nerdexam
EC-Council

312-50V11 · Question #808

The Payment Card Industry Data Security Standard (PCI DSS) con ai s six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to

The correct answer is C. Assign a unique ID to each person with computer access.. PCI DSS Requirement 8 - assigning unique IDs to each user - falls specifically under the 'Implement strong access control measures' objective, enabling accountability and traceability of access.

Information Security and Ethical Hacking Fundamentals

Question

The Payment Card Industry Data Security Standard (PCI DSS) con ai s six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to achieve compliance. Which of the following requirements would best fit under the objective, "Implement strong access control measures"?

Options

  • ARegularly test security systems and processes.
  • BEncrypt transmission of cardholder data across open, public networks.
  • CAssign a unique ID to each person with computer access.
  • DUse and regularly update anti-virus software on all systems commonly affected by malware.

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    94% (32)

Why each option

PCI DSS Requirement 8 - assigning unique IDs to each user - falls specifically under the 'Implement strong access control measures' objective, enabling accountability and traceability of access.

ARegularly test security systems and processes.

Regularly testing security systems and processes maps to the PCI DSS objective 'Regularly monitor and test networks,' not access control.

BEncrypt transmission of cardholder data across open, public networks.

Encrypting cardholder data transmission over public networks falls under the 'Protect cardholder data' objective, specifically Requirement 4.

CAssign a unique ID to each person with computer access.Correct

PCI DSS Requirement 8 (Identify and Authenticate Access to System Components) mandates assigning a unique ID to every user with computer access, which directly supports the 'Implement strong access control measures' objective. Unique IDs ensure that all actions on cardholder data systems can be attributed to a specific individual, enabling accountability and audit trails.

DUse and regularly update anti-virus software on all systems commonly affected by malware.

Maintaining and updating anti-virus software is part of the 'Maintain a vulnerability management program' objective, specifically Requirement 5.

Concept tested: PCI DSS access control objectives and requirement mapping

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#access control#compliance#unique user ID

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice