PCI ISA CERTIFICATION PRACTICE
EXAM 2026 QUESTIONS AND ANSWERS
1. According to PCI DSS v4.0, what is the minimum frequency for performing a formal risk
assessment?
A. Every six months
B. Annually
C. At least once every 12 months and upon significant changes
D. Every two years
Answer: C
Conceptual Explanation: PCI DSS v4.0 requires organizations to perform a formal risk
assessment at least once every 12 months and following any significant changes to the
environment.
2. Under PCI DSS Requirement 8.4.2, multi-factor authentication (MFA) is required for:
A. Only remote access to the CDE
B. All non-console access to the CDE for administrators
C. All access into the CDE for all personnel
,D. Only for third-party vendors
Answer: C
Conceptual Explanation: PCI DSS v4.0 mandates MFA for all access into the CDE, not just
for remote access or administrative access.
3. Which Self-Assessment Questionnaire (SAQ) is appropriate for merchants who outsource
all payment processing to PCI DSS validated third parties and have no electronic storage of
cardholder data?
A. SAQ B
B. SAQ A-EP
C. SAQ A
D. SAQ D
Answer: C
Conceptual Explanation: SAQ A is for card-not-present merchants (e-commerce,
mail/telephone order) who have fully outsourced all cardholder data functions to validated
third-party service providers.
4. What is the maximum time allowed for a security patch to be installed for ‘Critical’
vulnerabilities?
A. Within 24 hours
B. Within 7 days
, C. Within 90 days
D. Within one month of release
Answer: D
Conceptual Explanation: Requirement 6.3.3 requires that all critical security patches are
installed within one month of release.
5. Which of the following data elements must NOT be stored after authorization, even if
encrypted?
A. Primary Account Number (PAN)
B. Cardholder Name
C. Service Code
D. Sensitive Authentication Data (SAD)
Answer: D
Conceptual Explanation: Sensitive Authentication Data (SAD), which includes CVV2,
CVC2, and CID, must not be stored after authorization.
6. What is the primary role of an Internal Security Assessor (ISA)?
A. To perform external ASV scans for their organization
B. To audit other companies as a third-party consultant
C. To provide legal advice on PCI DSS compliance failures
EXAM 2026 QUESTIONS AND ANSWERS
1. According to PCI DSS v4.0, what is the minimum frequency for performing a formal risk
assessment?
A. Every six months
B. Annually
C. At least once every 12 months and upon significant changes
D. Every two years
Answer: C
Conceptual Explanation: PCI DSS v4.0 requires organizations to perform a formal risk
assessment at least once every 12 months and following any significant changes to the
environment.
2. Under PCI DSS Requirement 8.4.2, multi-factor authentication (MFA) is required for:
A. Only remote access to the CDE
B. All non-console access to the CDE for administrators
C. All access into the CDE for all personnel
,D. Only for third-party vendors
Answer: C
Conceptual Explanation: PCI DSS v4.0 mandates MFA for all access into the CDE, not just
for remote access or administrative access.
3. Which Self-Assessment Questionnaire (SAQ) is appropriate for merchants who outsource
all payment processing to PCI DSS validated third parties and have no electronic storage of
cardholder data?
A. SAQ B
B. SAQ A-EP
C. SAQ A
D. SAQ D
Answer: C
Conceptual Explanation: SAQ A is for card-not-present merchants (e-commerce,
mail/telephone order) who have fully outsourced all cardholder data functions to validated
third-party service providers.
4. What is the maximum time allowed for a security patch to be installed for ‘Critical’
vulnerabilities?
A. Within 24 hours
B. Within 7 days
, C. Within 90 days
D. Within one month of release
Answer: D
Conceptual Explanation: Requirement 6.3.3 requires that all critical security patches are
installed within one month of release.
5. Which of the following data elements must NOT be stored after authorization, even if
encrypted?
A. Primary Account Number (PAN)
B. Cardholder Name
C. Service Code
D. Sensitive Authentication Data (SAD)
Answer: D
Conceptual Explanation: Sensitive Authentication Data (SAD), which includes CVV2,
CVC2, and CID, must not be stored after authorization.
6. What is the primary role of an Internal Security Assessor (ISA)?
A. To perform external ASV scans for their organization
B. To audit other companies as a third-party consultant
C. To provide legal advice on PCI DSS compliance failures