PCI version 4.0 ISA Exam Questions
With 100% Verified Answers
Non-console administrator access to any web-based management
interfaces must be encrypted with technology such as......... -
correct answer ✅HTTPS
Requirements 2.2.2 and 2.2.3 cover the use of secure services,
protocols and
daemons. Which of the following is considered to be secure? -
correct answer ✅SSH
Which of the following is consider "Sensitive Authentication Data" -
correct answer ✅Card Verification Value (CAV2/CVC2/CVV2/CID),
Full Track Data,
PIN/PIN Block
True or False: It is acceptable for merchants to store Sensitive
Authentication after
authorization as long as it is strongly encrypted? -
correct answer ✅False
When a PAN is displayed to an employee who does NOT need to
see the full PAN, the minimum digits to be mased are -
correct answer ✅All digits between the first six and last four
,PCI version 4.0 ISA Exam Questions
With 100% Verified Answers
Which of the following is true regarding protection of PAN? -
correct answer ✅PAN must be rendered unreadable during
transmission over public, wireless networks
Which of the following may be used to render PAN unreadable in
order to meet requirement 3.4 -
correct answer ✅Hashing the entire PAN using strong
cryptography
True or False Where keys are stored on production systems, split
knowledge and
dual control is required? -
correct answer ✅True
When assessing requirement 6.5, testing to verify secure coding
techniques are in place to address common coding vulnerabilities
includes -
correct answer ✅Reviewing software development policies and
procedures
, PCI version 4.0 ISA Exam Questions
With 100% Verified Answers
One of the principles to be used when granting user access to
systems in CDE is: - -
correct answer ✅Least privilege
An example of a "one-way" cryptographic function used to render
data unreadable -
correct answer ✅SHA-2
Keyed Cryptographic Hash -
correct answer ✅A hashing function that incorporates a randomly
generated secret key to provide brute force attack resistance and
secret authentication integrity
Appropriate keyed cryptographic hashing algorithms include but
are not limited to: -
correct answer ✅HMAC, CMAC, and GMAC, with an effective
cryptographic strength of at least 128-bits (NIST SP 800-131Ar2).
A set of cryptographic hash functions designed by the National
Security Agency -
correct answer ✅
With 100% Verified Answers
Non-console administrator access to any web-based management
interfaces must be encrypted with technology such as......... -
correct answer ✅HTTPS
Requirements 2.2.2 and 2.2.3 cover the use of secure services,
protocols and
daemons. Which of the following is considered to be secure? -
correct answer ✅SSH
Which of the following is consider "Sensitive Authentication Data" -
correct answer ✅Card Verification Value (CAV2/CVC2/CVV2/CID),
Full Track Data,
PIN/PIN Block
True or False: It is acceptable for merchants to store Sensitive
Authentication after
authorization as long as it is strongly encrypted? -
correct answer ✅False
When a PAN is displayed to an employee who does NOT need to
see the full PAN, the minimum digits to be mased are -
correct answer ✅All digits between the first six and last four
,PCI version 4.0 ISA Exam Questions
With 100% Verified Answers
Which of the following is true regarding protection of PAN? -
correct answer ✅PAN must be rendered unreadable during
transmission over public, wireless networks
Which of the following may be used to render PAN unreadable in
order to meet requirement 3.4 -
correct answer ✅Hashing the entire PAN using strong
cryptography
True or False Where keys are stored on production systems, split
knowledge and
dual control is required? -
correct answer ✅True
When assessing requirement 6.5, testing to verify secure coding
techniques are in place to address common coding vulnerabilities
includes -
correct answer ✅Reviewing software development policies and
procedures
, PCI version 4.0 ISA Exam Questions
With 100% Verified Answers
One of the principles to be used when granting user access to
systems in CDE is: - -
correct answer ✅Least privilege
An example of a "one-way" cryptographic function used to render
data unreadable -
correct answer ✅SHA-2
Keyed Cryptographic Hash -
correct answer ✅A hashing function that incorporates a randomly
generated secret key to provide brute force attack resistance and
secret authentication integrity
Appropriate keyed cryptographic hashing algorithms include but
are not limited to: -
correct answer ✅HMAC, CMAC, and GMAC, with an effective
cryptographic strength of at least 128-bits (NIST SP 800-131Ar2).
A set of cryptographic hash functions designed by the National
Security Agency -
correct answer ✅