Question 21

The lockout of an user ID should be set until an administrator re-enables the user or to a minimum of
  • Question 22

    Merchants with segmented payment application systems connected to the Internet, no electronic cardholder data storage, may be eligible to use what SAQ?
  • Question 23

    The presumption of P2PE is that:
  • Question 24

    Internal and external penetration tests should be performed_______________ to meet requirement
    1 1.3.1 and 11.3.2
  • Question 25

    A digital certificate is a valid for "something you have" as long as it is unique for a particular user.