Non-console administrator access to any web-based management interfaces must
be encrypted with technology such as ........ - ANSWER- HTTPS
Requirements 2.2.2 and 2.2.3 cover the use of secure services, protocols and
d
...
Non-console administrator access to any web-based management interfaces must
be encrypted with technology such as ........ - ANSWER- HTTPS
Requirements 2.2.2 and 2.2.3 cover the use of secure services, protocols and
daemons. Which of the following is considered to be secure? - ANSWER- SSH
Which of the following is considered "Sensitive Authentication Data"? -
ANSWER- Card Verification Value (CAV2/CVC2/CVV2/CID), Full Track Data,
PIN/PIN Block
True or False: It is acceptable for merchants to store Sensitive Authentication after
authorization as long as it is strongly encrypted? - ANSWER- False
When a PAN is displayed to an employee who does NOT need to see the full PAN,
the minimum digits to be masked are: - ANSWER- All digits between the first six
and last four
Which of the following is true regarding protection of PAN? - ANSWER- PAN
must be rendered unreadable during transmission over public, wireless networks
Which of the following may be used to render PAN unreadable in order to meet
requirement 3.4? - ANSWER- Hashing the entire PAN using strong cryptography
True or False Where keys are stored on production systems, split knowledge and
dual control is required? - ANSWER- True
When assessing requirement 6.5, testing to verify secure coding techniques are in
place to address common coding vulnerabilities includes: - ANSWER- Reviewing
software development policies and procedures
One of the principles to be used when granting user access to systems in CDE is: -
ANSWER- Least privilege
An example of a "one-way" cryptographic function used to render data unreadable
is: - ANSWER- SHA-2
[Show More]