Which item is NOT considered Cardholder Data?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

Which item is NOT considered Cardholder Data?

Explanation:
In PCI terms, cardholder data includes the primary account number (PAN), the cardholder’s name, and the card’s expiration date (along with the service code in some contexts). Full track data from the magnetic stripe is not considered cardholder data; it falls under sensitive authentication data. Track data contains the same PAN and other details used for authentication, and PCI DSS requires that this data not be stored after authorization. Because it can fully reconstruct the card details, it’s treated as highly sensitive and must not be retained. Therefore, the item that is NOT cardholder data is the full track data.

In PCI terms, cardholder data includes the primary account number (PAN), the cardholder’s name, and the card’s expiration date (along with the service code in some contexts). Full track data from the magnetic stripe is not considered cardholder data; it falls under sensitive authentication data. Track data contains the same PAN and other details used for authentication, and PCI DSS requires that this data not be stored after authorization. Because it can fully reconstruct the card details, it’s treated as highly sensitive and must not be retained. Therefore, the item that is NOT cardholder data is the full track data.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy