Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PCI QSA_New_V4 Exam - Topic 5 Question 24 Discussion

What should the assessor verify when testing that cardholder data Is protected whenever It Is sent over open public networks?
C) The security protocol accepts only trusted keys.
A) The security protocol Is configured to accept all digital certificates.
B) A proprietary security protocol is used.
D) The security protocol accepts connections from systems with lower encryption strength than required by the protocol.

PCI QSA_New_V4 Exam - Topic 5 Question 24 Discussion

Actual exam question for PCI's QSA_New_V4 exam
Question #: 24
Topic #: 5
[All QSA_New_V4 Questions]

What should the assessor verify when testing that cardholder data Is protected whenever It Is sent over open public networks?

Show Suggested Answer Hide Answer
Suggested Answer: C

Requirement for Secure Transmission:

PCI DSS Requirement 4.1 mandates that cardholder data sent over open public networks must be protected with strong cryptographic protocols. Accepting only trusted keys ensures data integrity and prevents unauthorized access.

Key Validation Practices:

Trusted keys and certificates are verified to ensure authenticity. Using untrusted keys compromises the security of the encrypted communication.

Prohibited Practices:

A/D: Configuring protocols to accept all certificates or lower encryption strength violates PCI DSS encryption guidelines.

B: Proprietary protocols are not inherently compliant unless they meet strong cryptographic standards.

Testing and Verification:

Assessors verify the implementation of trusted keys by examining encryption settings, reviewing certificate chains, and conducting tests to confirm only trusted connections are accepted.


Contribute your Thoughts:

0/2000 characters
Garry
2 days ago
A is risky. Accepting all certificates can lead to breaches.
upvoted 0 times
...
Malcom
7 days ago
Agreed! Without trusted keys, data is vulnerable.
upvoted 0 times
...
Renay
12 days ago
I think C is the best choice. Trusted keys are crucial.
upvoted 0 times
...
Margo
17 days ago
Not sure about this... Are we really trusting all these protocols?
upvoted 0 times
...
Alita
23 days ago
Wait, D sounds risky. Why allow lower encryption?
upvoted 0 times
...
Valentin
28 days ago
I think B is a bit sketchy, proprietary protocols can be untested.
upvoted 0 times
...
Julio
1 month ago
A is a bad idea, it opens up too many risks.
upvoted 0 times
...
Ma
1 month ago
Definitely C! Only trusted keys should be accepted.
upvoted 0 times
...
Son
1 month ago
D seems off, why allow lower encryption? That's a no-go!
upvoted 0 times
...
Winifred
2 months ago
I agree with C, gotta keep it tight with trusted keys.
upvoted 0 times
...
Marcos
2 months ago
Wait, B? A proprietary protocol? Sounds sketchy.
upvoted 0 times
...
Maira
2 months ago
A is a bad idea, accepting all certs is risky!
upvoted 0 times
...
Mertie
2 months ago
Definitely C, only trusted keys should be accepted.
upvoted 0 times
...
Alishia
2 months ago
I feel like option C makes the most sense since it directly relates to ensuring cardholder data is protected. I just hope I remember the details correctly during the exam!
upvoted 0 times
...
Chauncey
2 months ago
I’m a bit confused about whether a proprietary security protocol is actually a good choice. It seems risky, but I can't recall the specifics.
upvoted 0 times
...
Jerrod
3 months ago
I remember a practice question that emphasized the importance of not accepting connections from systems with lower encryption strength, so I think that's crucial here too.
upvoted 0 times
...
Elfrieda
4 months ago
I think the assessor should verify that the security protocol accepts only trusted keys, but I'm not entirely sure if that's the main focus.
upvoted 0 times
...

Save Cancel