nerdexam
(ISC)2

CISSP · Question #174

A business has implemented Payment Card Industry Data Security Standard (PCI-DSS) compliant handheld credit card processing on their Wireless Local Area Network (WLAN) topology. The network team parti

The correct answer is C. The end devices, wireless access points, WLAN, switches, management console, and firewall.. The components that are in the scope of PCI-DSS are the end devices, wireless access points, WLAN, switches, management console, and firewall. PCI-DSS is a set of standards and requirements that aim to ensure the security of the cardholder data and the payment transactions. PCI-D

Submitted by lars.no· Mar 5, 2026Communication and Network Security

Question

A business has implemented Payment Card Industry Data Security Standard (PCI-DSS) compliant handheld credit card processing on their Wireless Local Area Network (WLAN) topology. The network team partitioned the WLAN to create a private segment for credit card processing using a firewall to control device access and route traffic to the card processor on the Internet. What components are in the scope of PCI-DSS?

Options

  • AThe entire enterprise network infrastructure.
  • BThe handheld devices, wireless access points and border gateway.
  • CThe end devices, wireless access points, WLAN, switches, management console, and firewall.
  • DThe end devices, wireless access points, WLAN, switches, management console, and Internet

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    84% (32)
  • D
    5% (2)

Explanation

The components that are in the scope of PCI-DSS are the end devices, wireless access points, WLAN, switches, management console, and firewall. PCI-DSS is a set of standards and requirements that aim to ensure the security of the cardholder data and the payment transactions. PCI-DSS applies to any entity that stores, processes, or transmits cardholder data, or that provides services or devices that affect the security of the cardholder data. The scope of PCI- DSS includes all the system components that are connected to or support the cardholder data environment, such as the hardware, the software, the network, or the personnel. In this question, the end devices, wireless access points, WLAN, switches, management console, and firewall are all part of the system components that are connected to or support the cardholder data environment, as they are used to process the credit card transactions on the WLAN. Therefore, they are in the scope of PCI-DSS, and they must comply with the PCI-DSS requirements. The entire enterprise network infrastructure and the Internet are not in the scope of PCI-DSS, as they are not directly connected to or support the cardholder data environment, and they are separated from the private segment for credit card processing by the firewall. The border gateway is not a system component, but a term that refers to a device that connects two networks with different protocols, such as a router or a proxy server.

Topics

#PCI-DSS#network segmentation#compliance scoping#wireless security

Community Discussion

No community discussion yet for this question.

Full CISSP Practice