Qualys PCI EXAM QUESTIONS WITH
// // // //
ANSWERS
// //
1. Which of the following best describes the recommended
// // // // // // // //
process for achieving the PCI DSS 11.2.2 external scanning
// // // // // // // // //
requirement? - CORRECT ANSWERS(S)✔✔A)Scan, Remediate,
// // // // //
Report
//
2. Sensitive authentication data should never be: - CORRECT
// // // // // // // //
ANSWERS(S)✔✔B)Stored
//
3. PCI Security Standards Council is made up of: - CORRECT
// // // // // // // // // //
ANSWERS(S)✔✔A)Major Credit Card Companies
// // // //
4. The "stakeholder that is required to hold the Scan Customer
// // // // // // // // // //
responsible for compliance is: - CORRECT
// // // // // //
ANSWERS(S)✔✔D)QSA
//
5. vulnerability scan report that was created using the PCI Scan
// // // // // // // // // //
Report Template (in Qualys VM), will display each detected
// // // // // // // // //
vulnerability, along with its______________. - CORRECT
// // // // // //
ANSWERS(S)✔✔A)PASS/FAIL status
// //
, 6. PCI DSS 11.2.1 (internal scanning) requires the resolution
// // // // // // // //
of_________
//
vulnerabilities. - CORRECT ANSWERS(S)✔✔B)High-risk
// // //
7. When viewing vulnerability details from an external PCI scan,
// // // // // // // // //
you can view the following data (choose 3): - CORRECT
// // // // // // // // // //
ANSWERS(S)✔✔A)solution
//
B)results
D)threat
8. Which PCI DSS "Stakeholder" does Qualys represent? -
// // // // // // // //
CORRECT ANSWERS(S)✔✔A)Approved Scanning Vendor (ASV)
// // // // //
9. Which of the twelve (12) PCI DSS requirements are covered or
// // // // // // // // // // //
addressed by the Qualys PCI Compliance application? (choose 3)
// // // // // // // // //
- CORRECT ANSWERS(S)✔✔A)6
// // //
C)1
D11
10. Automated "Fault Injection" testing can typically detect
// // // // // // //
___________of Web application vulnerabilities. - CORRECT
// // // // // //
ANSWERS(S)✔✔D)80 to 85%
// // //
// // // //
ANSWERS
// //
1. Which of the following best describes the recommended
// // // // // // // //
process for achieving the PCI DSS 11.2.2 external scanning
// // // // // // // // //
requirement? - CORRECT ANSWERS(S)✔✔A)Scan, Remediate,
// // // // //
Report
//
2. Sensitive authentication data should never be: - CORRECT
// // // // // // // //
ANSWERS(S)✔✔B)Stored
//
3. PCI Security Standards Council is made up of: - CORRECT
// // // // // // // // // //
ANSWERS(S)✔✔A)Major Credit Card Companies
// // // //
4. The "stakeholder that is required to hold the Scan Customer
// // // // // // // // // //
responsible for compliance is: - CORRECT
// // // // // //
ANSWERS(S)✔✔D)QSA
//
5. vulnerability scan report that was created using the PCI Scan
// // // // // // // // // //
Report Template (in Qualys VM), will display each detected
// // // // // // // // //
vulnerability, along with its______________. - CORRECT
// // // // // //
ANSWERS(S)✔✔A)PASS/FAIL status
// //
, 6. PCI DSS 11.2.1 (internal scanning) requires the resolution
// // // // // // // //
of_________
//
vulnerabilities. - CORRECT ANSWERS(S)✔✔B)High-risk
// // //
7. When viewing vulnerability details from an external PCI scan,
// // // // // // // // //
you can view the following data (choose 3): - CORRECT
// // // // // // // // // //
ANSWERS(S)✔✔A)solution
//
B)results
D)threat
8. Which PCI DSS "Stakeholder" does Qualys represent? -
// // // // // // // //
CORRECT ANSWERS(S)✔✔A)Approved Scanning Vendor (ASV)
// // // // //
9. Which of the twelve (12) PCI DSS requirements are covered or
// // // // // // // // // // //
addressed by the Qualys PCI Compliance application? (choose 3)
// // // // // // // // //
- CORRECT ANSWERS(S)✔✔A)6
// // //
C)1
D11
10. Automated "Fault Injection" testing can typically detect
// // // // // // //
___________of Web application vulnerabilities. - CORRECT
// // // // // //
ANSWERS(S)✔✔D)80 to 85%
// // //