PCI DSS Strong Access Control Measures Requirements

Answer Correct answer: A, E — Assign a unique ID to each person with computer access and restrict access to cardholder data on a need-to-know basis.

As a service provider is implementing Strong Access Control Measures, which two of the following PCI Data Security Standard requirements must be met? (Choose two.)

  1. Assign a unique ID to each person with computer access Correct Answer
  2. Encrypt transmission of cardholder data across open or public networks
  3. Each location must require validating PCI compliance if business has multiple locations
  4. Protect stored cardholder data
  5. Restrict access to cardholder data to on a need-to-know basis Correct Answer

Community Votes

AE
100%

100% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between general security controls (like encryption) and specific access control mandates (identity management and data access restriction). The trap is selecting encryption or storage protection, which are separate domains.

Identify the two specific PCI Data Security Standard requirements that constitute strong access control measures. This page establishes why user identification and need-to-know restrictions are the correct answers for service provider implementations.

Many learners select B (Encryption) because it is a high-priority PCI requirement, failing to realize the question specifically asks for 'Access Control' measures rather than transmission security.

Community Discussion (8 comments)

LordAndy 👍 1 Selected: AE
Identify users and authenticate access to system components Restrict access to cardholder data by business need-to-know
Devsin2000 👍 1 Selected: AD
A bad question: To me A D E seem correct answer, so toss the coin pick two. B fails because it says open networks.
kalulosu 👍 1 Selected: AE
I think correct answers are A and E.
bdp123 👍 4 Selected: AE
https://listings.pcisecuritystandards.org/documents/PCI_DSS-QRG-v3_2_1.pdf
Charles2024 👍 2
I think A and E. I believe its about physical access, not to do with traffic over the internet.
cwani11 👍 2 Selected: AE
Access Control Measures
blurain 👍 1 Selected: BD
https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard
Iyo 👍 1
A,B,E are all correct, but the question requires two answers. I'm not sure which two Cisco is now expecting as the correct answer. https://www.controlcase.com/what-are-the-12-requirements-of-pci-dss-compliance/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

According to the PCI Data Security Standard (DSS), 'Strong Access Control Measures' explicitly encompass Requirement 7 (Restrict access to cardholder data by business need-to-know basis) and Requirement 8 (Identify users and authenticate access to system components). Option A corresponds directly to Requirement 8 by mandating unique IDs for each person with computer access. Option E corresponds to Requirement 7 by enforcing the principle of least privilege through need-to-know access. These two options form the core definition of access control within the standard.

Why the Other Options Are Wrong

Option B refers to Requirement 4 (Encrypt transmission of cardholder data across open or public networks), which falls under the 'Network Security' domain, not Access Control. Option D refers to Requirement 3 (Protect stored cardholder data), which belongs to the 'Data Protection' domain. While these are critical PCI requirements, they do not answer the specific question about access control measures. Option C is not a standard PCI DSS requirement phrasing; compliance validation applies to the entity level, not as a per-location mandate in this context.

Community Comment Notes

Community consensus strongly favors AE, with many users noting that while B and D are valid PCI controls, they address different categories. As one commenter noted, "I think correct answers are A and E" because the question focuses on access control rather than traffic encryption. Another user pointed out that "A,B,E are all correct [as PCI requirements], but the question requires two answers," highlighting the need to distinguish between broad compliance and specific category mapping.

Official Reference

Exam Strategy

When answering PCI DSS questions, always map the option to the specific numbered requirement. If the question asks for a specific category (e.g., 'Access Control'), filter out correct statements from other categories (e.g., 'Encryption' or 'Storage'). Unique IDs and Need-to-Know are the hallmarks of Access Control.

Frequently Asked Questions

Why is encryption (Option B) not an access control measure?

Encryption protects data in transit but does not control who can access it. It falls under Network Security (Req 4), whereas Access Control (Req 7 & 8) manages identity and permissions.

Does PCI DSS require unique IDs for all employees?

Yes, Requirement 8 states that each person with computer access must be assigned a unique ID to ensure individual accountability and auditability.

Related Analysis

← Back to 400-007 Study Guide