Which type of administrative access must be encrypted using strong cryptography?

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

Which type of administrative access must be encrypted using strong cryptography?

Explanation:
Administrative access that travels over a network must be protected in transit with strong cryptography. Non-console administrative access refers to remote, network-based sessions (like SSH, RDP, or VPN) used to administer systems, and these sessions carry credentials and commands that could be intercepted if not encrypted. Console access is local and doesn’t traverse a network, so the in-transit encryption requirement doesn’t apply to it. Other options miss the scope of the requirement, which targets remote administrative sessions. Therefore, all non-console administrative access must be encrypted using strong cryptography.

Administrative access that travels over a network must be protected in transit with strong cryptography. Non-console administrative access refers to remote, network-based sessions (like SSH, RDP, or VPN) used to administer systems, and these sessions carry credentials and commands that could be intercepted if not encrypted. Console access is local and doesn’t traverse a network, so the in-transit encryption requirement doesn’t apply to it. Other options miss the scope of the requirement, which targets remote administrative sessions. Therefore, all non-console administrative access must be encrypted using strong cryptography.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy