exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 157 discussion

Actual exam question from CompTIA's PT0-002
Question #: 157
Topic #: 1
[All PT0-002 Questions]

PCI DSS requires which of the following as part of the penetration-testing process?

  • A. The penetration tester must have cybersecurity certifications.
  • B. The network must be segmented.
  • C. Only externally facing systems should be tested.
  • D. The assessment must be performed during non-working hours.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Random_Mane
Highly Voted 2 years, 7 months ago
Selected Answer: B
PCI DSS most certainly requires segmentation. PCI DSS Requirement 11.3.4 requires penetration testing to validate that segmentation controls and methods are operational, effective, and isolate all out-of-scope systems from systems in the CDE. 2.2.3 Testing Segmentation Controls The intent of segmentation is to prevent out-of-scope systems from being able to communicate with systems in the CDE or impact the security of the CDE. When properly implemented, a segmented (out-ofscope) system component could not impact the security of the CDE, even if an attacker obtained control of the out-of-scope system
upvoted 11 times
...
ryanzou
Highly Voted 2 years, 9 months ago
I think B is correct
upvoted 6 times
...
Etc_Shadow28000
Most Recent 1 year ago
Selected Answer: B
B. The network must be segmented. Explanation: B. The network must be segmented: • PCI DSS Requirement 11.3 specifies that penetration testing must be conducted to identify and exploit vulnerabilities that could be used to compromise the security of the cardholder data environment (CDE). One of the key requirements is to ensure that the CDE is segmented from other networks to reduce the scope of PCI DSS requirements and limit exposure.
upvoted 1 times
...
mehewas855
1 year, 7 months ago
Selected Answer: B
I think it is B not A because - Certifications held by a penetration tester may be an indication of the skill level and competence of a potential penetration tester or company. While these are not required certifications, they can indicate a common body of knowledge held by the candidate. not C - pentest should also assess internal systems to be sure, that it does not contain hidden vulnerabilities not D - time is part of the a agreement, PCI does not specify time
upvoted 1 times
...
solutionz
1 year, 11 months ago
Selected Answer: B
The Payment Card Industry Data Security Standard (PCI DSS) outlines various requirements for protecting cardholder data. Among the options listed, the one that aligns with PCI DSS as part of the penetration-testing process is: B. The network must be segmented. Explanation: Option B: Network segmentation is a common practice to isolate different parts of the network and minimize the risk of unauthorized access to sensitive areas, such as those that handle cardholder data. PCI DSS requires network segmentation as a way to reduce the scope of the PCI environment, making it easier to secure and comply with the standard.
upvoted 1 times
...
KingIT_ENG
2 years, 4 months ago
Answer B segmentation is very importent part of pentest
upvoted 2 times
...
nickwen007
2 years, 4 months ago
The best answer is C. PCI DSS requires that only externally facing systems should be tested as part of the penetration-testing process.
upvoted 1 times
[Removed]
2 years, 4 months ago
https://www.google.com/url?sa=t&source=web&rct=j&url=https://www.tevora.com/blog/understanding-pci-penetration-testing-and-vulnerability-scanning-requirements/&ved=2ahUKEwjChb2O-dD9AhXJ-KQKHSv8BPkQFnoECDAQAQ&usg=AOvVaw3H5-3THtNlpcDigpoR11ZG B is the answer
upvoted 2 times
...
[Removed]
2 years, 4 months ago
B is correct The network must be segmented check the book
upvoted 2 times
...
KingIT_ENG
2 years, 4 months ago
C is incorrect B is the correct answer
upvoted 2 times
...
...
kloug
2 years, 5 months ago
bbbbbbbbb
upvoted 3 times
...
[Removed]
2 years, 5 months ago
B is correct
upvoted 1 times
...
masso435
2 years, 7 months ago
Selected Answer: A
The network doesn't have to be segmented. It has to be both internal and external. It doesn't the time of day.
upvoted 1 times
Mr_BuCk3th34D
2 years, 6 months ago
You're incorrect. Segmentation is one of the most important aspects of PCI compliance.
upvoted 5 times
...
[Removed]
2 years, 6 months ago
Having internal and external networks means it is segmented lol.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...