nerdexam
CrowdStrike

CCCS-203B · Question #122

A company needs to ensure that its cloud environment aligns with PCI DSS (Payment Card Industry Data Security Standard) requirements. Which configuration should the company implement to meet…

The correct answer is D. Encrypt all sensitive data both at rest and in transit using strong cryptographic protocols. Option A: This is incorrect because publicly accessible storage creates a significant security risk and violates PCI DSS requirements for restricted access to sensitive data. Option B: This violates PCI DSS guidelines, which mandate unique credentials for each user to ensure…

Compliance and Regulatory Frameworks

Question

A company needs to ensure that its cloud environment aligns with PCI DSS (Payment Card Industry Data Security Standard) requirements. Which configuration should the company implement to meet compliance requirements?

Options

  • AStore sensitive data in publicly accessible cloud buckets.
  • BShare administrative credentials among multiple team members to enhance collaboration.
  • CAllow plaintext storage of sensitive customer payment data.
  • DEncrypt all sensitive data both at rest and in transit using strong cryptographic protocols.

How the community answered

(64 responses)
  • A
    3% (2)
  • B
    6% (4)
  • C
    2% (1)
  • D
    89% (57)

Explanation

Option A: This is incorrect because publicly accessible storage creates a significant security risk and violates PCI DSS requirements for restricted access to sensitive data. Option B: This violates PCI DSS guidelines, which mandate unique credentials for each user to ensure accountability and limit access to authorized personnel only. Sharing credentials undermines security and traceability. Option C: This violates PCI DSS requirements, which explicitly mandate the encryption of sensitive data to protect against unauthorized access. Plaintext storage is a major compliance Option D: This is the correct answer because PCI DSS mandates encryption of sensitive data to protect it from unauthorized access during storage and transmission. Strong encryption protocols (e.g., AES-256) are critical for ensuring compliance and mitigating risks of data breaches.

Topics

#PCI DSS#data encryption#compliance#cloud storage

Community Discussion

No community discussion yet for this question.

Full CCCS-203B Practice