Which of the following is true regarding network segmentation? ANS >>
Network Segmentation is not a PCI DSS requirement
When must critical security patches be installed ANS >> Within 1 month
Which statement is true for a merchant using a validated P2PE solution?
ANS >> The merchant is responsible for ensuring their own PCI compliance
Which of the following applications may go through a PA-DSS review?
ANS >> Commercial payment application without much customization
Strong access control lists include: ANS >> Don’t allow risky protocols
such as FTP or Telnet.