nerdexam
EC-Council

712-50 · Question #112

When working in the Payment Card Industry (PCI), how often should security logs be review to comply with the standards?

The correct answer is A. Daily. PCI DSS Requirement 10.6 mandates that security logs must be reviewed daily to detect and respond to anomalies, unauthorized access, and suspicious activity in a timely manner. Hourly (B) exceeds the standard's requirement and is not specified - while more frequent review isn't…

Governance (Policy, Legal & Compliance)

Question

When working in the Payment Card Industry (PCI), how often should security logs be review to comply with the standards?

Options

  • ADaily
  • BHourly
  • CWeekly
  • DMonthly

How the community answered

(46 responses)
  • A
    76% (35)
  • B
    7% (3)
  • C
    4% (2)
  • D
    13% (6)

Explanation

PCI DSS Requirement 10.6 mandates that security logs must be reviewed daily to detect and respond to anomalies, unauthorized access, and suspicious activity in a timely manner. Hourly (B) exceeds the standard's requirement and is not specified - while more frequent review isn't prohibited, it's not the compliance baseline. Weekly (C) and Monthly (D) are far too infrequent and would leave critical security events undetected for dangerous periods, violating the intent of continuous monitoring under PCI DSS.

Memory tip: Think "Daily = Data protection" - in PCI, cardholder data is at stake every day, so logs must be checked every day. The "D" in DSS can remind you of Daily.

Topics

#PCI DSS#Log Management#Compliance Requirements#Security Monitoring

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice