& CORRECT ANSWERS
between all wireless networks and the CHD environment. - correct answer ✔✔Perimeter
firewalls installed ______________________________.
At each Internet connection and between any DMZ and the internal network. - correct answer
✔✔Where should firewalls be installed?
6 months - correct answer ✔✔Review of firewall and router rule sets at least every
__________________.
logical access must be managed separately and independently of native operating system
authentication and access control mechanisms - correct answer ✔✔If disk encryption is used
Split knowledge AND Dual control of keys - correct answer ✔✔Manual clear-text key-
management procedures specify processes for the use of the following:
Card verification value - correct answer ✔✔What is considered "Sensitive Authentication Data"?
first 6; last 4 - correct answer ✔✔When a PAN is displayed to an employee who does NOT need
to see the full PAN, the minimum digits to be masked are: All digits between the ___________
and the __________.
PAN must be rendered unreadable during the transmission over public and wireless networks. -
correct answer ✔✔Regarding protection of PAN...
, Hashing the entire PAN using strong cryptography - correct answer ✔✔Under requirement 3.4,
what method must be used to render the PAN unreadable?
WEP, SSL, and TLS 1.0 or earlier - correct answer ✔✔Weak security controls that should NOT be
used
on all system components commonly affected by malicious software. - correct answer ✔✔Per
requirement 5, anti-virus technology must be deployed_________________
1) Detect
2) Remove
3) Protect - correct answer ✔✔Key functions for anti-vius program per Requirement 5:
there is legitimate technical need, as authorized by management on a case-by-case basis -
correct answer ✔✔Anti-virus solutions may be temporarily disabled only if
1 month - correct answer ✔✔When to install "critical" applicable vendor-supplied security
patches? ---> within _________ of release.
within an appropriate time frame (for example, within three months). - correct answer
✔✔When to install applicable vendor-supplied security patches?
Reviewing software development policies and procedures - correct answer ✔✔When assessing
requirement 6.5, testing to verify secure coding techniques are in place to address common
coding vulnerabilities includes:
Need-to-know and least privilege - correct answer ✔✔Requirements 7 restricted access
controls by: