nerdexam
EC-Council

312-50V13 · Question #9

What is not a PCI compliance recommendation?

The correct answer is C. Rotate employees handling credit card transactions on a yearly basis to different departments. PCI DSS specifies requirements for protecting cardholder data, including firewalls, encryption, and restricted access, but does not mandate yearly employee rotation to different departments.

Submitted by parkjh· Mar 6, 2026Information Security and Ethical Hacking Overview

Question

What is not a PCI compliance recommendation?

Options

  • AUse a firewall between the public network and the payment card data.
  • BUse encryption to protect all transmission of card holder data over any public network.
  • CRotate employees handling credit card transactions on a yearly basis to different departments.
  • DLimit access to card holder data to as few individuals as possible.

How the community answered

(39 responses)
  • B
    5% (2)
  • C
    92% (36)
  • D
    3% (1)

Why each option

PCI DSS specifies requirements for protecting cardholder data, including firewalls, encryption, and restricted access, but does not mandate yearly employee rotation to different departments.

AUse a firewall between the public network and the payment card data.

PCI DSS Requirement 1 explicitly mandates installing and maintaining a firewall configuration to protect cardholder data, especially between public networks and the cardholder data environment.

BUse encryption to protect all transmission of card holder data over any public network.

PCI DSS Requirement 4.1 mandates the use of strong cryptography and security protocols to protect cardholder data during transmission over open, public networks.

CRotate employees handling credit card transactions on a yearly basis to different departments.Correct

While job rotation can be a general security best practice for reducing fraud risk, rotating employees handling credit card transactions to different departments on a yearly basis is not a specific, mandated requirement or recommendation within the PCI DSS.

DLimit access to card holder data to as few individuals as possible.

PCI DSS Requirement 7.1 emphasizes limiting access to cardholder data to only those individuals whose job requires such access, adhering to the principle of least privilege.

Concept tested: PCI DSS compliance requirements

Source: https://www.pcisecuritystandards.org/documents/PCI_DSS_v4.0_Summary_of_Changes.pdf

Topics

#PCI DSS#compliance#data security standards#payment card data

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice