In accordance with PCI DSS Requirement 10, how long must audit logs be retained?
A.
At least 1 year, with the most recent 3 months immediately available.
B.
At least 2 years, with the most recent 3 months immediately available.
C.
At least 2 years, with the most recent month immediately available.
D.
At least 3 months, with the most recent month immediately available.
The Answer Is:
A
This question includes an explanation.
Explanation:
PerRequirement 10.5.1.2, audit logs must be retained forat least one year, and the mostrecent three months must be readily availablefor analysis. This ensures traceability of security events over both short and longer-term periods.
Option A:✅Correct. Matches both duration and availability criteria.
Option B:❌Incorrect. Two years is not required.
Option C:❌Incorrect. The retention period is misstated.
Option D:❌Incorrect. One month is insufficient for immediate access.