Question

Difficulty: MediumData Privacy and Compliance Regulations

A desktop technician is configuring standardized operating system security policies for remote laptops used by a financial services company. The laptops process live credit card transactions and manage personal records for customer accounts in the European Union. Which TWO of the following technical configurations must the technician enforce to maintain compliance with PCI-DSS and GDPR data privacy standards?

  1. Enforcing full-disk storage encryption on all endpoint drives that store or process Cardholder Data (CHD) and Personal Identifiable Information (PII).Answer
  2. Configuring automated screen lock timeouts after a brief period of system inactivity.Answer
  3. C
    Saving complete credit card verification codes (CVV/CVC) to an encrypted local log file to facilitate post-transaction audit reconciliation.
  4. D
    Configuring customer databases to retain all EU client personal records indefinitely to prevent compliance data loss.

Answer

The technician must enforce full-disk storage encryption on endpoint drives storing CHD or PII and configure automated screen lock timeouts after inactivity.
Enforcing full-disk storage encryption satisfies PCI-DSS and GDPR mandates for safeguarding Cardholder Data (CHD) and EU customer Personally Identifiable Information (PII) at rest. Configuring automated screen lock timeouts satisfies physical access control requirements under PCI-DSS by preventing unauthorized access to unattended remote workstations.

Step-by-Step Solution

1
Identify the data privacy frameworks applicable to the scenario.
Credit card handling requires PCI-DSS compliance, while European customer account management requires GDPR compliance.
Different regulatory bodies mandate specific technical and operational controls based on the data domain.
2
Evaluate technical endpoint protection controls.
Full-disk encryption protects data at rest (PCI-DSS and GDPR requirement), while automated screen locks restrict physical access during inactivity (PCI-DSS requirement).
Both practices fulfill standard regulatory safeguards for mobile and remote endpoints handling sensitive personal data.
3
Rule out non-compliant storage and retention practices.
Storing card CVV/CVC codes post-authorization violates PCI-DSS rules against retaining Sensitive Authentication Data, and retaining EU client records indefinitely violates GDPR storage limitation and erasure rights.
Understanding regulatory prohibitions prevents severe compliance violations.

Key Concept

Data Privacy and Compliance Regulations (PCI-DSS and GDPR Endpoint Controls)
Rate this question