Q: 2
The Payment Card Industry Data Security Standard (PCI DSS) contains six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to achieve compliance. Which of the following requirements would best fit under the objective, "Implement strong access control measures"?
Options
Discussion
C . Unique IDs are access control basics for PCI DSS.
Nah, it's not A here. C is the requirement that matches strong access control, since unique IDs tie to authentication. Sometimes B trips people up but that's encryption, not access control.
C . Assigning a unique ID to each user is a textbook access control move, which lines up exactly with PCI DSS's "strong access control" goals. B focuses on encryption for data in transit, not really about managing access itself. Pretty confident it's C but if anyone has seen PCI DSS group these differently, chime in.
C . Assigning a unique ID lines up best with strong access control for PCI DSS. The rest fit other objectives more closely.
C imo. Assigning unique IDs is classic access control per PCI DSS objectives. Official study guide and practice questions both highlight this as key. Not 100 percent but seems most direct fit.
C , I remember a similar scenario from labs. Assigning a unique ID directly supports strong access control since it helps you identify and track users. The others focus more on system or data security than user-level access. If someone disagrees, happy to hear it but this lines up with PCI DSS.
Assigning a unique ID to each person lines up with access control since you want individual accountability. That's why I'd go with C here. Other options deal more with system security or data protection, not really controlling who can get in. Pretty sure that's how PCI frames it, but correct me if I'm off.
I don’t think it’s D, that’s more about malware control. C is the one tied to strong access controls since assigning unique IDs is all about tracking who can get into systems. Saw similar wording in practice, B is tempting but that’s encryption, not access control. Let me know if you see it another way.
A is wrong, C. No extra reason, just fits that access control piece best.
C/D? Pretty common to see D picked for access control since anti-virus seems like it protects the system, but PCI DSS usually puts that under another objective.
Be respectful. No spam.