Which type of administrative access must be encrypted using strong cryptography?

Prepare for the PCI Approved Scanning Vendor ASV exam with our comprehensive study tools. Use flashcards and multiple choice questions, each with hints and explanations, to ace your test!

Multiple Choice

Which type of administrative access must be encrypted using strong cryptography?

Explanation:
Administrative access that travels over a network must be protected in transit with strong cryptography. Non-console administrative access refers to remote, network-based sessions (like SSH, RDP, or VPN) used to administer systems, and these sessions carry credentials and commands that could be intercepted if not encrypted. Console access is local and doesn’t traverse a network, so the in-transit encryption requirement doesn’t apply to it. Other options miss the scope of the requirement, which targets remote administrative sessions. Therefore, all non-console administrative access must be encrypted using strong cryptography.

Administrative access that travels over a network must be protected in transit with strong cryptography. Non-console administrative access refers to remote, network-based sessions (like SSH, RDP, or VPN) used to administer systems, and these sessions carry credentials and commands that could be intercepted if not encrypted. Console access is local and doesn’t traverse a network, so the in-transit encryption requirement doesn’t apply to it. Other options miss the scope of the requirement, which targets remote administrative sessions. Therefore, all non-console administrative access must be encrypted using strong cryptography.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy