Which of the following can be sampled for testing during a PCI DSS assessment?
A.
PCI DSS requirements and testing procedures.
B.
Compensating controls.
C.
Business facilities and system components.
D.
Security policies and procedures.
The Answer Is:
C
This question includes an explanation.
Explanation:
Sampling is a legitimate method under PCI DSS for assessing a representative subset of system components and locations.Section 6 – Sampling for PCI DSS Assessmentsoutlines thatsampling of business facilities and system componentsis allowed, as long as it’s justified, consistent, and documented.