CompTIA Server+ SK0-005 Practice Question

During an internal design review of a payment-processing server cluster, an auditor notes that the same Linux administrator can generate, load, and destroy the cryptographic keys used to protect stored cardholder data. The environment must comply with PCI DSS. Which of the following changes will BEST address this regulatory finding?

  • Implement split knowledge and dual control for all manual cryptographic key operations.

  • Enforce multifactor authentication and require administrators to change passwords every 60 days.

  • Enable AES-256 full-disk encryption on each database server that stores cardholder data.

  • Copy every new encryption key to an off-site, air-gapped tape library immediately after rotation.

CompTIA Server+ SK0-005
Security and Disaster Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $47
$390.00 $343.00
SAVE $53
CompTIA Server+ Voucher with Retake
v5 / SK0-005
Includes Retake
$439.00 $386.00
Bash, the Crucial Exams Chat Bot
AI Bot