ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 478 - CAS-004 discussion

Report
Export

A company would like to move its payment card data to a cloud provider. Which of the following solutions will best protect account numbers from unauthorized disclosure?

A.
Storing the data in an encoded file
Answers
A.
Storing the data in an encoded file
B.
Implementing database encryption at rest
Answers
B.
Implementing database encryption at rest
C.
Only storing tokenized card data
Answers
C.
Only storing tokenized card data
D.
Implementing data field masking
Answers
D.
Implementing data field masking
Suggested answer: C

Explanation:

Tokenization is the best solution to protect payment card data from unauthorized disclosure when moving to the cloud. Tokenization replaces sensitive card data with unique identifiers (tokens) that have no exploitable value outside the tokenization system. Even if the data is compromised, the attacker would not obtain actual card numbers. This is in line with PCI DSS requirements for protecting payment card information. Other solutions like encryption at rest or field masking help, but tokenization provides the strongest protection by ensuring that card data is not stored at all.

CASP+ CAS-004 Exam Objectives: Domain 1.0 -- Risk Management (Tokenization and PCI DSS Compliance)

CompTIA CASP+ Study Guide: Data Protection Techniques (Tokenization)

asked 02/10/2024
Yun-Ting Lo
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first