PCI SSC Qualified Security Assessor V4 Exam QSA_New_V4 Question # 12 Topic 2 Discussion

PCI SSC Qualified Security Assessor V4 Exam QSA_New_V4 Question # 12 Topic 2 Discussion

QSA_New_V4 Exam Topic 2 Question 12 Discussion:
Question #: 12
Topic #: 2

Which of the following is true regarding compensating controls?


A.

A compensating control is not necessary if all other PCI DSS requirements are in place.


B.

A compensating control must address the risk associated with not adhering to the PCI DSS requirement.


C.

An existing PCI DSS requirement can be used as compensating control if it is already implemented.


D.

A compensating control worksheet is not required if the acquirer approves the compensating control.


Get Premium QSA_New_V4 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.