CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
A retail company processes credit card transactions through a cloud-based e-commerce platform. To minimize the number of systems that must undergo annual PCI DSS assessment, the company places the servers handling cardholder data on an isolated virtual network with strict firewall rules preventing any communication with unrelated systems. Which technique is the company using to reduce PCI DSS audit scope?
- ANetwork segmentation
- BRole-based access control
- CField tokenization
- DMultifactor authentication
Show answer & explanationAnswer & explanation
Correct answer: A. Network segmentation
Network segmentation isolates the cardholder data environment (CDE) from the rest of the network, which reduces the number of systems in scope for PCI DSS assessment because only systems that can communicate with the CDE are considered in scope. Tokenization reduces exposure of card data but doesn't isolate network zones; RBAC and MFA are access controls that don't directly reduce assessment scope.
Why the other options are wrong
- B. RBAC controls who can access systems but does not isolate the cardholder data environment from other networks.
- C. Tokenization reduces the sensitivity of stored data but is a separate control from network isolation.
- D. MFA strengthens authentication but does not affect which systems fall within PCI DSS assessment scope.
PCI DSS Scope Reduction via Segmentation
Isolating the cardholder data environment (CDE) on a separate, firewalled network segment so that only in-scope systems require PCI DSS assessment.
- Reduces cost and complexity of annual PCI DSS audits
- CDE must have no unrestricted communication with out-of-scope systems
- Often combined with tokenization for further scope reduction
Memory trick: Build a moat around the cardholder data castle to keep auditors out of the rest of town.