PCI DSS allows for theuse of truncation and hashingfor protecting PAN, butRequirement 3.4.1and its guidance warn againstcombining hashed and truncated PANsin such a way that the original PAN could be reconstructed. If both formats exist,controls must ensurethey can't be used together to reverse-engineer the PAN.
Option A:✅Correct. Controls must ensure PAN cannot be reconstructed using both versions.
Option B:❌Incorrect. A hashed PAN does not need truncation — hashing is a separate mechanism.
Option C:❌Incorrect. PCI DSS aims to prevent correlation, not encourage it.
Option D:❌Incorrect. They can coexist, but must be secured so that PAN cannot be derived.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit