What should the assessor verify when testing that cardholder data is protected whenever it is sent over open public networks?

What should the assessor verify when testing that cardholder data is protected whenever it is sent over open public networks?
A . The security protocol is configured to accept all digital certificates
B . A proprietary security protocol is used
C . The security protocol accepts only trusted keys
D . The security protocol accepts connections from systems with lower encryption strength than
required by the protocol

Answer: C

Explanation:

According to the PCI DSS v3.2.1 Quick Reference Guide1, the security protocol accepts only trusted keys. This is one of the requirements for ensuring secure encryption and authentication.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments