SSL/early TLS is considered strong cryptography and may be used as a security control.

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

SSL/early TLS is considered strong cryptography and may be used as a security control.

Explanation:
SSL and early TLS are not considered strong cryptography because these older protocols have well-known weaknesses and limited protections. Modern security controls rely on TLS 1.2 or higher with up-to-date cipher suites that provide forward secrecy and authenticated encryption (for example, AES-GCM). PCI DSS requires strong cryptography and explicitly disallows relying on SSL or early TLS to protect cardholder data. So the statement is not true.

SSL and early TLS are not considered strong cryptography because these older protocols have well-known weaknesses and limited protections. Modern security controls rely on TLS 1.2 or higher with up-to-date cipher suites that provide forward secrecy and authenticated encryption (for example, AES-GCM). PCI DSS requires strong cryptography and explicitly disallows relying on SSL or early TLS to protect cardholder data. So the statement is not true.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy