PCI ISA Test Questions with Correct Answers
Types of Account Data - Cardholder Data
PAN, Cardholder Name, Expiration Datee
Types of Account Data - Sensitive Authentication Data (SAD)
Full track data (magnetic strip or chip), card verification code, and PINS
Cardholder
Purchaser
Merchant
accepts the cardholder information for purchase; merchant levels based on payment brand
Acquirer
Merchants Bank
Payment Brand Network
Facilities the transfer
Issuer
Cardholders Bank
Service Providers (TPSPs)
Directly involved in the processing, storage, or transmission of cardholder data on behalf of
another entity. If the TPSP can decrypt the data or has access to decryption keys, that it is in
scope
Requirement #1
, Install and Maintain Network Security Controls
Requirement #2
Apply secure configurations to all system components
Requirement #3
Protect Stored Account Data
Requirement #4
Protect cardholder Data with strong cryptography
Requirement #5
Protect all systems and networks from Malicious Software
Requirement #6
Develop and maintain secure systems and software
Requirement #7
Restrict Access to system components and cardholder data by business need to know
Requirement #8
Identify users and authenticate access to system components
Requirement #9
Restrict physical access to cardholder data
Requirement #10
Log and monitor all access to system components and cardholder data
Requirement #11
Types of Account Data - Cardholder Data
PAN, Cardholder Name, Expiration Datee
Types of Account Data - Sensitive Authentication Data (SAD)
Full track data (magnetic strip or chip), card verification code, and PINS
Cardholder
Purchaser
Merchant
accepts the cardholder information for purchase; merchant levels based on payment brand
Acquirer
Merchants Bank
Payment Brand Network
Facilities the transfer
Issuer
Cardholders Bank
Service Providers (TPSPs)
Directly involved in the processing, storage, or transmission of cardholder data on behalf of
another entity. If the TPSP can decrypt the data or has access to decryption keys, that it is in
scope
Requirement #1
, Install and Maintain Network Security Controls
Requirement #2
Apply secure configurations to all system components
Requirement #3
Protect Stored Account Data
Requirement #4
Protect cardholder Data with strong cryptography
Requirement #5
Protect all systems and networks from Malicious Software
Requirement #6
Develop and maintain secure systems and software
Requirement #7
Restrict Access to system components and cardholder data by business need to know
Requirement #8
Identify users and authenticate access to system components
Requirement #9
Restrict physical access to cardholder data
Requirement #10
Log and monitor all access to system components and cardholder data
Requirement #11