According to the PCI DSS v3.2.1 Quick Reference Guide1, the same AOC template is used for ROCs and SAQs. This is one of the requirements for ensuring consistency and accuracy in ROCs and SAQs.
Question 2
An organization has implemented a change-detection mechanism on their systems. How often must critical file comparisons be performed?
Options:
A.
At least weekly
B.
Periodically as defined by the entity
C.
Only after a valid change is installed
D.
At least monthly
Answer:
A
Explanation:
Explanation:
PCI DSS Requirement 11.5 states that entities must deploy a change-detection mechanism (for example, file-integrity monitoring tools) to alert personnel to unauthorized modification of critical system files, configuration files, or content files; and configure the software to perform critical file comparisons at least weekly1. This is to ensure that any unauthorized or malicious changes to the files are detected and reported in a timely manner, and that the integrity and security of the files are maintained. Critical files are those that affect the security of the cardholder data environment (CDE), such as system files, application executables, configuration files, database files, and log files2. Therefore, the correct answer is option A.
The other options are not true regarding the frequency of critical file comparisons for a change-detection mechanism. Option B is not true because PCI DSS does not allow the entity to define the periodicity of the file comparisons, as it specifies a minimum frequency of at least weekly1. Option C is not true because PCI DSS does not limit the file comparisons to only after a valid change is installed, as it requires the file comparisons to be performed at least weekly regardless of the change status1. Option D is not true because PCI DSS does not allow the file comparisons to be performed at least monthly, as it requires a higher frequency of at least weekly1. References:
PCI DSS v3.2.1
File Integrity Monitoring Tools For PCI DSS
Question 3
What is the intent of classifying media that contains cardholder data?
Options:
A.
Ensuring that media is property protected according to the sensitivity of the data it contains
B.
Ensuring that media containing cardholder data is moved from secured areas an a quarterly basis
C.
Ensuring that media is clearly and visibly labeled as 'Confidential so all personnel know that the media contains cardholder data
D.
Ensuring that all media is consistently destroyed on the same schedule regardless of the contents
Answer:
A
Explanation:
Explanation:
classifying media that contains cardholder data is intended to ensure that media is property protected according to the sensitivity of the data it contains, which means it should be markedwith labels or tags that indicate its level of confidentiality or integrity. This is one of the requirements for ensuring that media containing cardholder data is properly labeled.