Courseiva
Security and Risk ManagementmediumMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

A company is implementing PCI DSS compliance. Which requirement is related to protecting cardholder data at rest?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Protect stored cardholder data

PCI DSS Requirement 3 is to protect stored cardholder data, often through encryption or tokenization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Restrict physical access to cardholder data

    Why it's wrong here

    This option, while a critical component of PCI DSS Requirement 9, focuses on physical security controls to prevent unauthorized access to facilities, equipment, and media containing cardholder data. It involves measures like access control systems, surveillance, and visitor logs to safeguard the physical environment where data resides, rather than the logical protection of the data itself once stored.

  • Encrypt transmission of cardholder data over open networks

    Why it's wrong here

    Encrypting transmission of cardholder data over open networks is a fundamental aspect of PCI DSS Requirement 4, specifically addressing data in transit. This requirement mandates the use of strong cryptography and security protocols to protect cardholder data as it travels across internal and external networks, ensuring its confidentiality during communication, but it does not directly pertain to data at rest.

  • Install and maintain a firewall configuration

    Why it's wrong here

    Installing and maintaining a firewall configuration is a foundational element of PCI DSS Requirement 1, which establishes network security controls. This requirement focuses on segmenting the cardholder data environment (CDE) from untrusted networks, filtering traffic, and defining secure network zones to prevent unauthorized access to system components and cardholder data, primarily addressing network perimeter security.

  • Protect stored cardholder data

    Why this is correct

    Protecting stored cardholder data is precisely what PCI DSS Requirement 3 mandates, making this the correct answer. This requirement specifically addresses data at rest, compelling organizations to render cardholder data unreadable through methods such as strong encryption, truncation, masking, or tokenization when it is stored on systems, databases, or other media, thereby minimizing its value if a breach occurs.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.