400-007 · Question #181
Which two actions must merchants do to be compliant with the Payment Card Industry Data Security Standard? (Choose two.)
The correct answer is B. install firewalls C. use antivirus software. PCI DSS mandates specific prescriptive technical controls that merchants must implement to protect cardholder data environments from breaches and unauthorized access.
Question
Which two actions must merchants do to be compliant with the Payment Card Industry Data Security Standard? (Choose two.)
Options
- Aconduct risk analyses
- Binstall firewalls
- Cuse antivirus software
- Destablish monitoring policies
- Eestablish risk management policies
How the community answered
(25 responses)- A4% (1)
- B92% (23)
- D4% (1)
Why each option
PCI DSS mandates specific prescriptive technical controls that merchants must implement to protect cardholder data environments from breaches and unauthorized access.
Conducting risk analyses is a foundational requirement of ISO 27001 and NIST SP 800-30, not a primary prescriptive compliance action explicitly listed in PCI DSS.
Installing and maintaining network security controls such as firewalls is explicitly required under PCI DSS Requirement 1, which mandates protecting the cardholder data environment with network perimeter defenses. This is one of the foundational prescriptive controls that distinguishes PCI DSS from risk-based frameworks.
Using antivirus software is explicitly required under PCI DSS Requirement 5, which mandates that all systems at risk from malware be protected with regularly updated anti-malware solutions. This is a specific, named technical control within the standard.
While PCI DSS Requirement 10 addresses logging and monitoring, 'establishing monitoring policies' is phrased too broadly and is not one of the two explicit technical controls the standard is most known for mandating.
Establishing risk management policies is a core obligation under ISO 27001 and similar governance frameworks, whereas PCI DSS specifies concrete technical and operational controls rather than policy-level risk management programs.
Concept tested: PCI DSS core technical compliance requirements
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.