nerdexam
EC-Council

312-50V10 · Question #808

The Payment Card Industry Data Security Standard (PCI DSS) con ai s six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to

The correct answer is C. Assign a unique ID to each person with computer access.. PCI DSS organizes requirements under six control objectives; assigning unique IDs to users falls under 'Implement Strong Access Control Measures' as Requirement 8.

Information Security and Ethical Hacking Fundamentals

Question

The Payment Card Industry Data Security Standard (PCI DSS) con ai s six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to achieve compliance. Which of the following requirements would best fit under the objective, "Implement strong access control measures"?

Options

  • ARegularly test security systems and processes.
  • BEncrypt transmission of cardholder data across open, public networks.
  • CAssign a unique ID to each person with computer access.
  • DUse and regularly update anti-virus software on all systems commonly affected by malware.

How the community answered

(18 responses)
  • A
    6% (1)
  • C
    94% (17)

Why each option

PCI DSS organizes requirements under six control objectives; assigning unique IDs to users falls under 'Implement Strong Access Control Measures' as Requirement 8.

ARegularly test security systems and processes.

Regularly testing security systems and processes corresponds to PCI DSS Requirement 11, which falls under the 'Regularly Monitor and Test Networks' objective, not access control.

BEncrypt transmission of cardholder data across open, public networks.

Encrypting cardholder data transmission over public networks is PCI DSS Requirement 4, which falls under the 'Protect Cardholder Data' objective.

CAssign a unique ID to each person with computer access.Correct

Assigning a unique ID to each person with computer access maps directly to PCI DSS Requirement 8 (Identify and Authenticate Access to System Components), which is explicitly listed under the 'Implement Strong Access Control Measures' objective. Unique user identification ensures individual accountability and prevents shared credentials from obscuring audit trails. This is a foundational access control mechanism that cannot be substituted by the other listed controls for this specific objective.

DUse and regularly update anti-virus software on all systems commonly affected by malware.

Using and regularly updating anti-virus software is PCI DSS Requirement 5, which falls under the 'Maintain a Vulnerability Management Program' objective.

Concept tested: PCI DSS control objectives and requirement mapping

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#access control#compliance#unique user identification

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice