nerdexam
CompTIA

CAS-002 · Question #811

ABC Company must achieve compliance for PCI and SOX. Which of the following would BEST allow the organization to achieve compliance and ensure security? (Select THREE).

The correct answer is B. Establish a list of devices that must meet each regulation D. Compartmentalize the network F. Apply technical controls to meet compliance with the regulation. Achieving PCI and SOX compliance requires scoping devices under each regulation, segmenting the network to limit exposure, and applying technical controls that satisfy regulatory requirements.

Enterprise Security

Question

ABC Company must achieve compliance for PCI and SOX. Which of the following would BEST allow the organization to achieve compliance and ensure security? (Select THREE).

Options

  • AEstablish a list of users that must work with each regulation
  • BEstablish a list of devices that must meet each regulation
  • CCentralize management of all devices on the network
  • DCompartmentalize the network
  • EEstablish a company framework
  • FApply technical controls to meet compliance with the regulation

How the community answered

(45 responses)
  • A
    9% (4)
  • B
    84% (38)
  • C
    2% (1)
  • E
    4% (2)

Why each option

Achieving PCI and SOX compliance requires scoping devices under each regulation, segmenting the network to limit exposure, and applying technical controls that satisfy regulatory requirements.

AEstablish a list of users that must work with each regulation

User lists address access management but are not a primary compliance mechanism - device scoping and technical controls form the foundation of PCI and SOX compliance programs.

BEstablish a list of devices that must meet each regulationCorrect

Identifying which specific devices fall within the scope of PCI and SOX is foundational - compliance frameworks require a defined asset inventory so controls can be targeted and auditors can verify coverage.

CCentralize management of all devices on the network

Centralizing management of all devices would expand the compliance scope rather than reduce it, making it harder and more costly to achieve and maintain compliance.

DCompartmentalize the networkCorrect

Network compartmentalization (segmentation) limits the scope of regulated environments, reducing the attack surface and preventing lateral movement that could expose regulated data to out-of-scope systems.

EEstablish a company framework

A company framework alone is too vague and does not directly map to the specific technical and operational requirements mandated by PCI DSS or SOX.

FApply technical controls to meet compliance with the regulationCorrect

Technical controls such as encryption, access controls, and audit logging are the direct mechanisms that satisfy PCI DSS and SOX requirements and can be tested and verified by auditors.

Concept tested: PCI and SOX compliance scope and control implementation

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#SOX compliance#network segmentation#regulatory framework

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice