220-1002 · Question #812
A technician has been tasked with installing a workstation that will be used for point-of-sale transactions. The point-of-sale system will process credit cards and loyalty cards. Which of the…
The correct answer is A. Data-in-transit encryption. For a POS system processing credit and loyalty cards, data-in-transit encryption (such as TLS/SSL or point-to-point encryption, P2PE) is the primary security control required. PCI-DSS compliance strongly discourages storing cardholder data locally on the workstation, meaning…
Question
A technician has been tasked with installing a workstation that will be used for point-of-sale transactions. The point-of-sale system will process credit cards and loyalty cards. Which of the following encryption technologies should be used to secure the workstation in case of theft?
Options
- AData-in-transit encryption
- BFile encryption
- CUSB drive encryption
- DDisk encryption
How the community answered
(14 responses)- A64% (9)
- B7% (1)
- C21% (3)
- D7% (1)
Explanation
For a POS system processing credit and loyalty cards, data-in-transit encryption (such as TLS/SSL or point-to-point encryption, P2PE) is the primary security control required. PCI-DSS compliance strongly discourages storing cardholder data locally on the workstation, meaning there is minimal sensitive data at rest to protect. The real exposure is card data as it travels from the POS terminal to the payment processor. If the workstation is stolen and no card data is stored locally, data-in-transit encryption ensures that any intercepted network traffic cannot expose cardholder data. Disk encryption protects data stored on disk, but PCI-compliant POS systems avoid local storage of card data.
Topics
Community Discussion
No community discussion yet for this question.