Questions and Correct Detailed Answers Already
Graded A+
Perimeter firewalls installed ______________________________. - CORRECT
ANSWER-between all wireless networks and the CHD environment.
Where should firewalls be installed? - CORRECT ANSWER-At each Internet
connection and between any DMZ and the internal network.
Key Management documentation must specifies the following: - CORRECT
ANSWER-Procedures to:
1. Generate strong keys
2. Securely distribute keys
3. Securely store keys
4. Defined cryptoperiod
PAN must be - CORRECT ANSWER-render unreadable during transmission over
PUBLIC wireless network.
,Split knowledge - CORRECT ANSWER-Two or more entities need to separately
have key components that individually convey no knowledge of the resultant
cryptographic key
Dual control - CORRECT ANSWER-Required the present of two individuals to
perform a task
Critical vendor supplied patches should be installed within_______________. -
CORRECT ANSWER-1 month
What is the proper handling of displaying an error message? - CORRECT
ANSWER-by returning generic rather than specific error details (to not leak too
much information about the system)
For public web facing application, do we use both or either one of these
methods?
1) Use either manual or automated vulnerability security assessment tools or
methods at least annually and after any changes.
, 2) Use of automated technical solution that detects and prevents web-based
attacks (WAP) - CORRECT ANSWER-Either One
Req 7.1 - Limited access to what user roles based on _______________. -
CORRECT ANSWER-Least privileges and need-to-know basis based on job
functions.
Req 7.2 - Access control system must be set to _____________ by default. -
CORRECT ANSWER-deny-all
Multi-factor authentication is required for: ______________________ and
_________. - CORRECT ANSWER-All remote access by personnel (user and
administrator) and all third-party/vendor remote access
An example of a "one-way" cryptographic function used to render data
unreadable is: - CORRECT ANSWER-SHA-2
Req 10.4: Time-synchronization technology - What type of server is required to
receives time signals from external sources, and time signals from external
sources are based on International Atomic Time or UTC. - CORRECT ANSWER-
Central time server(s)