PCIP Exam Review v4.0 Questions with Correct Answers (Grade A+)
Question 1: PAN is rendered unreadable anywhere it is stored by using any of the following
approaches:
Answer: hashes
Question 2: Cardholder Data includes:
Answer: • Primary Account Number (PAN) • Cardholder Name • Expiration Date • Service Code
Question 3: Sensitive Authentication Data includes:
Answer: • Full track data (magnetic-stripe data or equivalent on a chip) • Card verification code • PINs/PIN
blocks
Question 4: account data covers the following:
Answer: the full PAN, any other elements of cardholder data that are present with the PAN, and any
elements of sensitive authentication data.
Question 5: Cannot be stored after authorization as defined in Requirement 3
Answer: Sensitive Authentication Data: full track / CVV / PIN
Question 6: Scope of PCI DSS Requirements
Answer: cardholder data environment (CDE) / System components, people, and processes that could impact
the security of the CDE
Question 7: is segmentation a requirement?
Answer: No but it can greatly reduce the scope, cost, difficulty, and risk involving processing and
compliance..
Question 8: "Flat Network"
Answer: entire network is in scope for the PCI DSS assessment ( no segmentation)
Question 9: Encrypted Cardholder Data and Impact on PCI DSS Scope
Answer: Encryption of cardholder data with strong cryptography is an acceptable method of rendering the
data unreadable according to PCI DSS Requirement 3.5. However, encryption alone is generally insufficient
to render the cardholder data out of scope for PCI DSS and does not remove the need for PCI DSS in that
environment.
Page 1
Question 1: PAN is rendered unreadable anywhere it is stored by using any of the following
approaches:
Answer: hashes
Question 2: Cardholder Data includes:
Answer: • Primary Account Number (PAN) • Cardholder Name • Expiration Date • Service Code
Question 3: Sensitive Authentication Data includes:
Answer: • Full track data (magnetic-stripe data or equivalent on a chip) • Card verification code • PINs/PIN
blocks
Question 4: account data covers the following:
Answer: the full PAN, any other elements of cardholder data that are present with the PAN, and any
elements of sensitive authentication data.
Question 5: Cannot be stored after authorization as defined in Requirement 3
Answer: Sensitive Authentication Data: full track / CVV / PIN
Question 6: Scope of PCI DSS Requirements
Answer: cardholder data environment (CDE) / System components, people, and processes that could impact
the security of the CDE
Question 7: is segmentation a requirement?
Answer: No but it can greatly reduce the scope, cost, difficulty, and risk involving processing and
compliance..
Question 8: "Flat Network"
Answer: entire network is in scope for the PCI DSS assessment ( no segmentation)
Question 9: Encrypted Cardholder Data and Impact on PCI DSS Scope
Answer: Encryption of cardholder data with strong cryptography is an acceptable method of rendering the
data unreadable according to PCI DSS Requirement 3.5. However, encryption alone is generally insufficient
to render the cardholder data out of scope for PCI DSS and does not remove the need for PCI DSS in that
environment.
Page 1