ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 459 - CAS-004 discussion

Report
Export

A company uses a CSP to provide a front end for its new payment system offering. The new offering is currently certified as PCI compliant. In order for the integrated solution to be compliant, the customer:

A.
must also be PCI compliant, because the risk is transferred to the provider.
Answers
A.
must also be PCI compliant, because the risk is transferred to the provider.
B.
still needs to perform its own PCI assessment of the provider's managed serverless service.
Answers
B.
still needs to perform its own PCI assessment of the provider's managed serverless service.
C.
needs to perform a penetration test of the cloud provider's environment.
Answers
C.
needs to perform a penetration test of the cloud provider's environment.
D.
must ensure in-scope systems for the new offering are also PCI compliant.
Answers
D.
must ensure in-scope systems for the new offering are also PCI compliant.
Suggested answer: D

Explanation:

Even though the company uses a cloud service provider (CSP) that is PCI compliant, the customer must still ensure that in-scope systems related to their new payment system offering are also PCI compliant. PCI DSS (Payment Card Industry Data Security Standard) applies to any system that processes, stores, or transmits credit card data, and this includes customer-owned systems, services, or applications integrated into the solution. The responsibility is shared between the CSP and the customer, and compliance is not automatically inherited just because the CSP is compliant. CASP+ emphasizes that organizations must ensure all components within their control are also PCI compliant.

CASP+ CAS-004 Exam Objectives: Domain 1.0 -- Risk Management (Compliance and PCI DSS)

CompTIA CASP+ Study Guide: Cloud Services and PCI Compliance

asked 02/10/2024
Kurt Woodfin
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first