Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 11 pages
Exam (elaborations)

PCI QUIZ 1 UPDATED ACTUAL QUESTIONS AND CORRECT ANSWERS

Document preview thumbnail
Preview 2 out of 11 pages

PCI QUIZ 1 UPDATED ACTUAL QUESTIONS AND CORRECT ANSWERS

Content preview

PCI QUIZ 1 UPDATED ACTUAL QUESTIONS AND
CORRECT ANSWERS

Question:
1. When confirming PCI-DSS requirements have been met, the accessors must always use which of the
following?
- previous reports on compliance (ROCs)
- independent judgment
- hard-copy documents
- Live testing
Answer:
independent judgment

Question:
2. Strong encryption of cardholder data is required during transmission over which of the following?
- Webservers in the DMZ and databases in an internal segment
- Any connection between host in the CDE
- Call center applications and data bases
- 4G connections from mobile terminal to the acquirer
Answer:
4G connections from mobile terminal to the acquirer

Question:
3. If network segmentation is being used to reduce the scope of the PCI-DSS assessment, what must the
assessor verify?
- All controls used for segmentation are configured properly
- The payment card brands have approved the segmentation
- The segmentation solution is one of the PCI SSC is approved segmentation solution
- The segmentation is controlled by firewall
Answer:
All controls used for segmentation are configured properly

Question:
4. Which of the following statement is true concerning transaction volumes of merchants?
- Transaction volume is based on the total number of combined transactions from all payment card brands
- Transaction volume is determined by each acquirer
- If transactions are split between two different acquirers, the merchant level is determined by halving the
transaction volume for each payment card brand
- If the transactions for different payment card brands are handled by the same acquirer, the merchant level
is determined by the total combined transaction volume of the acquirer
Answer:
Transaction volume is determined by each acquirer

, Question:
5. Which of the following is true related to use of EMV chip technology?
- PCI-DSS does not apply to the environment using EMV chip technology
- PCI-DSS applies to environments using EMV chip technology
- EMV chip technology increases the risk of fraudulent transactions in card -present environment
- Merchants are permitted to store the track equivalent data from EMV chip after authorization
Answer:
PCI-DSS applies to environments using EMV chip technology

Question:
6. Which of the following statement is true regarding card verification values/codes
(CAV2/CVC2/CVV2/CID)?
- They are sensitive authentication data (SAD), and must not be stored after authorization, even if
encrypted
- They are cardholder data and may be stored after authorization if encrypted with strong cryptography
- They are required for each recurring card-not-present transaction
- They are required for each recurring card-present transaction
Answer:
They are sensitive authentication data (SAD), and must not be stored after authorization, even if encrypted

Question:
7. In order to reduce PCI-DSS scope, what must adequate network segmentation do?
- Isolate systems that store, process, or transmit cardholder data from those that do not
- Connect databases containing cardholder data in the DMZ to the internet
- Control traffic between systems that store, process, and transmit cardholder data to those that do not
- Connect system that can store, process, or transmit cardholder data to those that do not
Answer:
Isolate systems that store, process, or transmit cardholder data from those that do not

Question:
8. Which of the following merchant environments could be eligible for SAQ B?
- Merchant with imprint machines, and electronic storage of less than 1M cardholder data records
- Merchant with stand-alone dial out terminals, and electronic storage of less than 1M cardholder data
records
- Merchant with standalone dial-out terminals, and no electronic cardholder data storage
- Merchant or service provider with imprint machines, and no electronic cardholder data storage
Answer:
Merchant or service provider with imprint machines, and no electronic cardholder data storage

Question:
9. Which of the following technologies can be configured in accordance with the requirement 2.3 for the
non-console admin access?
- FTP,VNC,SSL
- SSH, VPN, TLS
- RLOGIN, VPN, HTTPS
- SFTP, VNC, TLCS

Document information

Uploaded on
August 31, 2026
Number of pages
11
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
MGRADES
4.0
(235)
Sold
1532
Followers
108
Items
107225
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions