Q58. What must be reviewed daily to meet PCI DSS requirements?
a. Vulnerability scans and penetration testing reports
b. Security events and logs from critical system components
c. Data retention policies and procedures
d. Firewall and router rule sets
Q59. What do PCI DSS requirements for protecting cryptographic keys include?
a. Private or secret keys must be encrypted, stored with an SCD, or stored as key components
b. Data-encrypting keys must be stronger than the key-encrypting key that protects it
c. Public keys must be encrypted with a key-encrypting key
d. Key-encrypting keys and data-encrypting keys must be assigned to the same key custodian
Q60. What must be included in an organization's procedures for managing visitors?
a. Visitors retain their identification (for example, a visitor badge) for 30 days after completion of the visit
b. Visitor badges are identical to badges used by onsite personnel
c. Visitor log includes visitor's name, address, and contact phone number
d. Visitors are escorted at all times within areas where cardholder data is processed or maintained