PCI-DSS ISA Exam
A retail vicinity that doesn't use wi-fi gadgets in keep must check for the presence of
unauthorized wi-fi devices every ________________. - ANS-area
Acquirer - ANS-Bank or entity the service provider makes use of to technique their payment
card transactions
Acquirer is likewise referred to as:
Merchant Bank
ISO (from time to time)
Payment Brand - Amex, Discover, JCB
Never Visa or MasterCard
All security activities and logs of (a) all machine components that store, procedure, or transmit
CHD; (b) critical machine additives; (c) components that carry out protection capabilities (for
instance, firewalls, intrusion-detection structures/intrusion-prevention systems (IDS/IPS),
authentication servers, e-trade redirection servers, and so on.) to be reviewed as a minimum
______________. - ANS-day by day
An example of a "one-way" cryptographic function used to render information unreadable is: -
ANS-SHA-2
Anti-virus solutions may be temporarily disabled only if - ANS-there is valid technical need, as
authorized with the aid of control on a case-through-case basis
Appendix A1 applies to - ANS-website hosting companies
Appendix A2 applies to - ANS-entities the use of SSL/Early TLS
Appendix A3 applies to - ANS-Designated Entities Supplemental Validation (DESV)
An entity is needed to undergo an assessment in step with this Appendix ONLY if told to achieve
this by way of
an acquirer or a charge logo.
ASV scans ought to cover__________________________________. - ANS-ALL
Internet-Facing IP addresses in lifestyles on the entity.
Audit logs need to be at once available for analysis for a period of ________ and must be
retained for a period of _________. - ANS-3 months; 1 year
, Compensating controls want to be evaluated at least_________________. - ANS-yearly
Compensating controls requirement 1: - ANS-Constrains
Compensating controls requirement 2: - ANS-Objective
Compensating controls requirement 3: - ANS-Risk
Compensating controls requirement four: - ANS-Definition
Compensating controls requirement 5: - ANS-Validation
Compensating controls requirement 6: - ANS-Maintenance
Data from video cameras and/or access manipulate mechanisms is reviewed, and that data is
saved for at the least ________________. - ANS-3 months
Designated entities (DESV) need to file and verify the accuracy of PCI DSS scope at
least_________ and upon large modifications to the in-scope surroundings. - ANS-quarterly
Designated Entities (DESV) should make certain that pen assessments are achieved on
"segmentation controls" each _________________, and after great adjustments. - ANS-6
months
Detection and identification of legal and unauthorized wi-fi get admission to factors should arise
_________________. - ANS-quarterly
External vulnerability scans must be run through ____________ and carry out
________________. - ANS-an ASV; quarterly
FIM equipment ought to be configured to perform essential record comparisons take a look at at
least_______________, - ANS-weekly
For outside scans, no vulnerabilities exist which are scored _____________ by way of the
CVSS. - ANS-4.Zero or higher
How many logon attempts must be allowed till ensuing temporarily account locked-out? - ANS-6
attempts
If disk encryption is used - ANS-logical get admission to should be controlled one after the other
and independently of native operating system authentication and get admission to manage
mechanisms
A retail vicinity that doesn't use wi-fi gadgets in keep must check for the presence of
unauthorized wi-fi devices every ________________. - ANS-area
Acquirer - ANS-Bank or entity the service provider makes use of to technique their payment
card transactions
Acquirer is likewise referred to as:
Merchant Bank
ISO (from time to time)
Payment Brand - Amex, Discover, JCB
Never Visa or MasterCard
All security activities and logs of (a) all machine components that store, procedure, or transmit
CHD; (b) critical machine additives; (c) components that carry out protection capabilities (for
instance, firewalls, intrusion-detection structures/intrusion-prevention systems (IDS/IPS),
authentication servers, e-trade redirection servers, and so on.) to be reviewed as a minimum
______________. - ANS-day by day
An example of a "one-way" cryptographic function used to render information unreadable is: -
ANS-SHA-2
Anti-virus solutions may be temporarily disabled only if - ANS-there is valid technical need, as
authorized with the aid of control on a case-through-case basis
Appendix A1 applies to - ANS-website hosting companies
Appendix A2 applies to - ANS-entities the use of SSL/Early TLS
Appendix A3 applies to - ANS-Designated Entities Supplemental Validation (DESV)
An entity is needed to undergo an assessment in step with this Appendix ONLY if told to achieve
this by way of
an acquirer or a charge logo.
ASV scans ought to cover__________________________________. - ANS-ALL
Internet-Facing IP addresses in lifestyles on the entity.
Audit logs need to be at once available for analysis for a period of ________ and must be
retained for a period of _________. - ANS-3 months; 1 year
, Compensating controls want to be evaluated at least_________________. - ANS-yearly
Compensating controls requirement 1: - ANS-Constrains
Compensating controls requirement 2: - ANS-Objective
Compensating controls requirement 3: - ANS-Risk
Compensating controls requirement four: - ANS-Definition
Compensating controls requirement 5: - ANS-Validation
Compensating controls requirement 6: - ANS-Maintenance
Data from video cameras and/or access manipulate mechanisms is reviewed, and that data is
saved for at the least ________________. - ANS-3 months
Designated entities (DESV) need to file and verify the accuracy of PCI DSS scope at
least_________ and upon large modifications to the in-scope surroundings. - ANS-quarterly
Designated Entities (DESV) should make certain that pen assessments are achieved on
"segmentation controls" each _________________, and after great adjustments. - ANS-6
months
Detection and identification of legal and unauthorized wi-fi get admission to factors should arise
_________________. - ANS-quarterly
External vulnerability scans must be run through ____________ and carry out
________________. - ANS-an ASV; quarterly
FIM equipment ought to be configured to perform essential record comparisons take a look at at
least_______________, - ANS-weekly
For outside scans, no vulnerabilities exist which are scored _____________ by way of the
CVSS. - ANS-4.Zero or higher
How many logon attempts must be allowed till ensuing temporarily account locked-out? - ANS-6
attempts
If disk encryption is used - ANS-logical get admission to should be controlled one after the other
and independently of native operating system authentication and get admission to manage
mechanisms