CISSP Security and Risk Management Practice Question
A company is implementing PCI DSS compliance. Which requirement is related to protecting cardholder data at rest?
⚠ Common exam trap
CISSP often tests the confusion between data-at-rest and data-in-transit requirements, and candidates may incorrectly associate physical access or firewalls with protecting stored data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protect stored cardholder data
PCI DSS Requirement 3 is 'Protect stored cardholder data,' which specifically addresses data at rest through encryption, truncation, masking, and hashing. This requirement mandates protections for cardholder data wherever it is stored, including databases, files, and backups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restrict physical access to cardholder data
Why it's wrong here
This option, while a critical component of PCI DSS Requirement 9, focuses on physical security controls to prevent unauthorized access to facilities, equipment, and media containing cardholder data. It involves measures like access control systems, surveillance, and visitor logs to safeguard the physical environment where data resides, rather than the logical protection of the data itself once stored.
- ✗
Encrypt transmission of cardholder data over open networks
Why it's wrong here
Encrypting transmission of cardholder data over open networks is a fundamental aspect of PCI DSS Requirement 4, specifically addressing data in transit. This requirement mandates the use of strong cryptography and security protocols to protect cardholder data as it travels across internal and external networks, ensuring its confidentiality during communication, but it does not directly pertain to data at rest.
- ✗
Install and maintain a firewall configuration
Why it's wrong here
Installing and maintaining a firewall configuration is a foundational element of PCI DSS Requirement 1, which establishes network security controls. This requirement focuses on segmenting the cardholder data environment (CDE) from untrusted networks, filtering traffic, and defining secure network zones to prevent unauthorized access to system components and cardholder data, primarily addressing network perimeter security.
- ✓
Protect stored cardholder data
Why this is correct
Protecting stored cardholder data is precisely what PCI DSS Requirement 3 mandates, making this the correct answer. This requirement specifically addresses data at rest, compelling organizations to render cardholder data unreadable through methods such as strong encryption, truncation, masking, or tokenization when it is stored on systems, databases, or other media, thereby minimizing its value if a breach occurs.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Hashing
Hashing is a one-way mathematical function that converts any input data into a fixed-length string of characters, called a hash or digest, which is used to verify data integrity and store passwords securely.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.