Which of the following actions is NOT recommended by PCI DSS?

Prepare for the PCI DSS QSA Exam with detailed quiz questions. Sharpen your understanding with multiple choice questions, each curated to enhance your readiness for the official test. Ace your certification!

Using default passwords for system access is not recommended by PCI DSS because default passwords can create significant vulnerabilities within a system. When devices and applications are deployed with factory settings, including default usernames and passwords, they are commonly known and easily exploited by attackers. This practice violates the principle of implementing strong security controls, which PCI DSS emphasizes.

In contrast, periodic reviews of security policies are essential to ensure that they remain effective against evolving threats. Regular updates of security patches help protect systems from vulnerabilities that could be exploited by attackers. Additionally, monitoring access to cardholder data is critical to detect and prevent unauthorized access, ensuring that sensitive information is kept secure.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy