An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?
An LDAP server providing authentication services to the cardholder data environment is?
What is the intent of classifying media that contains cardholder data?
An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA, while also ensuring that the customized control is implemented securely. Which of the following statements is true?
Which of the following statements is true whenever a cryptographic key is retired and replaced with a new key?
Which of the following is true regarding compensating controls?
What would be an appropriate strength for the key-encrypting key (KEK) used to protect an AES 128-bit data-encrypting key (DEK)?
Which statement is true regarding the PCI DSS Report on Compliance (ROC)?
A "Partial Assessment" is a new assessment result. What is a “Partial Assessment"?
Which statement about the Attestation of Compliance (AOC) is correct?