nerdexam
CompTIA

CAS-003 · Question #666

An e-commerce company that provides payment gateways is concerned about the growing expense and time associated with PCI audits of its payment gateways and external audits by customers for their own…

The correct answer is C. Undertake ISO certification for all core infrastructure including datacenters. E. Implement DLP controls on HTTP'HTTPS and email. ISO 27001 certification (C) provides a recognized third-party attestation of security controls, which can satisfy many customers' own compliance audit requirements without requiring separate engagements - directly reducing the number and cost of external audits. Implementing…

Risk Management

Question

An e-commerce company that provides payment gateways is concerned about the growing expense and time associated with PCI audits of its payment gateways and external audits by customers for their own compliance reasons. The Chief Information Officer (CIO) asks the security team to provide a list of options that will: 1. Reduce the overall cost of these audits 2. Leverage existing infrastructure where possible 3. Keep infrastructure costs to a minimum 4. Provide some level of attestation of compliance Which of the following will BEST address the CIO"s concerns? (Select TWO)

Options

  • AInvest in new UBA to detect report, and remediate attacks faster
  • BSegment the network to reduce and limit the audit scope
  • CUndertake ISO certification for all core infrastructure including datacenters.
  • DImplement a GRC system to track and monitor controls
  • EImplement DLP controls on HTTP'HTTPS and email
  • FInstall EDR agents on all corporate endpoints

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    62% (23)
  • D
    8% (3)
  • F
    22% (8)

Explanation

ISO 27001 certification (C) provides a recognized third-party attestation of security controls, which can satisfy many customers' own compliance audit requirements without requiring separate engagements - directly reducing the number and cost of external audits. Implementing DLP controls on HTTP/HTTPS and email (E) enforces data protection policies over existing network infrastructure, minimizing infrastructure costs while addressing PCI DSS cardholder data protection requirements. Together, they reduce audit burden, leverage existing infrastructure, and provide attestation. Note: Network segmentation (B) is also commonly cited for reducing PCI DSS scope, but the combination of ISO attestation and DLP aligns more specifically with all four of the CIO's stated goals.

Topics

#PCI-DSS#audit scope reduction#compliance attestation#ISO certification

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice