A desktop technician is configuring standardized operating system security policies for remote laptops used by a financial services company. The laptops process live credit card transactions and manage personal records for customer accounts in the European Union. Which TWO of the following technical configurations must the technician enforce to maintain compliance with PCI-DSS and GDPR data privacy standards?
- Enforcing full-disk storage encryption on all endpoint drives that store or process Cardholder Data (CHD) and Personal Identifiable Information (PII).Cevap
- Configuring automated screen lock timeouts after a brief period of system inactivity.Cevap
- CSaving complete credit card verification codes (CVV/CVC) to an encrypted local log file to facilitate post-transaction audit reconciliation.
- DConfiguring customer databases to retain all EU client personal records indefinitely to prevent compliance data loss.
Cevap
The technician must enforce full-disk storage encryption on endpoint drives storing CHD or PII and configure automated screen lock timeouts after inactivity.
Enforcing full-disk storage encryption satisfies PCI-DSS and GDPR mandates for safeguarding Cardholder Data (CHD) and EU customer Personally Identifiable Information (PII) at rest. Configuring automated screen lock timeouts satisfies physical access control requirements under PCI-DSS by preventing unauthorized access to unattended remote workstations.
Adım Adım Çözüm
Anahtar Kavram
Data Privacy and Compliance Regulations (PCI-DSS and GDPR Endpoint Controls)