Payment Card Industry (PCI) Data Security Standards Practice Test

Disable ads (and more) with a membership for a one time $2.99 payment

Prepare for the Payment Card Industry (PCI) Data Security Standards Test. Study with multiple choice questions, hints, and explanations. Get ready to excel in your exam!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


In accordance with PCI DSS Requirement 10, how long must audit logs be retained?

  1. At least 1 year, with 3 months readily available

  2. At least 2 years, with 3 months readily available

  3. At least 2 years, with 1 month readily available

  4. At least 3 months, with 1 month readily available

The correct answer is: At least 1 year, with 3 months readily available

The correct answer is based on the specific requirements outlined in PCI DSS Requirement 10, which pertains to the retention of audit logs. According to this requirement, organizations are mandated to retain audit logs for at least one year. Furthermore, it specifies that these logs must be readily available for at least the past three months to ensure that they can be accessed quickly in the event of an investigation or incident response. The focus on retaining logs for a minimum of a year is critical because it helps organizations to maintain a comprehensive record of access and activity that could be vital for understanding security events over time. The three-month aspect of availability ensures that more recent activity can be reviewed without delay, as this time frame typically aligns with the period where incidents might be most relevant for immediate analysis. Options suggesting longer retention periods or different availability timelines deviate from this specific requirement, potentially leading organizations to hold onto logs for periods that are not necessary or not mandated, thus complicating data management without providing tangible benefits in compliance. In summary, the importance of both the one-year retention and the three months of availability lies in the balance between security auditing and efficient data management.