When implementing ACLs for PCI-DSS compliance, which traffic restriction is mandatory for the cardholder data environment (CDE)?
-
A
Allow all inbound traffic and log it
-
B
Restrict inbound and outbound traffic to only what is necessary
-
C
Block only inbound traffic from untrusted networks
-
D
Allow all internal traffic and block only external traffic