QUESTIONS AND CORRECT ANSWERS
PIN Block - CORRECT ANSWER What is an example of sensitive authentication data?
Expiration Date - CORRECT ANSWER What is an example of cardholder data?
PCI SSC - CORRECT ANSWER The __________________ is an independent industry
standards body providing oversight of the development and management of Payment Card Industry
Data Security Standards on a global basis.
Covers secure payment environments that store, process or transmit account data - CORRECT
ANSWER What does PCI DSS cover?
covers secure payment applications to support PCI DSS compliance - CORRECT ANSWER
What is PCI PA-DSS?
True - CORRECT ANSWER True or False: PCI PTS PIN Security covers secure management,
processing and transmission of personal identification number (PIN) data during online and office
payment transaction processing.
False
PCI PTS - POI - CORRECT ANSWER True or False: PCI PTS - HSM covers device tamper
detection, cryptographic processes, and other mechanisms used to protect the PIN and other sensitive
data, such as cryptographic keys.
- Install payment application in a manner which supports the customer's PCI DSS compliance using
PA-DSS implementation Guide
- Document for the customer any potential risks to PCI DSS compliance
- Explain any changes made to the customer's system(s) and any potential risks to the customer
- Provide a Feedback Form to the customer
- Support PCI Forensic Investigator (PFI) investigations in the event of a breach - CORRECT
ANSWER Core responsibilities as a QIR include:
, Merchant - CORRECT ANSWER Who is responsible for a Merchant's PCI Compliance?
Implementation Statement Summary - CORRECT ANSWER The PCI SSC Listing Number,
Payment Application Vendor, Payment Application Name and Application Version Number are found
in what part of the Implementation Statement?
covers encryption, decryption and key management requirements for point-to-point encryption. -
CORRECT ANSWER What is P2PE?
Settlement - CORRECT ANSWER What is the last step in the payment processing workflow?
Clearing - CORRECT ANSWER What is the 2nd step in the payment processing workflow?
Merchant requests and receives authorization - CORRECT ANSWER What tapes place in the
Authorization portion of the payment processing workfolw?
Also called Visa and/or Mastercard - CORRECT ANSWER Which of the following is not true
of acquirers?
True - CORRECT ANSWER True or False: Compliance validation requirements vary by
payment bread.
QSA - CORRECT ANSWER Who is responsible for validating the scope of a PCI DSS
assessment?
Maintaining an internal PA-QSA - CORRECT ANSWER Which of the following is not a
responsibility of the ASV?
True - CORRECT ANSWER True or False: The QIR program aims to assume quality and
provide effective feedback among QIRs, their customers and the PCI SSC.