CAS-002 · Question #525
John is hosting several Web sites on a single server. One is an e-commerce site that handles credit card transactions, while the other sites do not handle credit card data. Does this present a…
The correct answer is C. Credit card processing requires PCI compliance, the other sites do not. PCI requirements are very specific. When commingling the different sites, they will all need to be Answer option B is incorrect. Credit cards require PCI compliance, not HIPAA. Answer option A is incorrect. There can be significant security concerns. Answer option D is…
Question
John is hosting several Web sites on a single server. One is an e-commerce site that handles credit card transactions, while the other sites do not handle credit card data. Does this present a security problem, and if so, what?
Options
- AThere is no issue with different types of sites on one server
- BCredit card processing requires HIPAA compliance, the other sites do not
- CCredit card processing requires PCI compliance, the other sites do not
- DThe other sites may allow privilege escalation to the e-commerce site
How the community answered
(38 responses)- A13% (5)
- B3% (1)
- C79% (30)
- D5% (2)
Explanation
PCI requirements are very specific. When commingling the different sites, they will all need to be Answer option B is incorrect. Credit cards require PCI compliance, not HIPAA. Answer option A is incorrect. There can be significant security concerns. Answer option D is incorrect. Privilege escalation is not the most significant concern.
Topics
Community Discussion
No community discussion yet for this question.