An IT technician is configuring a new web server for an international organization that processes payment card transactions and collects account details from European Union residents. Which of the following technical procedures must the technician perform to align with PCI-DSS and GDPR regulations? (Select TWO.)
- Encrypt stored payment card numbers and restrict access to authorized personnel to comply with PCI-DSS requirements.Cevap
- BStore card verification codes (CVV) permanently in database tables to simplify recurring billing audits.
- Establish automated mechanisms to purge personal identifying records upon valid customer deletion requests to support GDPR right to erasure.Cevap
- DClassify all internal system configuration files as Protected Health Information (PHI) under HIPAA guidelines.
Cevap
The technician must encrypt stored payment card data to comply with PCI-DSS standards and establish automated data purging workflows to respect the GDPR right to erasure.
Encrypting stored payment card numbers satisfies PCI-DSS requirements for protecting cardholder data. Implementing automated workflows to remove personal data upon request fulfills the GDPR requirement regarding the right to erasure (right to be forgotten).
Adım Adım Çözüm
Anahtar Kavram
Data Privacy and Compliance Regulations (PCI-DSS, GDPR, HIPAA)