PCI Network Security & Architecture 1 — Questions and Answers
Question 1: What is the primary focus of PCI DSS Requirement 1?
- Encryption of stored cardholder data at rest
- Installing and maintaining network security controls (Correct answer)
- Restricting physical access to cardholder data
- Tracking and monitoring all network access
Correct answer: Installing and maintaining network security controls
PCI DSS Requirement 1 specifically addresses the installation and maintenance of network security controls to protect the cardholder data environment.
Question 2: Under PCI DSS, what is required between the internet and the cardholder data environment (CDE)?
- A dedicated VPN tunnel encrypting all traffic
- End-to-end encryption of all packets
- A DMZ with network security controls on both sides (Correct answer)
- A single stateful-inspection firewall
Correct answer: A DMZ with network security controls on both sides
PCI DSS requires a DMZ with network security controls between the internet and the DMZ, and between the DMZ and the CDE, providing layered protection.
Question 3: Which wireless encryption protocol does PCI DSS prohibit due to well-known cryptographic weaknesses?
- WPA3-Enterprise
- WPA2 with AES-CCMP
- WEP (Wired Equivalent Privacy) (Correct answer)
- 802.1X with EAP-TLS
Correct answer: WEP (Wired Equivalent Privacy)
WEP has fundamental cryptographic flaws that allow attackers to recover the encryption key within minutes, making it prohibited under PCI DSS.
Question 4: What must be included in network diagrams maintained for PCI DSS compliance?
- Only external-facing network components
- Only servers that store cardholder data
- All wireless networks and their connection to the CDE
- All network connections and all cardholder data flows (Correct answer)
Correct answer: All network connections and all cardholder data flows
PCI DSS requires comprehensive network diagrams showing all connections between system components and all cardholder data flows within the CDE.
Question 5: Under PCI DSS, which traffic rule principle must all network security controls protecting the CDE enforce?
- Allow all traffic and log exceptions
- Source IP verification before permitting any traffic
- Implicit deny — block all traffic not explicitly permitted (Correct answer)
- Rate-limiting of all inbound connections
Correct answer: Implicit deny — block all traffic not explicitly permitted
PCI DSS requires an implicit deny posture, meaning only explicitly authorized traffic is allowed and everything else is blocked by default.
Question 6: What is the PCI DSS requirement regarding vendor default settings for newly deployed network devices?
- Defaults may be kept if the device is behind the CDE perimeter
- All vendor-supplied defaults must be changed before deployment (Correct answer)
- Vendor defaults must be documented and approved by a QSA
- Changing defaults is only required for wireless devices
Correct answer: All vendor-supplied defaults must be changed before deployment
PCI DSS Requirement 2 mandates that all vendor-supplied defaults — including passwords and security parameters — must be changed before any system is placed in production.
Question 7: How does network segmentation primarily benefit a PCI DSS compliance program?
- It eliminates the need to encrypt stored cardholder data
- It permits the use of legacy security protocols within isolated segments
- It reduces the scope of the PCI DSS assessment (Correct answer)
- It satisfies all controls required under PCI DSS Requirement 6
Correct answer: It reduces the scope of the PCI DSS assessment
Effective network segmentation isolates the CDE from other networks, reducing the number of system components subject to PCI DSS assessment and thereby shrinking compliance scope.
What is the primary focus of PCI DSS Requirement 1?