Courseiva

CISSP Security and Risk Management Practice Question

A company is implementing PCI DSS compliance. Which requirement is related to protecting cardholder data at rest?

⚠ Common exam trap

CISSP often tests the confusion between data-at-rest and data-in-transit requirements, and candidates may incorrectly associate physical access or firewalls with protecting stored data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Protect stored cardholder data

PCI DSS Requirement 3 is 'Protect stored cardholder data,' which specifically addresses data at rest through encryption, truncation, masking, and hashing. This requirement mandates protections for cardholder data wherever it is stored, including databases, files, and backups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restrict physical access to cardholder data

    Why it's wrong here

    This option, while a critical component of PCI DSS Requirement 9, focuses on physical security controls to prevent unauthorized access to facilities, equipment, and media containing cardholder data. It involves measures like access control systems, surveillance, and visitor logs to safeguard the physical environment where data resides, rather than the logical protection of the data itself once stored.

  • ✗

    Encrypt transmission of cardholder data over open networks

    Why it's wrong here

    Encrypting transmission of cardholder data over open networks is a fundamental aspect of PCI DSS Requirement 4, specifically addressing data in transit. This requirement mandates the use of strong cryptography and security protocols to protect cardholder data as it travels across internal and external networks, ensuring its confidentiality during communication, but it does not directly pertain to data at rest.

  • ✗

    Install and maintain a firewall configuration

    Why it's wrong here

    Installing and maintaining a firewall configuration is a foundational element of PCI DSS Requirement 1, which establishes network security controls. This requirement focuses on segmenting the cardholder data environment (CDE) from untrusted networks, filtering traffic, and defining secure network zones to prevent unauthorized access to system components and cardholder data, primarily addressing network perimeter security.

  • ✓

    Protect stored cardholder data

    Why this is correct

    Protecting stored cardholder data is precisely what PCI DSS Requirement 3 mandates, making this the correct answer. This requirement specifically addresses data at rest, compelling organizations to render cardholder data unreadable through methods such as strong encryption, truncation, masking, or tokenization when it is stored on systems, databases, or other media, thereby minimizing its value if a breach occurs.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.