For wireless environments connected to the cardholder data environment, what action is required at installation?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

For wireless environments connected to the cardholder data environment, what action is required at installation?

Explanation:
When configuring wireless devices that connect to the cardholder data environment, you must start with secure, non-default settings. Vendor defaults are widely known and easy for attackers to guess or obtain, so leaving any default in place creates an open door into the network and, potentially, the CHD. Changing just one piece, like the wireless password, leaves other critical defaults—such as encryption keys and SNMP community strings—exposed and usable for unauthorized access or remote management. There’s no requirement to abandon wireless in favor of wired, so the correct approach is to replace all vendor defaults during installation, covering keys, passwords, and SNMP strings, to establish a solid, non-default baseline from the start.

When configuring wireless devices that connect to the cardholder data environment, you must start with secure, non-default settings. Vendor defaults are widely known and easy for attackers to guess or obtain, so leaving any default in place creates an open door into the network and, potentially, the CHD. Changing just one piece, like the wireless password, leaves other critical defaults—such as encryption keys and SNMP community strings—exposed and usable for unauthorized access or remote management. There’s no requirement to abandon wireless in favor of wired, so the correct approach is to replace all vendor defaults during installation, covering keys, passwords, and SNMP strings, to establish a solid, non-default baseline from the start.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy