An entity accepts e-commerce payment card transactions and stores account data in a database. The database server and the web server are both accessible from the Internet. The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements?
A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has implemented a badge access-control system that identifies who entered and exited the room, on what date, and at what time. There are no video cameras located in the server room. Based on this information, which statement is true regarding PCI DSS physical security requirements?
If segmentation is being used to reduce the scope of a PCI DSS assessment, the assessor will?
If an entity shares cardholder data with a TPSP, what activity is the entity required to perform?
An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?
Which scenario meets PCI DSS requirements for critical systems to have correct and consistent time?
Which of the following parties is responsible for completion of the Controls Matrix for the Customized Approach?