400-007 · Question #358
As a service provider is implementing Strong Access Control Measures, which two of the following PCI Data Security Standard requirements must be met? (Choose two.)
The correct answer is A. Assign a unique ID to each person with computer access E. Restrict access to cardholder data to on a need-to-know basis. PCI DSS groups its 12 requirements into six control objectives; 'Strong Access Control Measures' covers requirements 7, 8, and 9 - restricting need-to-know access and enforcing unique user identification.
Question
As a service provider is implementing Strong Access Control Measures, which two of the following PCI Data Security Standard requirements must be met? (Choose two.)
Options
- AAssign a unique ID to each person with computer access
- BEncrypt transmission of cardholder data across open or public networks
- CEach location must require validating PCI compliance if business has multiple locations
- DProtect stored cardholder data
- ERestrict access to cardholder data to on a need-to-know basis
How the community answered
(58 responses)- A91% (53)
- B3% (2)
- C3% (2)
- D2% (1)
Why each option
PCI DSS groups its 12 requirements into six control objectives; 'Strong Access Control Measures' covers requirements 7, 8, and 9 - restricting need-to-know access and enforcing unique user identification.
Requirement 8 of PCI DSS mandates that each individual with computer access be assigned a unique ID, preventing shared credentials and enabling accountability for all actions taken on cardholder data systems.
Encrypting transmission of cardholder data across open networks is Requirement 4, which falls under the 'Protect Cardholder Data' control objective - not 'Strong Access Control Measures'.
Validating PCI compliance at each business location is an organizational scoping consideration, not a standalone numbered PCI DSS requirement within the Strong Access Control Measures category.
Protecting stored cardholder data is Requirement 3, which belongs to the 'Protect Cardholder Data' control objective - a separate category from Strong Access Control Measures.
Requirement 7 of PCI DSS mandates restricting access to cardholder data on a need-to-know basis, ensuring that only authorized personnel with a legitimate business reason can access sensitive data.
Concept tested: PCI DSS Strong Access Control requirements 7 and 8
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.