Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?
An entity accepts e-commerce payment card transactions and stores account data in a database The database server and the web server are both accessible from the Internet The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements7
What must the assessor verify when testing that PAN is protected whenever it is sent over the Internet?
What should the assessor verify when testing that cardholder data is protected whenever it is sent over open public networks?
Which of the following describes "stateful responses' to communication initiated by a trusted network?
Which of the following parties is responsible for completion of the Controls Matrix for the Customized Approach?
Which statement is true regarding the presence of both hashed and truncated versions of the same PAN in an environment?
PCI DSS Requirement 12.7 requires screening and background checks for which of the following?
An LDAP server providing authentication services to the cardholder data environment is
An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?