PCI Data Security Standard Exam
Questions With 100% Verified Answers
-Customer purchasing goods either as a "Card Present" or Card Not
Present" transaction
-Receives the payment card and bills from the issuer -
correct answer ✅Cardholder
-Primary Account Number (PAN)
-Cardholder Name
-Expiration Date
-Service Code -
correct answer ✅Cardholder Data Include:
-Full track data (Magnetic-stripe data or equivalent on a chip)
-CAV2/CVC2/CVV2/CID
-PINs/PIN blocks -
correct answer ✅Sensitive Authentication Data includes:
American Express
Discover
JCB International
,PCI Data Security Standard Exam
Questions With 100% Verified Answers
MasterCard
Visa -
correct answer ✅Payment Brand
-Bank or other organization issuing a payment card on behalf of a
Payment Brand (e.g. MasterCard & Visa)
-Payment Brand issuing a payment card directly (e.g. Amex,
Discover, JCB) -
correct answer ✅Issuer
Organization accepting the payment card for payment during a
purchase -
correct answer ✅Merchant
*Bank or entity the merchant uses to process their payment card
transactions
*Receive authorization request from merchant and forward to
Issuer for approval
*Provide authorization, clearing, and settlement services to
merchants
*Acquirer is also called
,PCI Data Security Standard Exam
Questions With 100% Verified Answers
--Merchant Bank
--ISO
--Payment Brand -Amex, Discover, JCB
--Never Visa or MasterCard -
correct answer ✅Acquirer
*Acquirer is responsible for merchant compliance
--Know payment brand compliance programs and how they apply
to merchants
--Ensure that their merchants understand PCI DSS compliance
requirements and track compliance efforts
--Manage Merchant communications
*work with merchants until compliance has been validated
--Merchants are not compliant until all applicable requirements
have been met and validated
--Acquirer is responsible for providing merchant compliance status
to payment brands
, PCI Data Security Standard Exam
Questions With 100% Verified Answers
*Incur any liability that may result from non-compliance with
payment brand compliance programs -
correct answer ✅Common Acquirer Responsibilities
*A service provider is a business that is not a payment brand,
directly involved in the processing, storage, or transmission of
cardholder data on behalf of another entity.
-Sometimes a service provider is a merchant
*Service Provider also includes companies that provide services (to
merchants, service providers, or other entities), which control or
could impact the security of cardholder data -
correct answer ✅Service Providers
1. Install and maintain a firewall configuration to protect cardholder
data
2. Do not use vendor-supplied defaults for system passwords and
other security parameters -
correct answer ✅Standard 1: Build and Maintain a Secure Network
and Systems
Questions With 100% Verified Answers
-Customer purchasing goods either as a "Card Present" or Card Not
Present" transaction
-Receives the payment card and bills from the issuer -
correct answer ✅Cardholder
-Primary Account Number (PAN)
-Cardholder Name
-Expiration Date
-Service Code -
correct answer ✅Cardholder Data Include:
-Full track data (Magnetic-stripe data or equivalent on a chip)
-CAV2/CVC2/CVV2/CID
-PINs/PIN blocks -
correct answer ✅Sensitive Authentication Data includes:
American Express
Discover
JCB International
,PCI Data Security Standard Exam
Questions With 100% Verified Answers
MasterCard
Visa -
correct answer ✅Payment Brand
-Bank or other organization issuing a payment card on behalf of a
Payment Brand (e.g. MasterCard & Visa)
-Payment Brand issuing a payment card directly (e.g. Amex,
Discover, JCB) -
correct answer ✅Issuer
Organization accepting the payment card for payment during a
purchase -
correct answer ✅Merchant
*Bank or entity the merchant uses to process their payment card
transactions
*Receive authorization request from merchant and forward to
Issuer for approval
*Provide authorization, clearing, and settlement services to
merchants
*Acquirer is also called
,PCI Data Security Standard Exam
Questions With 100% Verified Answers
--Merchant Bank
--ISO
--Payment Brand -Amex, Discover, JCB
--Never Visa or MasterCard -
correct answer ✅Acquirer
*Acquirer is responsible for merchant compliance
--Know payment brand compliance programs and how they apply
to merchants
--Ensure that their merchants understand PCI DSS compliance
requirements and track compliance efforts
--Manage Merchant communications
*work with merchants until compliance has been validated
--Merchants are not compliant until all applicable requirements
have been met and validated
--Acquirer is responsible for providing merchant compliance status
to payment brands
, PCI Data Security Standard Exam
Questions With 100% Verified Answers
*Incur any liability that may result from non-compliance with
payment brand compliance programs -
correct answer ✅Common Acquirer Responsibilities
*A service provider is a business that is not a payment brand,
directly involved in the processing, storage, or transmission of
cardholder data on behalf of another entity.
-Sometimes a service provider is a merchant
*Service Provider also includes companies that provide services (to
merchants, service providers, or other entities), which control or
could impact the security of cardholder data -
correct answer ✅Service Providers
1. Install and maintain a firewall configuration to protect cardholder
data
2. Do not use vendor-supplied defaults for system passwords and
other security parameters -
correct answer ✅Standard 1: Build and Maintain a Secure Network
and Systems