CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium

A financial institution is implementing a new database system to comply with PCI DSS requirements for protecting cardholder data. The standard mandates that sensitive authentication data must not be stored after authorization. Which database security measure directly addresses this requirement?

  1. AUtilizing data tokenization for card numbers.
  2. BEnsuring data retention policies automatically purge old data.
  3. CConfiguring robust database auditing for all transactions.
  4. DImplementing Transparent Data Encryption (TDE) for the entire database.
Show answer & explanation

Correct answer: B. Ensuring data retention policies automatically purge old data.

PCI DSS requirement 3.2 explicitly states that sensitive authentication data (e.g., CVV, PINs) must not be stored after authorization. Implementing data retention policies that automatically purge this specific type of data ensures compliance with this 'do not store' mandate.

Why the other options are wrong

  • A. Tokenization replaces card numbers with non-sensitive tokens, which is good for primary account numbers, but PCI DSS prohibits storage of sensitive authentication data entirely.
  • C. Auditing tracks actions but doesn't prevent or remove the storage of prohibited data.
  • D. TDE encrypts data at rest but doesn't prevent storage of prohibited data types.

Data Retention Policy

A data retention policy defines how long specific types of data must be kept and how they should be securely disposed of after their retention period, often driven by legal, regulatory, or business requirements.

  • Specifies data lifespan.
  • Includes secure disposal methods.
  • Crucial for compliance and data minimization.

Memory trick: PCI says 'No' to some data after use.

More Data and Database Security questions