exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 506 discussion

Actual exam question from CompTIA's CAS-004
Question #: 506
Topic #: 1
[All CAS-004 Questions]

A company uses a CSP to provide a front end for its new payment system offering. The new offering is currently certified as PCI compliant. In order for the integrated solution to be compliant, the customer:

  • A. must also be PCI compliant, because the risk is transferred to the provider.
  • B. still needs to perform its own PCI assessment of the provider's managed serverless service.
  • C. needs to perform a penetration test of the cloud provider's environment.
  • D. must ensure in-scope systems for the new offering are also PCI compliant.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
3 weeks, 1 day ago
Selected Answer: D
In a Payment Card Industry (PCI) context, even if a company is using a Cloud Service Provider (CSP) to host or manage part of its system, the company remains responsible for ensuring that its in-scope systems (systems that store, process, or transmit payment card data) are PCI compliant. The certification of the offering as PCI compliant typically refers to the specific parts of the environment where payment card data is processed or stored, but it does not automatically extend to all other parts of the company’s environment. Thus, the company must ensure that all systems involved in the payment processing solution that are considered in-scope for PCI DSS requirements are compliant. The CSP may be responsible for ensuring that their infrastructure and services (such as cloud-based storage or serverless services) meet PCI compliance standards, but the customer still needs to confirm that their systems that interact with this service are also compliant.
upvoted 1 times
...
gbemimatti
1 month, 2 weeks ago
Selected Answer: D
When using a cloud service provider (CSP) for a payment system, compliance with PCI DSS (Payment Card Industry Data Security Standard) is a shared responsibility between the customer and the CSP. While the CSP might be PCI-compliant for its infrastructure or services, the customer is still responsible for ensuring that in-scope systems (those processing, transmitting, or storing cardholder data) in their environment are also PCI compliant.
upvoted 2 times
...
Bright07
3 months, 1 week ago
Ans D. In the context of using a Cloud Service Provider (CSP) for a PCI-compliant payment system, the correct option is D. must ensure in-scope systems for the new offering are also PCI compliant. While the CSP may be PCI compliant, the customer is responsible for ensuring that their own systems and processes that interact with the payment system also meet PCI compliance requirements.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago