For wireless environments connected to the cardholder data environment, what action is required at installation?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

For wireless environments connected to the cardholder data environment, what action is required at installation?

Explanation:
When configuring wireless devices that connect to the cardholder data environment, you must start with secure, non-default settings. Vendor defaults are widely known and easy for attackers to guess or obtain, so leaving any default in place creates an open door into the network and, potentially, the CHD. Changing just one piece, like the wireless password, leaves other critical defaults—such as encryption keys and SNMP community strings—exposed and usable for unauthorized access or remote management. There’s no requirement to abandon wireless in favor of wired, so the correct approach is to replace all vendor defaults during installation, covering keys, passwords, and SNMP strings, to establish a solid, non-default baseline from the start.

When configuring wireless devices that connect to the cardholder data environment, you must start with secure, non-default settings. Vendor defaults are widely known and easy for attackers to guess or obtain, so leaving any default in place creates an open door into the network and, potentially, the CHD. Changing just one piece, like the wireless password, leaves other critical defaults—such as encryption keys and SNMP community strings—exposed and usable for unauthorized access or remote management. There’s no requirement to abandon wireless in favor of wired, so the correct approach is to replace all vendor defaults during installation, covering keys, passwords, and SNMP strings, to establish a solid, non-default baseline from the start.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy