Which of the following file types must be monitored by a change-detection mechanism (for example, a file-integrity monitoring tool)?
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?
A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has Implemented a badge access-control system that Identifies who entered and exited the room, on what date, and at what time. There are no video cameras located in the server room.Based on this information, which statement is true regarding PCI DSS physical security requirements?
An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA, while also ensuring that the customized control is implemented securely. Which of the following statements is true?
An LDAP server providing authentication services to the cardholder data environment is_____________?
Which statement is true regarding the presence of both hashed and truncated versions of the same PAN in an environment?