What does requirement 1.3 prohibit?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

What does requirement 1.3 prohibit?

Explanation:
Requirement 1.3 is about not letting the Internet reach any system component that stores, processes, or transmits cardholder data directly. The cardholder data environment must be protected by a defined boundary—firewalls, and when appropriate a DMZ or other controls—so that all Internet traffic to CCDE components goes through those controls rather than directly hitting the systems themselves. That’s why prohibiting direct public access from the Internet to any CCDE component is the best description of what this requirement enforces. The other options describe different boundary scenarios that don’t capture the specific prohibition on direct Internet exposure to CCDE systems.

Requirement 1.3 is about not letting the Internet reach any system component that stores, processes, or transmits cardholder data directly. The cardholder data environment must be protected by a defined boundary—firewalls, and when appropriate a DMZ or other controls—so that all Internet traffic to CCDE components goes through those controls rather than directly hitting the systems themselves. That’s why prohibiting direct public access from the Internet to any CCDE component is the best description of what this requirement enforces. The other options describe different boundary scenarios that don’t capture the specific prohibition on direct Internet exposure to CCDE systems.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy