TLS v1.2 is considered best practice for PCI DSS security.

Prepare for the PCI Approved Scanning Vendor ASV exam with our comprehensive study tools. Use flashcards and multiple choice questions, each with hints and explanations, to ace your test!

Multiple Choice

TLS v1.2 is considered best practice for PCI DSS security.

Explanation:
PCI DSS requires strong cryptography and security protocols for transmitting cardholder data, and specifies that TLS 1.2 or higher must be used. That makes TLS 1.2 a baseline requirement, not just a best practice. In PCI DSS, older protocols (like TLS 1.0/1.1) are not acceptable for protecting data in transit, and you should also consider newer versions (such as TLS 1.3) when available. So the statement that TLS v1.2 is only best practice is not accurate; it’s the minimum standard that must be met.

PCI DSS requires strong cryptography and security protocols for transmitting cardholder data, and specifies that TLS 1.2 or higher must be used. That makes TLS 1.2 a baseline requirement, not just a best practice. In PCI DSS, older protocols (like TLS 1.0/1.1) are not acceptable for protecting data in transit, and you should also consider newer versions (such as TLS 1.3) when available. So the statement that TLS v1.2 is only best practice is not accurate; it’s the minimum standard that must be met.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy