If a session is idle for more than 15 minutes, what should happen?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

If a session is idle for more than 15 minutes, what should happen?

Explanation:
Session management through idle-time re-authentication helps protect cardholder data by ensuring that an unattended workstation cannot be misused. When a user session sits idle for 15 minutes, requiring them to re-authenticate to re-activate confirms the current user is still legitimately active and prevents someone else from taking over an open session. This tightens protection against session hijacking and accidental exposure when devices are left unattended. The other options either delay re-authentication too long, claim no re-auth is needed, or require re-authentication after an even longer period, all of which increase risk. So, re-authenticate after 15 minutes of inactivity.

Session management through idle-time re-authentication helps protect cardholder data by ensuring that an unattended workstation cannot be misused. When a user session sits idle for 15 minutes, requiring them to re-authenticate to re-activate confirms the current user is still legitimately active and prevents someone else from taking over an open session. This tightens protection against session hijacking and accidental exposure when devices are left unattended. The other options either delay re-authentication too long, claim no re-auth is needed, or require re-authentication after an even longer period, all of which increase risk. So, re-authenticate after 15 minutes of inactivity.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy