PCI DSS Strong Access Control Measures Requirements
As a service provider is implementing Strong Access Control Measures, which two of the following PCI Data Security Standard requirements must be met? (Choose two.)
Community Votes
100% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between general security controls (like encryption) and specific access control mandates (identity management and data access restriction). The trap is selecting encryption or storage protection, which are separate domains.
Identify the two specific PCI Data Security Standard requirements that constitute strong access control measures. This page establishes why user identification and need-to-know restrictions are the correct answers for service provider implementations.
Many learners select B (Encryption) because it is a high-priority PCI requirement, failing to realize the question specifically asks for 'Access Control' measures rather than transmission security.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
According to the PCI Data Security Standard (DSS), 'Strong Access Control Measures' explicitly encompass Requirement 7 (Restrict access to cardholder data by business need-to-know basis) and Requirement 8 (Identify users and authenticate access to system components). Option A corresponds directly to Requirement 8 by mandating unique IDs for each person with computer access. Option E corresponds to Requirement 7 by enforcing the principle of least privilege through need-to-know access. These two options form the core definition of access control within the standard.Why the Other Options Are Wrong
Option B refers to Requirement 4 (Encrypt transmission of cardholder data across open or public networks), which falls under the 'Network Security' domain, not Access Control. Option D refers to Requirement 3 (Protect stored cardholder data), which belongs to the 'Data Protection' domain. While these are critical PCI requirements, they do not answer the specific question about access control measures. Option C is not a standard PCI DSS requirement phrasing; compliance validation applies to the entity level, not as a per-location mandate in this context.Community Comment Notes
Community consensus strongly favors AE, with many users noting that while B and D are valid PCI controls, they address different categories. As one commenter noted, "I think correct answers are A and E" because the question focuses on access control rather than traffic encryption. Another user pointed out that "A,B,E are all correct [as PCI requirements], but the question requires two answers," highlighting the need to distinguish between broad compliance and specific category mapping.Official Reference
Exam Strategy
When answering PCI DSS questions, always map the option to the specific numbered requirement. If the question asks for a specific category (e.g., 'Access Control'), filter out correct statements from other categories (e.g., 'Encryption' or 'Storage'). Unique IDs and Need-to-Know are the hallmarks of Access Control.
Frequently Asked Questions
Why is encryption (Option B) not an access control measure?
Encryption protects data in transit but does not control who can access it. It falls under Network Security (Req 4), whereas Access Control (Req 7 & 8) manages identity and permissions.
Does PCI DSS require unique IDs for all employees?
Yes, Requirement 8 states that each person with computer access must be assigned a unique ID to ensure individual accountability and auditability.