Formulti-tenant service providers,isolation and segmentationare critical. As perRequirement 12.10.3, each customer’s environment must besegregated and protectedsuch that no tenant can access another’s data or systems.
Option A:✅Correct. This is the foundational control —isolation of customer environments.
Option B:❌Incorrect. Exposing system config files is a security risk.
Option C:❌Incorrect. Shared user IDs areexplicitly prohibitedby Requirement 8.2.1.
Option D:❌Incorrect. Customers should only access their own logs.
[Reference:PCI DSS v4.0.1 – Requirement 12.10.3; Scoping Guidance for Service Providers., , , , ]
Submit