101 · Question #342
Information leakage is a major obstacle to achieving PCI DSS compliance.
The correct answer is A. True. Information leakage - exposing cardholder data, system details, or error messages - directly violates multiple PCI DSS requirements, making it a significant compliance obstacle.
Question
Information leakage is a major obstacle to achieving PCI DSS compliance.
Options
- ATrue
- BFalse
How the community answered
(25 responses)- A92% (23)
- B8% (2)
Why each option
Information leakage - exposing cardholder data, system details, or error messages - directly violates multiple PCI DSS requirements, making it a significant compliance obstacle.
PCI DSS Requirements 3, 4, and 6 mandate that cardholder data be protected at rest and in transit, and that applications do not leak sensitive data through error messages, verbose responses, or insecure storage. Information leakage can expose Primary Account Numbers (PANs), authentication data, or infrastructure details that undermine the entire compliance posture.
Stating this is false would be incorrect because information leakage is explicitly addressed across multiple PCI DSS requirements and is a well-recognized barrier to achieving and maintaining compliance.
Concept tested: PCI DSS compliance and information leakage impact
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.