PCI Practice Test 2 with all Correct & 100% Verified
Answers |Guaranteed to Pass |Already Graded A+
Which of the below functions is associated with acquirers?
- Provide clearing services to a merchant
- Provide authorization services to the merchant
- All of the options
- Provide settlement services to the merchant ✔Correct Answer-All of the options
If virtualization technologies are used in cardholder data environment?
- Virtualization technologies are not to be used in the cardholder data environment
- The virtualization technologies are not in scope for PCI-DSS
- Entities using virtualization technologies should be complete SAQ C
- The virtualization technologies are included in scope for PCI DSS ✔Correct Answer-The
virtualization technologies are included in scope for PCI DSS
Access to view audit trails should be granted _____.
- only to individuals with a job-related need
- So that no personnel can view the logs
- To all system operators
- To all personnel ✔Correct Answer-only to individuals with a job-related need
Audit logs must be immediately available for analysis for a period of ____ and must be retained for a
period of _____.
- 3 months and 1 year
- 6 months and 1 year
- 2 months and 2 years
- 2 months and 1 year ✔Correct Answer-3 months and 1 year
Which of the following is true regarding protection of PAN?
- PAN must be rendered unreadable during transmission over public , wireless networks
- There are no PCI-DSS requirements for rendering PAN unreadable
- PAN must be rendered unreadable during transmission over private, secure network
- PAN must be rendered unreadable when present in volatile memory during a transaction
✔Correct Answer-PAN must be rendered unreadable during transmission over public , wireless
networks
One of the principles to be used when granting user access to systems in the CDE is:
- Default allow all
- Equal privilege
- Least privilege
- Most privilege ✔Correct Answer-Least privilege
Storing track data "long term" or "persistently" is permitted when_______.
- It is hashed by the merchants storing it.
- It is reported to the PCI SSC annually in a ROC
- It is encrypted by the merchant storing it.
- It is being stored by the issuers ✔Correct Answer-It is being stored by the issuers
, The decision about a merchant's level is made by the:
- Merchant's QSA
- Payment Brands
- Merchant
- Merchant's acquirer ✔Correct Answer-Merchant's acquirer
Which of the following is considered "sensitive authentication data"?
- Cardholder name
- Expiration date
- Card verification value
- PAN ✔Correct Answer-Card verification value
PCI-DSS Requirement 3.4 stats that PAN must be rendered unreadable when stored. Which of the
following must be used to meet the requirement?
- Encryption in the first six and the last four numbers of the PAN
- Hiding the column containing PAN data in the database
- Hashing the entire PAN using strong cryptography
- Masking the entire PAN using industry standards ✔Correct Answer-Hashing the entire PAN using
strong cryptography
Which of the following are parts if payment brand role? (Select all that apply)
- Develop and enforce compliance programs
- Endorse QSA, PA-QSA and ASV company qualification criteria
- Accept validation documentation from QSAs, PA-QSAs & ASV's
- Offer training for QSAs, PA. QSAs and ASVs ✔Correct Answer-Develop and enforce compliance
programs
Endorse QSA, PA-QSA and ASV company qualification criteria
Accept validation documentation from QSAs, PA-QSAs & ASV's
In which step does the payment brand network provide complete reconciliation to the merchant's
bank?
- Approval
- Clearing
- Settlement
- Authorization ✔Correct Answer-Clearing
Account data consists of _______ and ________.
- Cardholder data and Sensitive authentication data
- Card holder names and PANs
- PANs and PINs
- Cardholder data and PANs ✔Correct Answer-Cardholder data and Sensitive authentication data
Which entity is responsible for forensic investigations of account data compromise?
- QSA/ISA
-QIR
- PCI SSC
- Payment cards brands ✔Correct Answer-Payment cards brands
In order to be considered a compensating control, which of the following must exist?
- A documented business constraint
- A legitimate technical constraint and a documented business constraint
Answers |Guaranteed to Pass |Already Graded A+
Which of the below functions is associated with acquirers?
- Provide clearing services to a merchant
- Provide authorization services to the merchant
- All of the options
- Provide settlement services to the merchant ✔Correct Answer-All of the options
If virtualization technologies are used in cardholder data environment?
- Virtualization technologies are not to be used in the cardholder data environment
- The virtualization technologies are not in scope for PCI-DSS
- Entities using virtualization technologies should be complete SAQ C
- The virtualization technologies are included in scope for PCI DSS ✔Correct Answer-The
virtualization technologies are included in scope for PCI DSS
Access to view audit trails should be granted _____.
- only to individuals with a job-related need
- So that no personnel can view the logs
- To all system operators
- To all personnel ✔Correct Answer-only to individuals with a job-related need
Audit logs must be immediately available for analysis for a period of ____ and must be retained for a
period of _____.
- 3 months and 1 year
- 6 months and 1 year
- 2 months and 2 years
- 2 months and 1 year ✔Correct Answer-3 months and 1 year
Which of the following is true regarding protection of PAN?
- PAN must be rendered unreadable during transmission over public , wireless networks
- There are no PCI-DSS requirements for rendering PAN unreadable
- PAN must be rendered unreadable during transmission over private, secure network
- PAN must be rendered unreadable when present in volatile memory during a transaction
✔Correct Answer-PAN must be rendered unreadable during transmission over public , wireless
networks
One of the principles to be used when granting user access to systems in the CDE is:
- Default allow all
- Equal privilege
- Least privilege
- Most privilege ✔Correct Answer-Least privilege
Storing track data "long term" or "persistently" is permitted when_______.
- It is hashed by the merchants storing it.
- It is reported to the PCI SSC annually in a ROC
- It is encrypted by the merchant storing it.
- It is being stored by the issuers ✔Correct Answer-It is being stored by the issuers
, The decision about a merchant's level is made by the:
- Merchant's QSA
- Payment Brands
- Merchant
- Merchant's acquirer ✔Correct Answer-Merchant's acquirer
Which of the following is considered "sensitive authentication data"?
- Cardholder name
- Expiration date
- Card verification value
- PAN ✔Correct Answer-Card verification value
PCI-DSS Requirement 3.4 stats that PAN must be rendered unreadable when stored. Which of the
following must be used to meet the requirement?
- Encryption in the first six and the last four numbers of the PAN
- Hiding the column containing PAN data in the database
- Hashing the entire PAN using strong cryptography
- Masking the entire PAN using industry standards ✔Correct Answer-Hashing the entire PAN using
strong cryptography
Which of the following are parts if payment brand role? (Select all that apply)
- Develop and enforce compliance programs
- Endorse QSA, PA-QSA and ASV company qualification criteria
- Accept validation documentation from QSAs, PA-QSAs & ASV's
- Offer training for QSAs, PA. QSAs and ASVs ✔Correct Answer-Develop and enforce compliance
programs
Endorse QSA, PA-QSA and ASV company qualification criteria
Accept validation documentation from QSAs, PA-QSAs & ASV's
In which step does the payment brand network provide complete reconciliation to the merchant's
bank?
- Approval
- Clearing
- Settlement
- Authorization ✔Correct Answer-Clearing
Account data consists of _______ and ________.
- Cardholder data and Sensitive authentication data
- Card holder names and PANs
- PANs and PINs
- Cardholder data and PANs ✔Correct Answer-Cardholder data and Sensitive authentication data
Which entity is responsible for forensic investigations of account data compromise?
- QSA/ISA
-QIR
- PCI SSC
- Payment cards brands ✔Correct Answer-Payment cards brands
In order to be considered a compensating control, which of the following must exist?
- A documented business constraint
- A legitimate technical constraint and a documented business constraint