Payment Card Industry (PCI) Data Security Standards Practice Test

Disable ads (and more) with a membership for a one time $2.99 payment

Prepare for the Payment Card Industry (PCI) Data Security Standards Test. Study with multiple choice questions, hints, and explanations. Get ready to excel in your exam!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Which statement is correct regarding storage of cardholder data?

  1. Encrypting stored cardholder data removes it from PCI DSS scope

  2. Stored cardholder data that exceeds retention requirements needs to be removed on a quarterly basis

  3. Log files containing cardholder data must be securely deleted on a quarterly basis

  4. Stored cardholder data that exceeds retention requirements needs to be removed on an annual basis

The correct answer is: Log files containing cardholder data must be securely deleted on a quarterly basis

The correct understanding of data storage relative to cardholder data is particularly critical in maintaining compliance with PCI DSS requirements. The focus of this question pertains to the management of log files that include cardholder data. These log files must be securely deleted because they can present significant risks if they are not handled properly—violations in compliance can lead to breaches of cardholder data protection. Keeping such logs absent a clear business need or proper retention policies puts organizations at risk. The requirement to manage these logs quarterly is aligned with the PCI DSS emphasis on minimizing the quantity of stored sensitive data and maintaining security controls. In contrast, other statements may imply alternate measures that do not accurately reflect the PCI DSS guidelines for data retention and deletion. Encrypting data does not automatically remove it from PCI DSS scope, as even encrypted data needs to be managed appropriately. Additionally, while there are mandates for data deletion, the specific timeframe of quarterly or annual removal of stored cardholder data is subject to the requirements outlined in the organization’s data retention policy and legal considerations, making the specific claim about annual deletion incorrect.