Courseiva
Security and Risk ManagementhardMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Under the PCI DSS, which of the following best describes a 'cardholder data environment' (CDE)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Systems that store, process, or transmit cardholder data

The CDE includes people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data. Segmentation is used to isolate the CDE from other networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A physical room where payment cards are stored

    Why it's wrong here

    While a physical room might house components of the Cardholder Data Environment (CDE), the CDE itself is not merely a physical space. The PCI DSS definition of CDE encompasses all system components, processes, and people that store, process, or transmit cardholder data, including both physical and logical elements. Therefore, defining the CDE solely as a physical room is an incomplete and overly narrow description, failing to account for the logical infrastructure and data flow.

  • Any system that connects to the internet

    Why it's wrong here

    This definition is overly broad and inaccurate for the PCI DSS context. Not every system connected to the internet interacts with cardholder data; for instance, a public-facing corporate website without payment functionality or an internal email server connected to the internet would not typically be part of the CDE. The CDE's scope is determined by the presence and handling of cardholder data, not simply by network connectivity to the internet.

  • Systems that store, process, or transmit cardholder data

    Why this is correct

    This statement precisely defines the Cardholder Data Environment (CDE) according to PCI DSS. It includes all system components, applications, and network devices that directly store, process, or transmit cardholder data, as well as any system that could impact the security of the CDE. This comprehensive definition ensures that all relevant assets handling sensitive payment information are brought under the stringent security controls mandated by the standard.

  • A network segment that contains only point-of-sale devices

    Why it's wrong here

    This definition is too restrictive, as the CDE extends beyond just point-of-sale (POS) devices and their immediate network segment. The CDE encompasses all systems that interact with cardholder data, which includes not only POS terminals but also payment application servers, databases storing cardholder data, authentication systems, security logging servers, and network infrastructure (e.g., firewalls, switches, routers) that protect or facilitate the flow of cardholder data. Limiting the CDE to only POS devices would leave many critical components out of scope.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.