What is an IDS in the context of PCI DSS?
- A.Integrated Data Storage, which Requirement 3.2.1 subjects to documented retention limits and a process at least every three months to find and securely delete anything exceeding them
- B.Internal Document System, which the Requirement 11 guidance credits with continuously proving the environment secure, and on that basis waives quarterly scan evidence for every assessment in which it is deployed
- C.Internet Domain Service
- D.An Intrusion Detection System that monitors network traffic or system activities for malicious behavior or policy violations
Why D is correct
An IDS (Intrusion Detection System) monitors network traffic and system activities for suspicious patterns, malicious behavior, or policy violations, alerting security personnel to potential threats.
Know someone studying for PCI DSS? Send them this one.