企業に対する内部侵入テスト中に、侵入テスト担当者はネットワークの別の部分に移動し、住所、電話番号、クレジット カード番号などの顧客情報を含むフォルダーを見つけることができました。PCI に準拠するために、企業がこのデータを最善に保護するために実装する必要があるのは、次のうちどれですか?
正解:B
Network segmentation is the practice of dividing a network into smaller subnetworks or segments based on different criteria, such as function, security level, or access control. Network segmentation can enhance the security of a network by isolating sensitive or critical systems from less secure or untrusted systems, reducing the attack surface, limiting the spread of malware or intrusions, and enforcing granular policies and rules for each segment. To be PCI compliant, which is a set of standards for protecting payment card data, the company should have implemented network segmentation to separate the servers that perform financial transactions from other parts of the network that may be less secure or more exposed to threats. The other options are not specific requirements for PCI compliance, although they may be good security practices in general.