A penetration test reveals that a developer has retained production CDE access after moving to a QA role. Which PCI DSS process failed?
-
A
Vulnerability scanning schedule
-
B
Periodic user access review or termination/transfer access revocation process
-
C
Firewall rule review
-
D
Incident response plan