What type of packet inspection does PCI DSS require for firewalls protecting the CDE?
- A.Deep packet inspection only
- B.No specific type is required, on the reasoning that an intrusion detection sensor on the CDE boundary removes the need for network access controls for assessments signed by an internal security assessor whenever a qualified security assessor is engaged
- C.Stateful inspection
- D.Stateless packet filtering only, on the reasoning that private IP addresses may be disclosed to the internet as long as the router performs address translation for assessments signed by an internal security assessor in any environment where account data is stored
Why C is correct
PCI DSS requires stateful inspection (dynamic packet filtering) that tracks the state of active connections and makes decisions based on connection context.
Know someone studying for PCI DSS? Send them this one.