nerdexam
Cisco

400-007 · Question #248

A banking customer determines that it is operating POS and POI terminals that are noncompliant with PCI DSS requirements, as it is running TLSv1.0. The customer plans to migrate the terminals to…

The correct answer is B. Apply strong cryptography and security protocols to safeguard sensitive cardholder data. C. Apply strong encryption for transmission of cardholder data across public networks. PCI DSS Requirements 4 and 4.2.1 directly mandate the use of strong cryptography and encryption for protecting cardholder data in transit, making them the applicable requirements for a TLS 1.0 to 1.2 migration.

Designing Security

Question

A banking customer determines that it is operating POS and POI terminals that are noncompliant with PCI DSS requirements, as it is running TLSv1.0. The customer plans to migrate the terminals to TLSv1.2. What are two requirements to complete the migration? (Choose two.)

Options

  • AEnsure that strong cryptography is applied for users who have administrative access through
  • BApply strong cryptography and security protocols to safeguard sensitive cardholder data.
  • CApply strong encryption for transmission of cardholder data across public networks.
  • DProtect all user systems against malware and frequently update antivirus software
  • EMaintain a policy that addresses information security for employees and third parties.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    83% (25)
  • D
    3% (1)
  • E
    10% (3)

Why each option

PCI DSS Requirements 4 and 4.2.1 directly mandate the use of strong cryptography and encryption for protecting cardholder data in transit, making them the applicable requirements for a TLS 1.0 to 1.2 migration.

AEnsure that strong cryptography is applied for users who have administrative access through

PCI DSS Requirement 8 addresses strong cryptography for non-console administrative access, which is a user authentication control and is not specifically tied to the POS/POI terminal TLS protocol migration.

BApply strong cryptography and security protocols to safeguard sensitive cardholder data.Correct

PCI DSS Requirement 4 mandates applying strong cryptography and security protocols such as TLSv1.2 or higher to safeguard sensitive cardholder data during transmission, which is the direct technical objective of migrating away from the deprecated TLSv1.0.

CApply strong encryption for transmission of cardholder data across public networks.Correct

PCI DSS Requirement 4.2.1 specifically requires strong encryption for the transmission of cardholder data across open, public networks, which maps precisely to the protocol upgrade being performed on POS and POI terminals.

DProtect all user systems against malware and frequently update antivirus software

PCI DSS Requirement 5 covers anti-malware and antivirus software protections for systems, which is unrelated to the TLS protocol version upgrade on payment terminals.

EMaintain a policy that addresses information security for employees and third parties.

PCI DSS Requirement 12 addresses maintaining an information security policy for all personnel and contractors, which is an administrative governance control unrelated to the technical TLS migration.

Concept tested: PCI DSS TLS migration encryption requirements for cardholder data

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#TLS#encryption#compliance

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice