200-201 Question 388
Single answerYou are a security analyst investigating data traffic on your organization's network. During your analysis, you come across a data packet that contains what appears to be a 16-digit number, a full name, and an expiration date. Which of the following types of protected data is most likely being transmitted, and what actions should be prioritized to protect it?
- A
Credit card information; ensure the transmission is encrypted and compliant with PCI DSS standards.
- B
Social Security Number (SSN); block the transmission and report it to the compliance officer.
- C
Medical records; confirm HIPAA compliance for the transmission.
- D
Employee ID numbers; log the event and notify the HR department.
Show answer and explanation
Correct answer: A
Explanation
The data packet identified likely contains credit card information, given the format of a 16-digit number, a name, and an expiration date. Credit card data is considered protected information and must comply with PCI DSS standards to ensure encryption during transmission. Identifying the data type allows appropriate actions to be taken to secure the network and comply with relevant regulations.
- A. Correct.
Credit card information typically consists of a 16-digit number, a name, and an expiration date. This data is highly sensitive and protected under PCI DSS standards, which require encryption during transmission to prevent unauthorized access.
- B. Incorrect.
Social Security Numbers (SSNs) do not include expiration dates and are formatted differently, typically as nine digits (e.g., XXX-XX-XXXX). This does not match the data identified in the packet.
- C. Incorrect.
Medical records are covered under HIPAA but generally include health-related information such as diagnoses or treatments rather than a 16-digit number and an expiration date.
- D. Incorrect.
Employee ID numbers are typically shorter and do not include expiration dates or names in the format described. This data does not align with the information in the packet.