400-007 · Question #283
An IT service provider is upgrading network infrastructure to comply with PCI security standards. The network team finds that 802.1X and VPN authentication based on locally-significant certificates…
The correct answer is A. Enable phone VPN authentication based on end-user username and password. When legacy phones cannot support certificate-based 802.1X or VPN authentication required by PCI standards, username and password VPN authentication serves as a compliant fallback mechanism.
Question
An IT service provider is upgrading network infrastructure to comply with PCI security standards. The network team finds that 802.1X and VPN authentication based on locally-significant certificates are not available on some legacy phones. Which workaround solution meets the requirement?
Options
- AEnable phone VPN authentication based on end-user username and password
- BReplace legacy phones with new phones because the legacy phones will lose trust if the
- CTemporarily allow fallback to TLS 1.0 when using certificates and then upgrade the software on
- DUse authentication-based clear text password with no EAP-MD5 on the legacy phones
How the community answered
(33 responses)- A73% (24)
- B6% (2)
- C15% (5)
- D6% (2)
Why each option
When legacy phones cannot support certificate-based 802.1X or VPN authentication required by PCI standards, username and password VPN authentication serves as a compliant fallback mechanism.
Username and password-based VPN authentication is a recognized alternative when device certificates are not supported by legacy hardware. It maintains an authenticated and encrypted tunnel to the network, satisfying PCI DSS requirements for protecting cardholder data in transit. This workaround avoids the need to replace hardware while still enforcing access control.
Replacing all legacy phones is a hardware procurement action, not a workaround solution, and does not address the immediate compliance requirement.
Allowing fallback to TLS 1.0 violates PCI DSS requirements, as TLS 1.0 is explicitly prohibited under PCI DSS v3.2.1 and later due to known vulnerabilities such as POODLE.
Clear text password authentication provides no encryption and EAP-MD5 is considered cryptographically weak, both of which fail PCI security standards for network authentication.
Concept tested: Legacy device workarounds for PCI-compliant VPN authentication
Source: https://docs.cisco.com/en/cisco-secure-access-control/index.html
Topics
Community Discussion
No community discussion yet for this question.