PCI-DSS ISA Exam Questions With
100% Verified Answers
Perimeter firewalls installed ______________________________. -
correct answer ✅between all wireless networks and the CHD
environment.
Where should firewalls be installed? -
correct answer ✅At each Internet connection and between any
DMZ and the internal network.
Review of firewall and router rule sets at least every
__________________. -
correct answer ✅6 months
If disk encryption is used -
correct answer ✅logical access must be managed separately and
independently of native operating system authentication and
access control mechanisms
Manual clear-text key-management procedures specify processes
for the use of the following: -
correct answer ✅Split knowledge AND Dual control of keys
, PCI-DSS ISA Exam Questions With
100% Verified Answers
What is considered "Sensitive Authentication Data"? -
correct answer ✅Card verification value
When a PAN is displayed to an employee who does NOT need to
see the full PAN, the minimum digits to be masked are: All digits
between the ___________ and the __________. -
correct answer ✅first 6; last 4
Regarding protection of PAN... -
correct answer ✅PAN must be rendered unreadable during the
transmission over public and wireless networks.
Under requirement 3.4, what method must be used to render the
PAN unreadable? -
correct answer ✅Hashing the entire PAN using strong
cryptography
Weak security controls that should NOT be used -
correct answer ✅WEP, SSL, and TLS 1.0 or earlier
Per requirement 5, anti-virus technology must be
deployed_________________ -
100% Verified Answers
Perimeter firewalls installed ______________________________. -
correct answer ✅between all wireless networks and the CHD
environment.
Where should firewalls be installed? -
correct answer ✅At each Internet connection and between any
DMZ and the internal network.
Review of firewall and router rule sets at least every
__________________. -
correct answer ✅6 months
If disk encryption is used -
correct answer ✅logical access must be managed separately and
independently of native operating system authentication and
access control mechanisms
Manual clear-text key-management procedures specify processes
for the use of the following: -
correct answer ✅Split knowledge AND Dual control of keys
, PCI-DSS ISA Exam Questions With
100% Verified Answers
What is considered "Sensitive Authentication Data"? -
correct answer ✅Card verification value
When a PAN is displayed to an employee who does NOT need to
see the full PAN, the minimum digits to be masked are: All digits
between the ___________ and the __________. -
correct answer ✅first 6; last 4
Regarding protection of PAN... -
correct answer ✅PAN must be rendered unreadable during the
transmission over public and wireless networks.
Under requirement 3.4, what method must be used to render the
PAN unreadable? -
correct answer ✅Hashing the entire PAN using strong
cryptography
Weak security controls that should NOT be used -
correct answer ✅WEP, SSL, and TLS 1.0 or earlier
Per requirement 5, anti-virus technology must be
deployed_________________ -