An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA, while also ensuring that the customized control is implemented securely. Which of the following statements is true?
An internal NTP server that provides time services to the Cardholder Data Environment is?
An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity’s PCI DSS assessment?
In the ROC Reporting Template, which of the following is the best approach for a response where the requirement was “In Place”?
Which of the following describes “stateful responses” to communication initiated by a trusted network?
An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?
In accordance with PCI DSS Requirement 10, how long must audit logs be retained?
An organization has implemented a change-detection mechanism on their systems. How often must critical file comparisons be performed?
Which of the following statements is true whenever a cryptographic key is retired and replaced with a new key?
If disk encryption is used to protect account data, what requirement should be met for the disk encryption solution?
PCI DSS Requirement 12.7 requires screening and background checks for which of the following?
An entity accepts e-commerce payment card transactions and stores account data in a database. The database server and the web server are both accessible from the Internet. The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements?
Which of the following describes the intent of installing one primary function per server?
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?