ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 239 - PT0-002 discussion

Report
Export

During an internal penetration test against a company, a penetration tester was able to navigate to another part of the network and locate a folder containing customer information such as addresses, phone numbers, and credit card numbers. To be PCI compliant, which of the following should the company have implemented to BEST protect this data?

A.
Vulnerability scanning
Answers
A.
Vulnerability scanning
B.
Network segmentation
Answers
B.
Network segmentation
C.
System hardening
Answers
C.
System hardening
D.
Intrusion detection
Answers
D.
Intrusion detection
Suggested answer: B

Explanation:

Network segmentation is the practice of dividing a network into smaller subnetworks or segments based on different criteria, such as function, security level, or access control. Network segmentation can enhance the security of a network by isolating sensitive or critical systems from less secure or untrusted systems, reducing the attack surface, limiting the spread of malware or intrusions, and enforcing granular policies and rules for each segment. To be PCI compliant, which is a set of standards for protecting payment card data, the company should have implemented network segmentation to separate the servers that perform financial transactions from other parts of the network that may be less secure or more exposed to threats. The other options are not specific requirements for PCI compliance, although they may be good security practices in general.

asked 02/10/2024
Malik Spamu
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first