What is the retention requirement for audit trail history?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

What is the retention requirement for audit trail history?

Explanation:
The key idea is how long and how accessibly audit logs must be kept under PCI DSS. The standard requires audit log histories to be retained for at least one year, with the most recent three months available online for quick review and monitoring. This setup ensures you can investigate recent activity without delay while still preserving a substantial period of historical data for forensic analysis or compliance checks. The other options don’t match this requirement: six months is shorter than the mandated one year; keeping two years online exceeds the specified online window of three months; retaining logs indefinitely goes beyond the minimum one-year rule and isn’t what PCI DSS requires.

The key idea is how long and how accessibly audit logs must be kept under PCI DSS. The standard requires audit log histories to be retained for at least one year, with the most recent three months available online for quick review and monitoring. This setup ensures you can investigate recent activity without delay while still preserving a substantial period of historical data for forensic analysis or compliance checks. The other options don’t match this requirement: six months is shorter than the mandated one year; keeping two years online exceeds the specified online window of three months; retaining logs indefinitely goes beyond the minimum one-year rule and isn’t what PCI DSS requires.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy