Which items are considered Sensitive Authentication Data?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

Which items are considered Sensitive Authentication Data?

Explanation:
Sensitive Authentication Data refers to the security-related information that proves a cardholder’s identity during a payment. This includes card verification codes/values (CVV/CVC/CID), full track data from the magnetic stripe, and the PIN and PIN blocks. These elements are used to authenticate the cardholder and the card, so they are extremely sensitive and must not be stored after authorization. The other items—cardholder name, card expiration date, and merchant category code—are not used to authenticate the cardholder and are not considered Sensitive Authentication Data.

Sensitive Authentication Data refers to the security-related information that proves a cardholder’s identity during a payment. This includes card verification codes/values (CVV/CVC/CID), full track data from the magnetic stripe, and the PIN and PIN blocks. These elements are used to authenticate the cardholder and the card, so they are extremely sensitive and must not be stored after authorization. The other items—cardholder name, card expiration date, and merchant category code—are not used to authenticate the cardholder and are not considered Sensitive Authentication Data.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy