nerdexam
Cisco

400-007 · Question #181

Which two actions must merchants do to be compliant with the Payment Card Industry Data Security Standard? (Choose two.)

The correct answer is B. install firewalls C. use antivirus software. PCI DSS mandates specific prescriptive technical controls that merchants must implement to protect cardholder data environments from breaches and unauthorized access.

Designing Security

Question

Which two actions must merchants do to be compliant with the Payment Card Industry Data Security Standard? (Choose two.)

Options

  • Aconduct risk analyses
  • Binstall firewalls
  • Cuse antivirus software
  • Destablish monitoring policies
  • Eestablish risk management policies

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    92% (23)
  • D
    4% (1)

Why each option

PCI DSS mandates specific prescriptive technical controls that merchants must implement to protect cardholder data environments from breaches and unauthorized access.

Aconduct risk analyses

Conducting risk analyses is a foundational requirement of ISO 27001 and NIST SP 800-30, not a primary prescriptive compliance action explicitly listed in PCI DSS.

Binstall firewallsCorrect

Installing and maintaining network security controls such as firewalls is explicitly required under PCI DSS Requirement 1, which mandates protecting the cardholder data environment with network perimeter defenses. This is one of the foundational prescriptive controls that distinguishes PCI DSS from risk-based frameworks.

Cuse antivirus softwareCorrect

Using antivirus software is explicitly required under PCI DSS Requirement 5, which mandates that all systems at risk from malware be protected with regularly updated anti-malware solutions. This is a specific, named technical control within the standard.

Destablish monitoring policies

While PCI DSS Requirement 10 addresses logging and monitoring, 'establishing monitoring policies' is phrased too broadly and is not one of the two explicit technical controls the standard is most known for mandating.

Eestablish risk management policies

Establishing risk management policies is a core obligation under ISO 27001 and similar governance frameworks, whereas PCI DSS specifies concrete technical and operational controls rather than policy-level risk management programs.

Concept tested: PCI DSS core technical compliance requirements

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#compliance#firewalls#antivirus

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice