Which scenario meets PCI DSS requirements for critical systems to have correct and consistent time?
If an entity shares cardholder data with a TPSP, what activity is the entity required to perform'?
An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity's PCI DSS assessment?
An internal NTP server that provides time services to the Cardholder Data Environment is?
Which of the following parties is responsible for completion of the Controls Matrix for the Customized Approach?
An organization has implemented a change-detection mechanism on their systems. How often must critical file comparisons be performed?
Could an entity use both the Customized Approach and the Defined Approach to meet the same requirement?
A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has implemented a badge access-control system that identities who entered and exited the room on what date and at what time There are no video cameras located in the server room Based on this information, which statement is true regarding PCI DSS physical security requirements?
Which of the following describes the intent of installing one primary function per server?