220-1102 Question 746
Single answerCredit card payment informationA help desk technician receives a call from an employee in accounting who says a customer emailed a credit card number, expiration date, and CVV so payment could be processed quickly. The employee asks the technician how to save the message so the team can refer back to it later if there is a billing dispute. Which of the following is the BEST recommendation?
- A
Save the email in a shared folder so authorized accounting staff can access it when needed
- B
Print the email and store it in a locked cabinet to reduce exposure to online threats
- C
Delete the email after directing the employee to use the company's approved payment-processing method instead
- D
Forward the email to the manager and security team so multiple departments have a record of the payment details
Show answer and explanation
Correct answer: C
Explanation
For A+ Core 2, candidates should recognize that credit card payment information is highly sensitive and should only be handled through approved, secure payment-processing systems. Email is not an appropriate place to store or circulate full cardholder data, particularly when it includes the CVV. Under PCI DSS best practices, organizations should minimize storage of cardholder data and protect it during transmission; sensitive authentication data such as the card verification code must not be stored after authorization. In a real support scenario, the technician should guide staff to stop using insecure methods, delete improperly received payment details according to company policy, and use the official payment channel for any future transactions.
- A. Incorrect.
This is incorrect. Even if access is limited to accounting staff, storing full credit card data from email creates unnecessary risk and may violate company policy and payment card industry requirements. Email is not an approved repository for cardholder data, especially when sensitive authentication data such as the CVV is included.
- B. Incorrect.
This is incorrect. Printing the message does not solve the compliance or security problem. Physical copies of full card data and CVV still expose sensitive payment information and create additional handling and retention risks. Converting insecure electronic storage into paper storage is not an appropriate mitigation.
- C. Correct.
This is correct. The best action is to avoid retaining unencrypted cardholder data received through an unapproved channel and instead direct the employee or customer to the organization's approved payment-processing solution. This reduces exposure of cardholder data and aligns with standard security practice to minimize collection, storage, and transmission of sensitive payment information.
- D. Incorrect.
This is incorrect. Forwarding the email increases the number of copies and expands exposure of the cardholder data. Sending the information to more recipients is the opposite of data minimization and increases the chance of compromise or policy violations.