PCI Network Security & Architecture 2 — Questions and Answers
Question 1: According to PCI DSS, how often must the configurations of network security controls be reviewed?
- Monthly
- Quarterly
- Every six months (Correct answer)
- Annually
Correct answer: Every six months
PCI DSS requires that network security control configurations, including firewall and router rule sets, be reviewed at least every six months to ensure they remain appropriate.
Question 2: What does PCI DSS require for outbound traffic originating from within the cardholder data environment?
- All outbound traffic must be encrypted with a minimum of TLS 1.2
- Outbound traffic must be restricted to only that which is necessary for business operations (Correct answer)
- All outbound sessions require explicit QSA approval before routing
- Outbound traffic controls are optional when inbound controls are sufficiently robust
Correct answer: Outbound traffic must be restricted to only that which is necessary for business operations
PCI DSS requires that outbound traffic from the CDE be restricted to only those communications necessary for the cardholder data environment to function, preventing unauthorized data exfiltration.
Question 3: Which of the following remote management protocols is PROHIBITED in a PCI DSS compliant environment?
- TLS 1.2 HTTPS management interface
- SSH version 2
- Telnet (Correct answer)
- SFTP
Correct answer: Telnet
Telnet transmits credentials and data in clear text, making it insecure and prohibited by PCI DSS; secure alternatives such as SSH must be used instead.
Question 4: What multi-factor authentication (MFA) requirement applies to remote access into the CDE under PCI DSS?
- MFA is only required for administrator accounts accessing the CDE remotely
- MFA is required only when connecting from an untrusted public network
- MFA must be used for all non-console remote access into the CDE (Correct answer)
- MFA is required for outbound internet access from within the CDE
Correct answer: MFA must be used for all non-console remote access into the CDE
PCI DSS Requirement 8 mandates MFA for all non-console administrative access and all remote access to the CDE, regardless of user role.
Question 5: What action must an organization take when a wireless network is detected near the CDE that was not authorized?
- Immediately decommission all wireless access points in the building
- Report the finding to the PCI SSC within 24 hours
- Document the network and notify management within 30 days
- Treat it as a potential security incident and follow incident response procedures (Correct answer)
Correct answer: Treat it as a potential security incident and follow incident response procedures
An unauthorized wireless network near the CDE is a potential intrusion or reconnaissance threat and must be handled under the organization's incident response plan.
Question 6: Under PCI DSS, what must be installed and active on mobile or employee-owned devices that are permitted to connect to the CDE or store cardholder data?
- Personal firewalls are optional if the device uses a VPN connection
- Personal firewalls must be installed and actively running on all such devices (Correct answer)
- Personal firewalls are only required when connecting via public Wi-Fi
- Mobile devices are completely prohibited from accessing the CDE under PCI DSS
Correct answer: Personal firewalls must be installed and actively running on all such devices
PCI DSS requires that personal firewall software be installed and active on any mobile or employee-owned devices that access the CDE or store cardholder data.
Question 7: How frequently does PCI DSS require organizations to test for unauthorized (rogue) wireless access points?
- Monthly
- At least quarterly (Correct answer)
- Annually
- Only when new wireless infrastructure is deployed
Correct answer: At least quarterly
PCI DSS requires that organizations test for the presence of unauthorized wireless access points and rogue devices at least quarterly using scanning methods or wireless IDS/IPS.
According to PCI DSS, how often must the configurations of network security controls be reviewed?