PCI DSS Requirements Practice Test

Access More Questions
Which statement describes a criterion for compensating controls?
Correct Answer:
They meet the intent and rigor of the original PCI DSS requirement
Explanation:
Compensating controls are allowed when you can’t meet a PCI DSS requirement as written, but they must deliver protection that is equivalent to the original requirement. The key test is that the compensating controls meet the intent and rigor of the original PCI DSS control, providing at least the same level of protection and being verifiable as such. That’s why stating that they meet the original requirement’s intent and rigor is the best description. It captures both the purpose (protecting cardholder data in the same way the original control would) and the standard for acceptance (they must be as strong as, or stronger than, the original control and demonstrably achieve its protective goals). Relying on existing PCI DSS requirements alone isn’t enough on its own to justify compensating controls, because they must specifically demonstrate equivalent protection to the original requirement. Cost differences don’t determine eligibility, since a compensating control can be more or less expensive and still be valid if it preserves the same level of risk mitigation. Finally, the idea that they don’t need to be above and beyond other PCI DSS requirements isn’t correct; the focus is on achieving equivalent protection, which may involve strengthening controls beyond the bare minimum in some areas to compensate for the gap.

Access more questions from this quiz

Continue to PCI DSS Requirements Practice Test for more practice questions and the full quiz experience.

Access More Questions