What is the maximum idle session time before re-authentication is required?

Prepare for the PCI DSS Requirements Test with our interactive quizzes. Use multiple choice questions, flashcards, and detailed explanations. Ace your exam with confidence!

Multiple Choice

What is the maximum idle session time before re-authentication is required?

Explanation:
Idle session timeouts protect cardholder data by ensuring a session is not left open if someone steps away. PCI DSS requires that systems automatically require re-authentication after a short period of inactivity to prevent unauthorized access from an unattended workstation. The maximum allowed idle time is 15 minutes or less, which strikes a balance between usability and security. Longer timeouts, like 30 or 60 minutes, would exceed the recommended limit and raise risk of session hijacking. A 5-minute timeout is stricter than necessary for the maximum, so it doesn’t reflect the allowed upper bound.

Idle session timeouts protect cardholder data by ensuring a session is not left open if someone steps away. PCI DSS requires that systems automatically require re-authentication after a short period of inactivity to prevent unauthorized access from an unattended workstation. The maximum allowed idle time is 15 minutes or less, which strikes a balance between usability and security. Longer timeouts, like 30 or 60 minutes, would exceed the recommended limit and raise risk of session hijacking. A 5-minute timeout is stricter than necessary for the maximum, so it doesn’t reflect the allowed upper bound.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy