Which of the following is true regarding compensating controls?
A.
A compensating control is not necessary if all other PCI DSS requirements are in place
B.
A compensating control must address the risk associated with not adhering to the PCI DSS requirement
C.
An existing PCI DSS requirement can be used as compensating control if it is already implemented
D.
A compensating control worksheet is not required if the acquirer approves the compensating control
The Answer Is:
B
This question includes an explanation.
Explanation:
According to the PCI DSS v3.2.1 Quick Reference Guide1, a compensating control must address the risk associated with not adhering to a PCI DSS requirement and must be approved by an authorized person before implementation. This is one of the requirements for reducing or eliminating a risk that cannot be eliminated by other means
Assessor_New_V4 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"