What is one way to address PCI DSS v4.0 Requirement 6.4.2 (formerly 6.6) for public-facing web applications?
- A.Deploying a Web Application Firewall (WAF) in front of public-facing web applications
- B.Installing antivirus on the web server, extended by v4.0 Requirement 5.4.1 to include mechanisms that detect and protect personnel against phishing attacks
- C.Using HTTPS only
- D.Implementing network firewalls
Why A is correct
PCI DSS v4.0 Requirement 6.4.2 (Requirement 6.6 in v3.2.1) is addressed by deploying an automated technical solution, such as a WAF, in front of public-facing web applications to detect and prevent web-based attacks. The earlier alternative of periodic application vulnerability reviews (6.4.1) was superseded when 6.4.2 became mandatory on 31 March 2025.
Know someone studying for PCI DSS? Send them this one.