.1 mandates that cardholder data be identified and classified before implementing controls like tokenization or encryption. Without discovery, subsequent controls may miss critical data stores, leaving plaintext PANs exposed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement tokenization for credit card numbers
Why it's wrong here
Tokenization is a control but should follow discovery and classification.
- ✗
Deploy a data loss prevention (DLP) solution
Why it's wrong here
DLP is a detective control, not the first step.
- ✗
Encrypt the database at rest
Why it's wrong here
Encryption is a control but should follow classification.
- ✓
Perform data discovery and classification
Why this is correct
First step is to find and classify sensitive data to understand scope.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.