nerdexam
CompTIA

PT0-002 · Question #588

An organization is required to undergo a penetration test to assess the segmentation of its network. Which of the following standards or regulations requires this type of testing?

The correct answer is C. PCI DSS. PCI DSS (Payment Card Industry Data Security Standard) requires organizations that handle credit card transactions to undergo regular penetration testing to assess the security of their networks. Specifically, Requirement 11.3 mandates segmentation testing to ensure that…

Planning and Scoping

Question

An organization is required to undergo a penetration test to assess the segmentation of its network. Which of the following standards or regulations requires this type of testing?

Options

  • AISSAF
  • BGDPR
  • CPCI DSS
  • DISO 27001

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    87% (34)
  • D
    3% (1)

Explanation

PCI DSS (Payment Card Industry Data Security Standard) requires organizations that handle credit card transactions to undergo regular penetration testing to assess the security of their networks. Specifically, Requirement 11.3 mandates segmentation testing to ensure that cardholder data environments (CDEs) are properly isolated from other parts of the network. This segmentation is crucial to reduce the scope of PCI compliance and protect sensitive payment

Topics

#Penetration Testing#Regulations#PCI DSS#Network Segmentation

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice