Question 1
When evaluating "above and beyond" for compensating controls, an existing PCI DSS requirement MAY be considered as compensating controls if they are required for another area, but are not required for the item under review
Question 2
Internal and external vulnerability scans should run at minimum on every __________ to meet requirement 11.2
Question 3
PCI DSS Requirement 3.4 states that PAN must be rendered unreadable when stored. Which of the following may be used to meet this requirement?
Question 4
For initial PCI DSS compliance, it's not required that four quarters of passing scans must be completed if the assessor verifies that 1) the most recent scan result was a passing scan, 2) the entity has documented policies and procedures requiring quarterly scanning, and 3) vulnerabilities noted in the scan results have been corrected as shown in a re-scan(s).
Question 5
Users passwords/passphrases should be changed on a minimal of what interval to meet Requirement
8 .2.4?
8 .2.4?