A systems administrator for a global e-commerce enterprise is establishing security baseline controls for databases storing payment transaction history and European customer profiles. To maintain strict compliance with both PCI-DSS and GDPR regulations during routine data maintenance and archival, which of the following operational practices MUST the administrator implement? (Select TWO.)
- Apply industry-standard cryptographic encryption to payment cardholder data (CHD) and personal data both in transit across public networks and at rest in backup repositories.Cevap
- Establish technical workflows to sanitize and permanently remove European Union customer records upon verified request under the right to be forgotten.Cevap
- CLog full card verification value (CVV/CVC) codes alongside primary account numbers in unencrypted application audit files for post-transaction verification.
- DRetain all customer identity records indefinitely in active database tables to streamline open-ended legal discovery requests regardless of data subject opt-out notices.
Cevap
The administrator must encrypt cardholder and personal data both at rest and in transit, and establish automated technical workflows to erase customer personal data upon valid GDPR right-to-be-forgotten requests.
The correct operational practices are applying strong cryptographic encryption to cardholder data and PII at rest and in transit, and setting up workflows to permanently erase EU customer data upon request under GDPR. PCI-DSS mandates encryption for cardholder data across storage and public network transmissions, while GDPR enforces technical data security (Article 32) and data erasure rights (Article 17).
Adım Adım Çözüm
Anahtar Kavram
Data Privacy and Compliance Regulations (PCI-DSS and GDPR Operational Controls)