Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 212-82 Topic 17 Question 51 Discussion

Actual exam question for Eccouncil's 212-82 exam
Question #: 51
Topic #: 17
[All 212-82 Questions]

Ayden works from home on his company's laptop. During working hours, he received an antivirus software update notification on his laptop. Ayden clicked on the update button; however, the system restricted the update and displayed a message stating that the update could only be performed by authorized personnel. Which of the following PCI-DSS requirements is demonstrated In this scenario?

Show Suggested Answer Hide Answer
Suggested Answer: A

PCI-DSS requirement no 5.3 is the PCI-DSS requirement that is demonstrated in this scenario. PCI-DSS (Payment Card Industry Data Security Standard) is a set of standards that applies to entities that store, process, or transmit payment card information, such as merchants, service providers, or payment processors. PCI-DSS requires them to protect cardholder data from unauthorized access, use, or disclosure. PCI-DSS consists of 12 requirements that are grouped into six categories: build and maintain a secure network and systems, protect cardholder data, maintain a vulnerability management program, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy. PCI-DSS requirement no 5.3 is part of the category ''maintain a vulnerability management program'' and states that antivirus mechanisms must be actively running and cannot be disabled or altered by users, unless specifically authorized by management on a case-by-case basis for a limited time period. In the scenario, Ayden works from home on his company's laptop. During working hours, he received an antivirus software update notification on his laptop. Ayden clicked on the update button; however, the system restricted the update and displayed a message stating that the update could only be performed by authorized personnel. This means that his company's laptop has an antivirus mechanism that is actively running and cannot be disabled or altered by users, which demonstrates PCI-DSS requirement no 5.3.


Contribute your Thoughts:

Lorrie
13 days ago
Haha, looks like Ayden's laptop is on lockdown! Probably a good thing, though, to prevent any unauthorized changes. I'd say the answer is B.
upvoted 0 times
...
Felix
15 days ago
This is a tricky one. I'm torn between B and D, but I'll go with D since the update notification seems to be coming from an external source.
upvoted 0 times
...
Willodean
1 months ago
I'm going with C. Ayden's company should have proper antivirus software in place to prevent malware infections, which is covered under PCI-DSS requirement 5.1.
upvoted 0 times
Hannah
19 days ago
User 2: I agree with Hannah. It makes sense that the system restricted the update in this case.
upvoted 0 times
...
Rocco
26 days ago
User 1: I think it's B. Only authorized personnel should be able to update software.
upvoted 0 times
...
...
Tasia
1 months ago
I'm not sure, but I think it could also be D) PCI-DSS requirement no 1.3.2, as it relates to restricting access to security parameters.
upvoted 0 times
...
Bobbye
1 months ago
I agree with Yong, because requirement 1.3.1 states that only authorized personnel should have access to security parameters.
upvoted 0 times
...
Oretha
2 months ago
Hmm, I think the answer is B. Restricting unauthorized updates sounds like a PCI-DSS requirement to protect the system from vulnerabilities.
upvoted 0 times
Shantell
20 days ago
User 2: Yeah, I think so too. It helps protect the system from potential vulnerabilities.
upvoted 0 times
...
Allene
29 days ago
User 1: I agree, B seems like the right answer. It's important to restrict unauthorized updates.
upvoted 0 times
...
...
Yong
2 months ago
I think the answer is B) PCI-DSS requirement no 1.3.1
upvoted 0 times
...

Save Cancel