PCI DSS QSA ACTUAL EXAM
QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED
ANSWERS)
Who is Acquirer -
correct answer ✅Also referred to as "merchant bank," "acquiring
bank," or "acquiring financial institution". Entity, typically a financial
institution, that processes payment card transactions for merchants
and is defined by a payment brand as an acquirer. Acquirers are
subject to payment brand rules and procedures regarding merchant
compliance
AOC -
correct answer ✅Acronym for "attestation of compliance". The
AOC is a form for merchants and service providers to attest to the
results of a PCI DSS assessment, as documented in the Self-
Assessment Questionnaire or Report on Compliance
ASV -
correct answer ✅Acronym for "approved Scanning Vendor".
Company approved by the PCI SSC to conduct external vulnerability
scanning services.
What is Authorization? -
correct answer ✅Cardholder swipes card at merchant, acquirer
,PCI DSS QSA ACTUAL EXAM
QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED
ANSWERS)
asks payment brand network to determine issuer, issuer approves
purchase, payment network sends the approval to acquirer,
acquirer sends approval to merchant, merchant displays
"approved" and completes purchase.
What is Settlement? -
correct answer ✅Issuer determines acquirer via payment network,
issuer sends payment to acquirer, acquirer pay merchant for
cardholder's purchases, issuer bills the cardholder.
Who is Service Provider? -
correct answer ✅A business that is not a payment brand, directly
involved in the processing, storage or transmission of cardholder
data on behalf of another entity.
SAQ A -
correct answer ✅Card not Present (e commerce or MO/TO)
merchants, all cardholder data functions outsourced to compliant
service providers.
, PCI DSS QSA ACTUAL EXAM
QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED
ANSWERS)
SAQ A-EP -
correct answer ✅Applies to E-Commerce merchants who
outsoruce all payment processing to PCI DSS validated third parties,
and who have website(s) that doesn't directly receive cardholder
data but that can impact the security of the payment transaction.
No electronic storage, processing or transmission of any cardholder
data on the merchants systems and premises.
SAQ B -
correct answer ✅Applies to Imprint only merchants with no
electronic cardholder data storage or standalone, dial out terminal
merchants with no electronic cardholder data storage.
SAQ B-IP -
correct answer ✅Used for merchants who process payments via
standalone PTS-approved point-of-interaction (POI) devices with an
IP connection to the payment processor with no electronic
cardholder data storage.
QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED
ANSWERS)
Who is Acquirer -
correct answer ✅Also referred to as "merchant bank," "acquiring
bank," or "acquiring financial institution". Entity, typically a financial
institution, that processes payment card transactions for merchants
and is defined by a payment brand as an acquirer. Acquirers are
subject to payment brand rules and procedures regarding merchant
compliance
AOC -
correct answer ✅Acronym for "attestation of compliance". The
AOC is a form for merchants and service providers to attest to the
results of a PCI DSS assessment, as documented in the Self-
Assessment Questionnaire or Report on Compliance
ASV -
correct answer ✅Acronym for "approved Scanning Vendor".
Company approved by the PCI SSC to conduct external vulnerability
scanning services.
What is Authorization? -
correct answer ✅Cardholder swipes card at merchant, acquirer
,PCI DSS QSA ACTUAL EXAM
QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED
ANSWERS)
asks payment brand network to determine issuer, issuer approves
purchase, payment network sends the approval to acquirer,
acquirer sends approval to merchant, merchant displays
"approved" and completes purchase.
What is Settlement? -
correct answer ✅Issuer determines acquirer via payment network,
issuer sends payment to acquirer, acquirer pay merchant for
cardholder's purchases, issuer bills the cardholder.
Who is Service Provider? -
correct answer ✅A business that is not a payment brand, directly
involved in the processing, storage or transmission of cardholder
data on behalf of another entity.
SAQ A -
correct answer ✅Card not Present (e commerce or MO/TO)
merchants, all cardholder data functions outsourced to compliant
service providers.
, PCI DSS QSA ACTUAL EXAM
QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED
ANSWERS)
SAQ A-EP -
correct answer ✅Applies to E-Commerce merchants who
outsoruce all payment processing to PCI DSS validated third parties,
and who have website(s) that doesn't directly receive cardholder
data but that can impact the security of the payment transaction.
No electronic storage, processing or transmission of any cardholder
data on the merchants systems and premises.
SAQ B -
correct answer ✅Applies to Imprint only merchants with no
electronic cardholder data storage or standalone, dial out terminal
merchants with no electronic cardholder data storage.
SAQ B-IP -
correct answer ✅Used for merchants who process payments via
standalone PTS-approved point-of-interaction (POI) devices with an
IP connection to the payment processor with no electronic
cardholder data storage.