During testing of Req 2.3, what should you verify about admin login?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

During testing of Req 2.3, what should you verify about admin login?

Explanation:
The key idea is protecting admin credentials as they travel over the network. For admin login, you must ensure a strong, encrypted channel is established before any password is sent. This means the login occurs over a secure protocol (like TLS/HTTPS or SSH) with strong cryptography, so the password isn’t exposed in transit. If credentials could be sent over an unencrypted channel, or if insecure remote-login methods are allowed, or if encryption isn’t required at all, the requirement isn’t being met. By validating that encryption is in place before the password request, you confirm the admin login process protects sensitive credentials from interception.

The key idea is protecting admin credentials as they travel over the network. For admin login, you must ensure a strong, encrypted channel is established before any password is sent. This means the login occurs over a secure protocol (like TLS/HTTPS or SSH) with strong cryptography, so the password isn’t exposed in transit. If credentials could be sent over an unencrypted channel, or if insecure remote-login methods are allowed, or if encryption isn’t required at all, the requirement isn’t being met. By validating that encryption is in place before the password request, you confirm the admin login process protects sensitive credentials from interception.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy