To safeguard sensitive cardholder data during transmission over open networks, which of the following best describes the required control?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

To safeguard sensitive cardholder data during transmission over open networks, which of the following best describes the required control?

Explanation:
Protecting cardholder data in transit relies on strong cryptography applied through secure protocols. PCI DSS requires that any transmission of cardholder data over open networks be protected with strong cryptography and approved security protocols. The best way to describe the required control is to use the strongest available encryption, and apply it via robust protocols (such as TLS or IPsec) so the data remains unreadable to anyone intercepting the transmission. This emphasis on strength and using proven, current protocols is why the option stating to use the strongest available encryption, regardless of protocol, is the correct choice. In practice, this means avoiding deprecated or weak options like WEP and choosing modern, strong encryption with appropriate protocols. The other statements are too restrictive or incorrect: PCI does not mandate avoiding wireless networks entirely, WEP is not acceptable, and WEP with a strong password is still not acceptable.

Protecting cardholder data in transit relies on strong cryptography applied through secure protocols. PCI DSS requires that any transmission of cardholder data over open networks be protected with strong cryptography and approved security protocols. The best way to describe the required control is to use the strongest available encryption, and apply it via robust protocols (such as TLS or IPsec) so the data remains unreadable to anyone intercepting the transmission. This emphasis on strength and using proven, current protocols is why the option stating to use the strongest available encryption, regardless of protocol, is the correct choice. In practice, this means avoiding deprecated or weak options like WEP and choosing modern, strong encryption with appropriate protocols. The other statements are too restrictive or incorrect: PCI does not mandate avoiding wireless networks entirely, WEP is not acceptable, and WEP with a strong password is still not acceptable.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy