Which statement about 10.1 audit trails is correct?

Boost your readiness for the PCI DSS Requirements Exam with engaging flashcards and comprehensive multiple choice questions. Each comes with hints and explanations to maximize your understanding!

Multiple Choice

Which statement about 10.1 audit trails is correct?

Explanation:
Auditing in PCI DSS is about capturing who did what and when, so you can reconstruct events and detect unauthorized activity. For the 10.1 area, the requirement is that audit trails are enabled and actively maintained on all system components and that access to those components is linked to individual users. This combination provides accountability and supports forensic analysis by showing exactly which user performed which action at a given time. That’s why this statement is the best fit: it reflects both the need for enabled, ongoing logs across all components and the importance of tying those actions to specific user identities. It isn’t optional, it isn’t limited to file servers, and logs shouldn’t be disabled during off-hours—continuous, user-linked auditing is essential for effective monitoring and incident response.

Auditing in PCI DSS is about capturing who did what and when, so you can reconstruct events and detect unauthorized activity. For the 10.1 area, the requirement is that audit trails are enabled and actively maintained on all system components and that access to those components is linked to individual users. This combination provides accountability and supports forensic analysis by showing exactly which user performed which action at a given time.

That’s why this statement is the best fit: it reflects both the need for enabled, ongoing logs across all components and the importance of tying those actions to specific user identities. It isn’t optional, it isn’t limited to file servers, and logs shouldn’t be disabled during off-hours—continuous, user-linked auditing is essential for effective monitoring and incident response.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy