mediumMultiple Choice
CISSP Developing a mobile payment application Practice Question
A company is developing a mobile payment application. To comply with PCI DSS, what should be implemented to protect cardholder data during transmission?
⚠ Common exam trap
A common mix-up: candidates confuse encoding (base64) with encryption, or assume that any SSL/TLS version is acceptable, but PCI DSS specifically requires TLS 1.2 or higher and prohibits deprecated protocols like SSL 3.0 and weak ciphers like RC4.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement TLS 1.2 or higher with strong ciphers.
TLS 1.2 or higher with strong ciphers is the correct choice because PCI DSS Requirement 4 mandates that cardholder data must be encrypted using strong cryptography (e.g., TLS 1.2/1.3) during transmission over open, public networks. TLS provides mutual authentication, data integrity, and confidentiality through a handshake that negotiates a session key, protecting against eavesdropping and tampering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply base64 encoding.
Why it's wrong here
Base64 is a reversible encoding, not encryption, so cardholder data remains readable in transit and fails PCI DSS encryption requirements. It is tempting because it obscures data visually and is commonly used to embed binary content in text protocols, but it would only be appropriate for encoding non-sensitive payloads, never for protecting cardholder data.
- ✗
Use RC4 encryption.
Why it's wrong here
RC4 is deprecated and insecure.
- ✓
Implement TLS 1.2 or higher with strong ciphers.
Why this is correct
TLS 1.2 or higher with strong ciphers encrypts cardholder data in transit between the mobile app and backend, preventing interception. PCI DSS requires strong cryptography for transmission over open, public networks, which older protocols and weak ciphers fail to provide.
- ✗
Use SSL 3.0.
Why it's wrong here
SSL 3.0 is deprecated and vulnerable to POODLE, so it cannot satisfy PCI DSS transmission requirements; PCI DSS mandates TLS 1.2 or higher. It is tempting because SSL was historically used to encrypt web traffic, and would have been acceptable before TLS superseded it, but modern compliance forbids it outright.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
TLS
Transport Layer Security (TLS) is a cryptographic protocol that encrypts data sent over the internet to keep it private and ensure it hasn’t been tampered with.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.