What is required to monitor entry and exit to sensitive areas and what is the data retention requirement?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

What is required to monitor entry and exit to sensitive areas and what is the data retention requirement?

Explanation:
Monitoring entry to sensitive areas requires using video surveillance or access control systems to track who enters and exits. This creates an auditable trail that supports security investigations and enforces protection of cardholder data by ensuring only authorized personnel can access sensitive zones. In addition, the data produced by these controls—whether video footage or access logs—must be retained for at least three months, providing a window to review incidents or anomalies. The other options don’t fit because they either rely on door locks alone, omit surveillance, or propose retention that isn’t aligned with the required minimum.

Monitoring entry to sensitive areas requires using video surveillance or access control systems to track who enters and exits. This creates an auditable trail that supports security investigations and enforces protection of cardholder data by ensuring only authorized personnel can access sensitive zones. In addition, the data produced by these controls—whether video footage or access logs—must be retained for at least three months, providing a window to review incidents or anomalies. The other options don’t fit because they either rely on door locks alone, omit surveillance, or propose retention that isn’t aligned with the required minimum.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy