nerdexam
F5

101 · Question #346

The PCI compliance report is proof that a company is secure.

The correct answer is B. False. A PCI DSS compliance report demonstrates adherence to a defined set of controls at a point in time but does not guarantee that a company is fully or continuously secure.

Section 4: Security Basics

Question

The PCI compliance report is proof that a company is secure.

Options

  • ATrue
  • BFalse

How the community answered

(44 responses)
  • A
    11% (5)
  • B
    89% (39)

Why each option

A PCI DSS compliance report demonstrates adherence to a defined set of controls at a point in time but does not guarantee that a company is fully or continuously secure.

ATrue

Compliance frameworks like PCI DSS address a defined subset of controls and cannot account for all possible attack vectors, zero-day vulnerabilities, or misconfigurations introduced after the audit.

BFalseCorrect

PCI DSS compliance is a point-in-time assessment against a specific set of cardholder data protection requirements, not a comprehensive security certification. A company can pass a PCI audit and still have unaddressed vulnerabilities outside the PCI scope or newly introduced after the assessment. Security is an ongoing process, whereas a compliance report is a static snapshot.

Concept tested: PCI DSS compliance vs. actual security posture

Source: https://www.pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/does-pci-dss-compliance-make-a-company-secure/

Topics

#PCI DSS#compliance#security assessment

Community Discussion

No community discussion yet for this question.

Full 101 Practice