ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your organization, a PCI DSS compliant e-commerce provider, is migrating from version 3.2.1 to PCI DSS 4.0, which now explicitly requires TLS 1.2 or higher for cardholder data in transit. Which update to the continuous monitoring program best satisfies this new requirement?
Require quarterly user access reviews for all privileged accounts with cardholder data access.
Extend retention of web server logs from 90 to 365 days to support forensic investigations.
Integrate automated scanning that validates active cipher suites and flags any outbound session using TLS 1.1 or lower.
Increase malware signature update frequency on payment servers from weekly to daily.
Because PCI DSS 4.0 raises the minimum acceptable protocol version to TLS 1.2, the monitoring strategy must be able to detect any data-in-transit that does not use that level of encryption. Adding automated checks that inventory active cipher suites and generate alerts whenever outbound sessions rely on TLS 1.1 or older directly measures compliance with the new control objective. The other actions-more frequent malware-signature updates, quarterly access reviews, or extended log retention-are valuable security activities but do not validate whether transmissions are using the mandated level of encryption, so they do not specifically address the updated requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is TLS and why is TLS 1.2 required for PCI DSS compliance?
Open an interactive chat with Bash
How does automated scanning validate cipher suites in PCI DSS compliance?
Open an interactive chat with Bash
Why are other activities like user access reviews or extended log retention insufficient for PCI DSS encryption compliance?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .