List of questions
Related questions
Question 459 - CAS-004 discussion
A company uses a CSP to provide a front end for its new payment system offering. The new offering is currently certified as PCI compliant. In order for the integrated solution to be compliant, the customer:
A.
must also be PCI compliant, because the risk is transferred to the provider.
B.
still needs to perform its own PCI assessment of the provider's managed serverless service.
C.
needs to perform a penetration test of the cloud provider's environment.
D.
must ensure in-scope systems for the new offering are also PCI compliant.
Your answer:
0 comments
Sorted by
Leave a comment first