PCI FUNDAMENTALS EXAM
QUESTIONS AND ANSWERS. VERIFIED
2026.
ASV - ANS Approved Scanning Vendor
PCI - ANS Payment Card Industry
PTS - ANS PIN Transaction Security (device)
QSA - ANS Qualified Security Assessor
ROC - ANS Report on Compilance
ROV - ANS Report on Validation
QIR - ANS Qualified Integrator Reseller
Which entity is responsible for developing and enforcing compliance programs? -
ANS Payment Brands
1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.
, Which entity is responsible for forensic investigations of account data compromise? -
ANS Payment Brands
Which entity is response to Accept validation documentation from QSAs, PA-QSAs and ASVs -
ANS Payment Brands
Which entity is response Endorse QSA, PA-QSA and ASV company qualification criteria -
ANS Payment Brands
Merchant obligations may include submitting their compliance status to multiple entities. True
or false? - ANS True
The decision about a merchant's level is made by the - ANS Merchant's aquirer
Level 1 and 2 merchants must include ___________ as part of their PCI DSS compliance
validation reporting process? - ANS Level 1 and 2 merchants need quarterly external
vulnerability scans to be performed by an ASV. Level 2 merchants may use SAQs to validate
compliance.
SAQ - ANS Self-assessment Questionaire
Type of SAQ? Card-Not-Present (e-commerce or MO/TO) merchants, all cardholder data
functions outsourced to PCI DSS compliant service providers.
Not applicable to face-to-face channels. - ANS A
2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.
QUESTIONS AND ANSWERS. VERIFIED
2026.
ASV - ANS Approved Scanning Vendor
PCI - ANS Payment Card Industry
PTS - ANS PIN Transaction Security (device)
QSA - ANS Qualified Security Assessor
ROC - ANS Report on Compilance
ROV - ANS Report on Validation
QIR - ANS Qualified Integrator Reseller
Which entity is responsible for developing and enforcing compliance programs? -
ANS Payment Brands
1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.
, Which entity is responsible for forensic investigations of account data compromise? -
ANS Payment Brands
Which entity is response to Accept validation documentation from QSAs, PA-QSAs and ASVs -
ANS Payment Brands
Which entity is response Endorse QSA, PA-QSA and ASV company qualification criteria -
ANS Payment Brands
Merchant obligations may include submitting their compliance status to multiple entities. True
or false? - ANS True
The decision about a merchant's level is made by the - ANS Merchant's aquirer
Level 1 and 2 merchants must include ___________ as part of their PCI DSS compliance
validation reporting process? - ANS Level 1 and 2 merchants need quarterly external
vulnerability scans to be performed by an ASV. Level 2 merchants may use SAQs to validate
compliance.
SAQ - ANS Self-assessment Questionaire
Type of SAQ? Card-Not-Present (e-commerce or MO/TO) merchants, all cardholder data
functions outsourced to PCI DSS compliant service providers.
Not applicable to face-to-face channels. - ANS A
2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED.