Courseiva
mediumMultiple Choice

CISSP Developing a mobile payment application Practice Question

A company is developing a mobile payment application. To comply with PCI DSS, what should be implemented to protect cardholder data during transmission?

⚠ Common exam trap

A common mix-up: candidates confuse encoding (base64) with encryption, or assume that any SSL/TLS version is acceptable, but PCI DSS specifically requires TLS 1.2 or higher and prohibits deprecated protocols like SSL 3.0 and weak ciphers like RC4.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement TLS 1.2 or higher with strong ciphers.

TLS 1.2 or higher with strong ciphers is the correct choice because PCI DSS Requirement 4 mandates that cardholder data must be encrypted using strong cryptography (e.g., TLS 1.2/1.3) during transmission over open, public networks. TLS provides mutual authentication, data integrity, and confidentiality through a handshake that negotiates a session key, protecting against eavesdropping and tampering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply base64 encoding.

    Why it's wrong here

    Base64 is a reversible encoding, not encryption, so cardholder data remains readable in transit and fails PCI DSS encryption requirements. It is tempting because it obscures data visually and is commonly used to embed binary content in text protocols, but it would only be appropriate for encoding non-sensitive payloads, never for protecting cardholder data.

  • ✗

    Use RC4 encryption.

    Why it's wrong here

    RC4 is deprecated and insecure.

  • ✓

    Implement TLS 1.2 or higher with strong ciphers.

    Why this is correct

    TLS 1.2 or higher with strong ciphers encrypts cardholder data in transit between the mobile app and backend, preventing interception. PCI DSS requires strong cryptography for transmission over open, public networks, which older protocols and weak ciphers fail to provide.

  • ✗

    Use SSL 3.0.

    Why it's wrong here

    SSL 3.0 is deprecated and vulnerable to POODLE, so it cannot satisfy PCI DSS transmission requirements; PCI DSS mandates TLS 1.2 or higher. It is tempting because SSL was historically used to encrypt web traffic, and would have been acceptable before TLS superseded it, but modern compliance forbids it outright.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.