What is required to monitor entry and exit to sensitive areas and what is the data retention requirement?

Prepare for the PCI DSS Requirements Test. Utilize interactive flashcards and practice multiple choice questions, each with detailed explanations. Enhance your readiness and confidence for your certification exam!

Multiple Choice

What is required to monitor entry and exit to sensitive areas and what is the data retention requirement?

Explanation:
Monitoring entry to sensitive areas requires using video surveillance or access control systems to track who enters and exits. This creates an auditable trail that supports security investigations and enforces protection of cardholder data by ensuring only authorized personnel can access sensitive zones. In addition, the data produced by these controls—whether video footage or access logs—must be retained for at least three months, providing a window to review incidents or anomalies. The other options don’t fit because they either rely on door locks alone, omit surveillance, or propose retention that isn’t aligned with the required minimum.

Monitoring entry to sensitive areas requires using video surveillance or access control systems to track who enters and exits. This creates an auditable trail that supports security investigations and enforces protection of cardholder data by ensuring only authorized personnel can access sensitive zones. In addition, the data produced by these controls—whether video footage or access logs—must be retained for at least three months, providing a window to review incidents or anomalies. The other options don’t fit because they either rely on door locks alone, omit surveillance, or propose retention that isn’t aligned with the required minimum.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy