TLS v1.2 is considered best practice for PCI DSS security.

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

TLS v1.2 is considered best practice for PCI DSS security.

Explanation:
PCI DSS requires strong cryptography and security protocols for transmitting cardholder data, and specifies that TLS 1.2 or higher must be used. That makes TLS 1.2 a baseline requirement, not just a best practice. In PCI DSS, older protocols (like TLS 1.0/1.1) are not acceptable for protecting data in transit, and you should also consider newer versions (such as TLS 1.3) when available. So the statement that TLS v1.2 is only best practice is not accurate; it’s the minimum standard that must be met.

PCI DSS requires strong cryptography and security protocols for transmitting cardholder data, and specifies that TLS 1.2 or higher must be used. That makes TLS 1.2 a baseline requirement, not just a best practice. In PCI DSS, older protocols (like TLS 1.0/1.1) are not acceptable for protecting data in transit, and you should also consider newer versions (such as TLS 1.3) when available. So the statement that TLS v1.2 is only best practice is not accurate; it’s the minimum standard that must be met.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy