What is the purpose of a digital certificate in PCI DSS encryption?
- A.To compress data
- B.To store passwords, which Requirement 8.6.2 forbids from being hardcoded in scripts, configuration files, or bespoke source code when used interactively
- C.To verify the identity of a server or entity and establish trust for encrypted communications, ensuring data is sent to the legitimate recipient
- D.To encrypt data directly, addressed by Requirement 3.6 through documented key-management policies that cover the full lifecycle of the keys protecting stored account data
Why C is correct
Digital certificates verify entity identity and establish trust for encrypted communications, ensuring cardholder data is transmitted to legitimate recipients.
Know someone studying for PCI DSS? Send them this one.