Qualys PCI EXAM questions with |\ |\ |\ |\ |\
answers
1. Which of the following best describes the
|\ |\ |\ |\ |\ |\ |\ |\
recommended process for achieving the PCI DSS 11.2.2 |\ |\ |\ |\ |\ |\ |\ |\
external scanning requirement? - CORRECT ANSWERS
|\ |\ |\ |\ |\ |\
✔✔A)Scan, Remediate, Report |\ |\
2. Sensitive authentication data should never be: -
|\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔B)Stored |\ |\
3. PCI Security Standards Council is made up of: -
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔A)Major Credit Card Companies
|\ |\ |\ |\ |\
4. The "stakeholder that is required to hold the Scan
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
Customer responsible for compliance is: - CORRECT
|\ |\ |\ |\ |\ |\ |\
ANSWERS ✔✔D)QSA |\
5. vulnerability scan report that was created using the PCI
|\ |\ |\ |\ |\ |\ |\ |\ |\
Scan Report Template (in Qualys VM), will display each
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
detected vulnerability, along with its______________. -
|\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔A)PASS/FAIL status
|\ |\ |\
, 6. PCI DSS 11.2.1 (internal scanning) requires the
|\ |\ |\ |\ |\ |\ |\ |\
resolution of_________ |\
vulnerabilities. - CORRECT ANSWERS ✔✔B)High-risk |\ |\ |\ |\
7. When viewing vulnerability details from an external PCI
|\ |\ |\ |\ |\ |\ |\ |\
scan, you can view the following data (choose 3): -
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔A)solution |\ |\
B)results
D)threat
8. Which PCI DSS "Stakeholder" does Qualys represent? -
|\ |\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔A)Approved Scanning Vendor
|\ |\ |\ |\ |\
(ASV)
9. Which of the twelve (12) PCI DSS requirements are
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
covered or addressed by the Qualys PCI Compliance
|\ |\ |\ |\ |\ |\ |\ |\
application? (choose 3) - CORRECT ANSWERS ✔✔A)6 |\ |\ |\ |\ |\ |\
C)1
D11
10. Automated "Fault Injection" testing can typically
|\ |\ |\ |\ |\ |\ |\
detect ___________of Web application vulnerabilities. -
|\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔D)80 to 85% |\ |\ |\ |\
answers
1. Which of the following best describes the
|\ |\ |\ |\ |\ |\ |\ |\
recommended process for achieving the PCI DSS 11.2.2 |\ |\ |\ |\ |\ |\ |\ |\
external scanning requirement? - CORRECT ANSWERS
|\ |\ |\ |\ |\ |\
✔✔A)Scan, Remediate, Report |\ |\
2. Sensitive authentication data should never be: -
|\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔B)Stored |\ |\
3. PCI Security Standards Council is made up of: -
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔A)Major Credit Card Companies
|\ |\ |\ |\ |\
4. The "stakeholder that is required to hold the Scan
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
Customer responsible for compliance is: - CORRECT
|\ |\ |\ |\ |\ |\ |\
ANSWERS ✔✔D)QSA |\
5. vulnerability scan report that was created using the PCI
|\ |\ |\ |\ |\ |\ |\ |\ |\
Scan Report Template (in Qualys VM), will display each
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
detected vulnerability, along with its______________. -
|\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔A)PASS/FAIL status
|\ |\ |\
, 6. PCI DSS 11.2.1 (internal scanning) requires the
|\ |\ |\ |\ |\ |\ |\ |\
resolution of_________ |\
vulnerabilities. - CORRECT ANSWERS ✔✔B)High-risk |\ |\ |\ |\
7. When viewing vulnerability details from an external PCI
|\ |\ |\ |\ |\ |\ |\ |\
scan, you can view the following data (choose 3): -
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔A)solution |\ |\
B)results
D)threat
8. Which PCI DSS "Stakeholder" does Qualys represent? -
|\ |\ |\ |\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔A)Approved Scanning Vendor
|\ |\ |\ |\ |\
(ASV)
9. Which of the twelve (12) PCI DSS requirements are
|\ |\ |\ |\ |\ |\ |\ |\ |\ |\
covered or addressed by the Qualys PCI Compliance
|\ |\ |\ |\ |\ |\ |\ |\
application? (choose 3) - CORRECT ANSWERS ✔✔A)6 |\ |\ |\ |\ |\ |\
C)1
D11
10. Automated "Fault Injection" testing can typically
|\ |\ |\ |\ |\ |\ |\
detect ___________of Web application vulnerabilities. -
|\ |\ |\ |\ |\ |\
CORRECT ANSWERS ✔✔D)80 to 85% |\ |\ |\ |\