400-007 · Question #248
A banking customer determines that it is operating POS and POI terminals that are noncompliant with PCI DSS requirements, as it is running TLSv1.0. The customer plans to migrate the terminals to…
The correct answer is B. Apply strong cryptography and security protocols to safeguard sensitive cardholder data. C. Apply strong encryption for transmission of cardholder data across public networks. PCI DSS Requirements 4 and 4.2.1 directly mandate the use of strong cryptography and encryption for protecting cardholder data in transit, making them the applicable requirements for a TLS 1.0 to 1.2 migration.
Question
A banking customer determines that it is operating POS and POI terminals that are noncompliant with PCI DSS requirements, as it is running TLSv1.0. The customer plans to migrate the terminals to TLSv1.2. What are two requirements to complete the migration? (Choose two.)
Options
- AEnsure that strong cryptography is applied for users who have administrative access through
- BApply strong cryptography and security protocols to safeguard sensitive cardholder data.
- CApply strong encryption for transmission of cardholder data across public networks.
- DProtect all user systems against malware and frequently update antivirus software
- EMaintain a policy that addresses information security for employees and third parties.
How the community answered
(30 responses)- A3% (1)
- B83% (25)
- D3% (1)
- E10% (3)
Why each option
PCI DSS Requirements 4 and 4.2.1 directly mandate the use of strong cryptography and encryption for protecting cardholder data in transit, making them the applicable requirements for a TLS 1.0 to 1.2 migration.
PCI DSS Requirement 8 addresses strong cryptography for non-console administrative access, which is a user authentication control and is not specifically tied to the POS/POI terminal TLS protocol migration.
PCI DSS Requirement 4 mandates applying strong cryptography and security protocols such as TLSv1.2 or higher to safeguard sensitive cardholder data during transmission, which is the direct technical objective of migrating away from the deprecated TLSv1.0.
PCI DSS Requirement 4.2.1 specifically requires strong encryption for the transmission of cardholder data across open, public networks, which maps precisely to the protocol upgrade being performed on POS and POI terminals.
PCI DSS Requirement 5 covers anti-malware and antivirus software protections for systems, which is unrelated to the TLS protocol version upgrade on payment terminals.
PCI DSS Requirement 12 addresses maintaining an information security policy for all personnel and contractors, which is an administrative governance control unrelated to the technical TLS migration.
Concept tested: PCI DSS TLS migration encryption requirements for cardholder data
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.