If a session is idle for more than 15 minutes, what should happen?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

If a session is idle for more than 15 minutes, what should happen?

Explanation:
Session management through idle-time re-authentication helps protect cardholder data by ensuring that an unattended workstation cannot be misused. When a user session sits idle for 15 minutes, requiring them to re-authenticate to re-activate confirms the current user is still legitimately active and prevents someone else from taking over an open session. This tightens protection against session hijacking and accidental exposure when devices are left unattended. The other options either delay re-authentication too long, claim no re-auth is needed, or require re-authentication after an even longer period, all of which increase risk. So, re-authenticate after 15 minutes of inactivity.

Session management through idle-time re-authentication helps protect cardholder data by ensuring that an unattended workstation cannot be misused. When a user session sits idle for 15 minutes, requiring them to re-authenticate to re-activate confirms the current user is still legitimately active and prevents someone else from taking over an open session. This tightens protection against session hijacking and accidental exposure when devices are left unattended. The other options either delay re-authentication too long, claim no re-auth is needed, or require re-authentication after an even longer period, all of which increase risk. So, re-authenticate after 15 minutes of inactivity.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy