PT0-002 · Question #588
An organization is required to undergo a penetration test to assess the segmentation of its network. Which of the following standards or regulations requires this type of testing?
The correct answer is C. PCI DSS. PCI DSS (Payment Card Industry Data Security Standard) requires organizations that handle credit card transactions to undergo regular penetration testing to assess the security of their networks. Specifically, Requirement 11.3 mandates segmentation testing to ensure that…
Question
An organization is required to undergo a penetration test to assess the segmentation of its network. Which of the following standards or regulations requires this type of testing?
Options
- AISSAF
- BGDPR
- CPCI DSS
- DISO 27001
How the community answered
(39 responses)- A3% (1)
- B8% (3)
- C87% (34)
- D3% (1)
Explanation
PCI DSS (Payment Card Industry Data Security Standard) requires organizations that handle credit card transactions to undergo regular penetration testing to assess the security of their networks. Specifically, Requirement 11.3 mandates segmentation testing to ensure that cardholder data environments (CDEs) are properly isolated from other parts of the network. This segmentation is crucial to reduce the scope of PCI compliance and protect sensitive payment
Topics
Community Discussion
No community discussion yet for this question.