nerdexam
EC-Council

312-50V11 · Question #11

What is not a PCI compliance recommendation?

The correct answer is C. Rotate employees handling credit card transactions on a yearly basis to different departments. PCI DSS specifies technical and operational controls for protecting cardholder data, but mandatory yearly rotation of employees across departments is not among its requirements.

Information Security and Ethical Hacking Fundamentals

Question

What is not a PCI compliance recommendation?

Options

  • AUse a firewall between the public network and the payment card data.
  • BUse encryption to protect all transmission of card holder data over any public network.
  • CRotate employees handling credit card transactions on a yearly basis to different departments.
  • DLimit access to card holder data to as few individuals as possible.

How the community answered

(53 responses)
  • A
    4% (2)
  • B
    6% (3)
  • C
    89% (47)
  • D
    2% (1)

Why each option

PCI DSS specifies technical and operational controls for protecting cardholder data, but mandatory yearly rotation of employees across departments is not among its requirements.

AUse a firewall between the public network and the payment card data.

PCI DSS Requirement 1 explicitly mandates installing and maintaining a firewall configuration to protect cardholder data, including between public networks and the cardholder data environment.

BUse encryption to protect all transmission of card holder data over any public network.

PCI DSS Requirement 4 mandates encrypting transmission of cardholder data across open or public networks using strong cryptography.

CRotate employees handling credit card transactions on a yearly basis to different departments.Correct

PCI DSS Requirements 7 and 8 focus on restricting and controlling access to cardholder data based on need-to-know and enforcing authentication, but there is no requirement to rotate employees handling card transactions to different departments on any schedule. Mandatory job rotation is not listed in any PCI DSS requirement or guidance.

DLimit access to card holder data to as few individuals as possible.

PCI DSS Requirement 7 mandates restricting access to system components and cardholder data to only those individuals whose job requires such access - the least privilege principle.

Concept tested: PCI DSS requirements for cardholder data protection

Source: https://www.pcisecuritystandards.org/document_library/?category=pcidss&document=pci_dss

Topics

#PCI-DSS#compliance requirements#access control#cardholder data

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice