CISSP Security and Risk Management Practice Question
Under the PCI DSS, which of the following best describes a 'cardholder data environment' (CDE)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Systems that store, process, or transmit cardholder data
The CDE includes people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data. Segmentation is used to isolate the CDE from other networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A physical room where payment cards are stored
Why it's wrong here
While a physical room might house components of the Cardholder Data Environment (CDE), the CDE itself is not merely a physical space. The PCI DSS definition of CDE encompasses all system components, processes, and people that store, process, or transmit cardholder data, including both physical and logical elements. Therefore, defining the CDE solely as a physical room is an incomplete and overly narrow description, failing to account for the logical infrastructure and data flow.
- ✗
Any system that connects to the internet
Why it's wrong here
This definition is overly broad and inaccurate for the PCI DSS context. Not every system connected to the internet interacts with cardholder data; for instance, a public-facing corporate website without payment functionality or an internal email server connected to the internet would not typically be part of the CDE. The CDE's scope is determined by the presence and handling of cardholder data, not simply by network connectivity to the internet.
- ✓
Systems that store, process, or transmit cardholder data
Why this is correct
This statement precisely defines the Cardholder Data Environment (CDE) according to PCI DSS. It includes all system components, applications, and network devices that directly store, process, or transmit cardholder data, as well as any system that could impact the security of the CDE. This comprehensive definition ensures that all relevant assets handling sensitive payment information are brought under the stringent security controls mandated by the standard.
- ✗
A network segment that contains only point-of-sale devices
Why it's wrong here
This definition is too restrictive, as the CDE extends beyond just point-of-sale (POS) devices and their immediate network segment. The CDE encompasses all systems that interact with cardholder data, which includes not only POS terminals but also payment application servers, databases storing cardholder data, authentication systems, security logging servers, and network infrastructure (e.g., firewalls, switches, routers) that protect or facilitate the flow of cardholder data. Limiting the CDE to only POS devices would leave many critical components out of scope.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
PCI DSS
The Payment Card Industry Data Security Standard is a set of security requirements designed to protect credit card data during storage, processing, and transmission.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.