PCI DSS Extra Exam Questions And
Answers
Compensating controls can be documented in which section of the
SAQ? -
correct answer ✅Appendix B
The following are examples of common PCI DSS control failures
except: -
correct answer ✅a) Inadequate access controls due to improperly
installed point-of-sale (POS) systems, allowing malicious users in via
paths intended for POS vendors (Requirements 7.1, &.2, *.2, and
*.3).
b) Storage of sensitive authentication data (SAD), such as track
data, after authorization (Requirement 3.2).
c) Unnecessary and insecure services not removed or secured when
the system was installed (Requirements 2.2.2 and 2.2.3).
d) Missing and outdated security patches (Requirement 6.2)
e) Ensuring audit Logging is running (Requirement 10)
A common error in scoping a PCI DSS assessment includes: -
correct answer ✅Assuming encrypted data is out-of-scope
, PCI DSS Extra Exam Questions And
Answers
GPRS Refers to: -
correct answer ✅Acronym for "General Radio Service." Mobile
data service available to users of GSM mobile phones.
The PCI DSS Self-Assessment Questionnaires (SAQs) are validation
tools intended to assist merchants and service providers in self-
evaluating their compliance with PCI DSS. -
correct answer ✅True
The purpose of a Qualified Integrator and Reseller (QIR) reseller
does not include: -
correct answer ✅Being qualified to assess payment applications
against the PA-DSS standard.
This is hardware and/or software used to process payment card
transactions at merchant locations. -
correct answer ✅POS/POI - Point-of-Sale/Point-of-Interaction
When assessing if a cardholder data should be stored, which should
not be considered? -
correct answer ✅If Payment brand rules allow for the storage of
primary account number(PAN)
Answers
Compensating controls can be documented in which section of the
SAQ? -
correct answer ✅Appendix B
The following are examples of common PCI DSS control failures
except: -
correct answer ✅a) Inadequate access controls due to improperly
installed point-of-sale (POS) systems, allowing malicious users in via
paths intended for POS vendors (Requirements 7.1, &.2, *.2, and
*.3).
b) Storage of sensitive authentication data (SAD), such as track
data, after authorization (Requirement 3.2).
c) Unnecessary and insecure services not removed or secured when
the system was installed (Requirements 2.2.2 and 2.2.3).
d) Missing and outdated security patches (Requirement 6.2)
e) Ensuring audit Logging is running (Requirement 10)
A common error in scoping a PCI DSS assessment includes: -
correct answer ✅Assuming encrypted data is out-of-scope
, PCI DSS Extra Exam Questions And
Answers
GPRS Refers to: -
correct answer ✅Acronym for "General Radio Service." Mobile
data service available to users of GSM mobile phones.
The PCI DSS Self-Assessment Questionnaires (SAQs) are validation
tools intended to assist merchants and service providers in self-
evaluating their compliance with PCI DSS. -
correct answer ✅True
The purpose of a Qualified Integrator and Reseller (QIR) reseller
does not include: -
correct answer ✅Being qualified to assess payment applications
against the PA-DSS standard.
This is hardware and/or software used to process payment card
transactions at merchant locations. -
correct answer ✅POS/POI - Point-of-Sale/Point-of-Interaction
When assessing if a cardholder data should be stored, which should
not be considered? -
correct answer ✅If Payment brand rules allow for the storage of
primary account number(PAN)