Which network segmentation approach most effectively reduces PCI DSS scope by isolating the cardholder data environment (CDE)?
-
A
Using VLANs alone to separate CDE traffic
-
B
Implementing firewall-enforced network segmentation with documented access controls
-
C
Placing all servers on a single flat network with host-based firewalls only
-
D
Using MAC address filtering to restrict CDE access