Which statement is NOT a PCI compliance recommendation?

Study for the EC-Council Certified Ethical Hacker (CEH) v13 Exam. Utilize flashcards and multiple-choice questions with helpful hints and detailed explanations. Excel in your exam preparation!

Multiple Choice

Which statement is NOT a PCI compliance recommendation?

Explanation:
PCI DSS focuses on protecting cardholder data through strong access controls, data protection, and ongoing network monitoring. Rotating employees handling card transactions among different departments isn’t a PCI requirement; PCI emphasizes ensuring access is restricted to those with a business need (least privilege) and that access rights are reviewed, but it doesn’t mandate annual cross-department rotations. In contrast, the other three practices align directly with PCI guidance: applying least-privilege access so users only have the minimum rights needed; encrypting cardholder data in transit and at rest to keep data unreadable even if intercepted or accessed; and regularly monitoring and testing networks to identify and address security weaknesses. Therefore, rotating staff is not a PCI compliance recommendation, while the others are.

PCI DSS focuses on protecting cardholder data through strong access controls, data protection, and ongoing network monitoring. Rotating employees handling card transactions among different departments isn’t a PCI requirement; PCI emphasizes ensuring access is restricted to those with a business need (least privilege) and that access rights are reviewed, but it doesn’t mandate annual cross-department rotations. In contrast, the other three practices align directly with PCI guidance: applying least-privilege access so users only have the minimum rights needed; encrypting cardholder data in transit and at rest to keep data unreadable even if intercepted or accessed; and regularly monitoring and testing networks to identify and address security weaknesses. Therefore, rotating staff is not a PCI compliance recommendation, while the others are.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy