EC-Council Certified Ethical Hacker (CEH) v12Information Security and Ethical Hacking OverviewMedium

During a security audit, an organization is found to be storing customer credit card numbers in plain text within an unencrypted database. This practice directly violates which core principle of the Payment Card Industry Data Security Standard (PCI DSS)?

  1. ABuild and Maintain a Secure Network and Systems
  2. BImplement Strong Access Control Measures
  3. CMaintain a Vulnerability Management Program
  4. DProtect Cardholder Data
Show answer & explanation

Correct answer: D. Protect Cardholder Data

PCI DSS Requirement 3, under Principle 2, specifically mandates the protection of stored cardholder data, including encryption of sensitive authentication data and rendering Primary Account Numbers (PANs) unreadable wherever stored. Storing plain text credit card numbers is a direct violation of this principle.

Why the other options are wrong

  • A. While important, this principle (Requirement 1 & 2) focuses on firewalls, secure configurations, etc., not specifically the encryption of stored data.
  • B. This principle (Requirements 7, 8, 9) focuses on limiting access, strong authentication, and physical security, not the inherent protection of the data itself through encryption.
  • C. This principle (Requirements 6 & 11) deals with patching, secure development, and regular testing, not the storage format of data.

PCI DSS Principle 2

A core principle of the Payment Card Industry Data Security Standard (PCI DSS) that mandates the protection of stored cardholder data, specifically requiring encryption and rendering sensitive data unreadable wherever it is stored.

  • Part of the 12 PCI DSS Requirements.
  • Focuses on securing stored cardholder data.
  • Requires encryption for sensitive authentication data.
  • Mandates truncation or rendering unreadable of Primary Account Numbers (PANs).

Memory trick: Build, Protect, Manage, Control, Monitor, Test, Policy.

More Information Security and Ethical Hacking Overview questions