An organization has multiple business locations, each with its own payment processing setup. Some locations process card-present transactions using point-of-sale (POS) terminals, while others handle e-commerce transactions through their website. As a PCI Professional, which Self-Assessment Questionnaire (SAQ) would be most appropriate for the organization's overall PCI DSS compliance assessment?
A merchant is undergoing penetration testing and are using a test/developer environment to ensure the penetration testers do not cause any outages to their live database. Which piece of live CHD (cardholder data) may not be used inside this test/developer environment?