What is the intent of classifying media that contains cardholder data?
A.
Ensuring that media is properly protected according to the sensitivity of the data it contains.
B.
Ensuring that media containing cardholder data Is moved from secured areas an a quarterly basis.
C.
Ensuring that media is clearly and visibly labeled as "Confidential" so all personnel know that the media contains cardholder data.
D.
Ensuring that all media is consistently destroyed on the same schedule, regardless of the contents.
The Answer Is:
A
This question includes an explanation.
Explanation:
Purpose of Classifying Media
PCI DSS v4.0 emphasizes the need to classify media based on the sensitivity of the data it contains. Media classification ensures appropriate handling, storage, and destruction processes.
Media Protection Requirements
Media containing cardholder data must be securely stored, transferred, and destroyed when no longer needed.
Classification informs the level of protection required, such as encryption, physical security, or controlled access.
Incorrect Options
Option B: Moving media quarterly is not a requirement.
Option C: Labeling as "Confidential" is insufficient without a comprehensive protection strategy.
Option D: Destruction schedules should depend on retention requirements and data sensitivity, not a universal timeline.
QSA_New_V4 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"