During a penetration test for a client subject to the PCI DSS, you identify a service running on a system within the cardholder data environment that does not appear to be necessary for the processing, storage, or transmission of cardholder data. According to PCI DSS requirements, what is the BEST action to take?
You selected this option
Review the terms within the Service Level Agreements (SLAs) regarding the operation of unauthorized services.
You selected this option
Suggest enhancing the intrusion detection system to monitor the unauthorized service closely.
You selected this option
Perform a comprehensive asset inventory to confirm the presence of the service across the network.
You selected this option
Recommend the disabling of unnecessary services to comply with the principle of least functionality.
You selected this option
Advocate for stronger encryption methods for stored cardholder data to offset any risks introduced by the service.
Choosing to 'Recommend the disabling of unnecessary services to comply with the principle of least functionality' is correct as it aligns with PCI DSS Requirement 2.2.2, which states that services and protocols not directly needed to perform the device's specified function should be disabled. Simply encrypting cardholder data, performing asset inventory, or enhancing intrusion detection would not directly address the specific issue of unnecessary services running. While reviewing existing SLAs can be part of compliance checks, it does not address the immediate concern of extraneous services that could pose a security risk.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Principle of Least Functionality?
Open an interactive chat with Bash
What are the PCI DSS requirements regarding services?
Open an interactive chat with Bash
Why is simply enhancing intrusion detection systems not sufficient?