A sample of business facilities is reviewed during the PCI DSS assessment What is the assessor required to validate about the sample?
According to requirement 1, what is the purpose of "Network Security Controls?
Which scenario meets PCI DSS requirements for critical systems to have correct and consistent time?
If segmentation is being used to reduce the scope of a PCI DSS assessment the assessor will?
Which systems must have anti-malware solutions'
Where an entity under assessment is using the customized approach, which of the following steps is the responsibility of the assessor?
The intent of assigning a risk ranking to vulnerabilities is to?
What does the PCI PTS standard cover?
Which of the following is true regarding internal vulnerability scans?
Which of the following describes "stateful responses' to communication initiated by a trusted network?
What would be an appropriate strength for the key-encrypting key (KEK) used to protect an AES 128-bit data-encrypting key (DEK)
An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA. while also ensuing that the customized control is implemented securely. Which of the following statements is true?
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?
Which statement is true regarding the use of intrusion detection techniques, such as intrusion detection systems and/or intrusion protection systems (IDS'IPS)?
What is the intent of classifying media that contains cardholder data?
Which of the following is an example of multi-factor authentication?
Which of the following file types must be monitored by a change-detection mechanism (for example, a file-integrity monitoring tool)?
An entity accepts e-commerce payment card transactions and stores account data in a database The database server and the web server are both accessible from the Internet The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements7