PCIP Cardholder Data Environment 1 — Questions and Answers
Question 1: Which of the following best defines the Cardholder Data Environment (CDE) in the context of PCI DSS?
- Any system that connects to the internet and processes financial transactions
- The people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data (Correct answer)
- Only the servers that store primary account numbers (PANs) in encrypted form
- The network segment that hosts the organization's payment gateway exclusively
Correct answer: The people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data
The CDE encompasses all people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data, as well as systems connected to or that could impact its security.
Question 2: Which of the following data elements is considered cardholder data under PCI DSS?
- The full CVV2/CVC2 code stored post-authorization
- The Primary Account Number (PAN) (Correct answer)
- The full contents of the magnetic stripe stored after transaction approval
- The PIN verification value (PVV) stored in a database
Correct answer: The Primary Account Number (PAN)
The Primary Account Number (PAN) is cardholder data; the other options describe sensitive authentication data (SAD) that must never be stored post-authorization.
Question 3: A retailer's point-of-sale terminals transmit cardholder data to a back-office server that then forwards it to an acquirer. Which systems are considered part of the CDE?
- Only the back-office server, since it is the central processing point
- Only the POS terminals and the acquirer's systems
- The POS terminals and the back-office server, but not the acquirer's systems
- The POS terminals, back-office server, and all systems that could impact their security (Correct answer)
Correct answer: The POS terminals, back-office server, and all systems that could impact their security
PCI DSS defines the CDE to include all systems that store, process, or transmit cardholder data AND any systems that could impact the security of those systems, so all interconnected components are in scope.
Question 4: Under PCI DSS, which of the following is classified as Sensitive Authentication Data (SAD)?
- Cardholder name
- Primary Account Number (PAN)
- Full track data from the magnetic stripe (Correct answer)
- Expiration date
Correct answer: Full track data from the magnetic stripe
Full track data (magnetic stripe or equivalent on a chip) is Sensitive Authentication Data and must never be stored after authorization, unlike PANs, names, or expiration dates, which are cardholder data.
Question 5: What is the primary purpose of network segmentation when applied to the CDE?
- To eliminate the need for firewalls within the payment environment
- To improve network performance by reducing broadcast traffic
- To reduce the scope of PCI DSS compliance by isolating cardholder data systems (Correct answer)
- To enable the organization to avoid annual PCI DSS assessments
Correct answer: To reduce the scope of PCI DSS compliance by isolating cardholder data systems
Network segmentation isolates the CDE from other networks, which reduces the number of systems in scope for PCI DSS and can simplify compliance efforts.
Question 6: Which statement about storing Sensitive Authentication Data (SAD) post-authorization is correct under PCI DSS?
- SAD may be stored post-authorization only if it is encrypted with AES-256
- SAD may be stored post-authorization if a documented business justification exists
- SAD must never be stored after the authorization process is complete, regardless of encryption (Correct answer)
- SAD may be stored by issuers but not by merchants or acquirers
Correct answer: SAD must never be stored after the authorization process is complete, regardless of encryption
PCI DSS prohibits storing SAD after authorization for all entities — this rule applies regardless of encryption or business need for merchants, service providers, and acquirers.
Question 7: A company uses a third-party payment processor that handles all cardholder data on its behalf, and the company never touches card data directly. How does this affect the company's PCI DSS scope?
- The company is entirely exempt from PCI DSS requirements
- The company's scope is reduced but it still has PCI DSS obligations related to how it connects to the processor (Correct answer)
- The company must still store a full copy of cardholder data for audit purposes
- Only the third-party processor must comply with PCI DSS, not the company
Correct answer: The company's scope is reduced but it still has PCI DSS obligations related to how it connects to the processor
Outsourcing card processing reduces scope but does not eliminate it; the company is still responsible for ensuring secure connections to the processor and may need to validate compliance via an SAQ.
Which of the following best defines the Cardholder Data Environment (CDE) in the context of PCI DSS?