PCIP Exam, Questions with Correct Answers (Grade A+)
Question 1: PCI Data Security Standard (PCI DSS)
Answer: The PCI DSS applies to all entities that store, process, and/or transmit cardholder data. It covers
technical and operational system components included in or connected to cardholder data. If you accept or
process payment cards, PCI DSS applies to you.
Question 2: Sensitive Authentication Data
Answer: Merchants, service providers, and other entities involved with payment card processing must never
store sensitive authentication data after authorization. This includes the 3- or 4- digit security code printed
on the front or back of a card (CVD), the data stored on a card's magnetic stripe or chip (also called "Full
Track Data") - and personal identification numbers (PIN) entered by the cardholder.
Question 3: Card Verification Data Codes (CVD)
Answer: 3 or 4 digit code that further authenticates a not-present cardholder Visa-CVV2 MC- CVC2
Discover- CVD JCB-CAV2 AmEx- CID
Question 4: Requirement 1
Answer: Install and maintain a firewall configuration to protect cardholder data
Question 5: Network devices in scope for Requirement 1
Answer: Firewalls and Routers- Routers connect traffic between networks, Firewalls control the traffic
between networks and within internal network
Page 1
,Question 6: QIR Qualified Integrators & Resellers
Answer: Qualified Integrators & Resellersauthorized by the SSC to implement, configure and/or support
PA-DSS payment applications. Visa requires all level 4 merchants use QIRs for POS application and
terminal installation and servicing
Question 7: Compensating Controls
Answer: An alternative control, put in place to satisfy the requirement for a security measure that is deemed
too difficult or impractical to implement at the present time.
Question 8: Permitted reasons for using Compensating Controls
Answer: Organizations needing an alternative to security requirements that could not be met due to
legitimate technological OR documented business constraints, but has sufficiently mitigated the risk
associated with the requirement through implementation of other compensating controls
Question 9: Examples of Compensating Controls
Answer: (i) Segregation of Duties (SOD) and (ii) Encryption
Question 10: Compensating Controls must:
Answer: 1) Meet the intent and rigor of the original stated requirement; 2) Provide a similar level of defense
as the original stated requirement; 3) Be "above and beyond" other PCI DSS requirements (not simply in
compliance with other PCI DSS requirements); and 4) Be commensurate with the additional risk imposed
by not adhering to the original stated requirement.
Question 11: Compensating Controls Worksheet
Answer: 1) Constraint; 2) Objective; 3) Identified Risk; 4) Define Compensating Control; 5)Validate
Controls; 6) Maintenance (COIDVM)
Question 12: Card Data that cannot be stored by Merchants, Service providers after authorization
Answer: Sensitive Authentication Data. i) 3- or 4- digit security code printed on the front or back of a card,
ii) data stored on a card's magnetic stripe or chip (also called "Full Track Data"), and iii) personal
identification numbers (PIN) entered by the cardholder
Question 13: Card Data that MAY be stored
Answer: i) cardholder name, ii) service code (identifies industry iii) Personal Account Number (PAN) iv)
expiration date may be stored.
Page 2
, Question 14: Network Segmentation
Answer: The process of isolating the cardholder data environment from the remainder of an entity's network
Not a requirement but strongly recommended.
Question 15: Report on Compliance (ROC)
Answer: Prepared at the time of the assessment of PCI compliance and comprehensively provides details
about the assessment approach and compliance standing against each PCI DSS requirement
Question 16: What is included in the Report on Compliance (ROC)?
Answer: ROC includes (1) Executive summary, (2) description of scope of work and approach taken, (3)
details about reviewed environment, (4) contact information and report date, (5) quarterly scan results and
(6) findings and observations.
Question 17: Steps to take for a PCI Assessment (hint: SARA's Remediation)
Answer: 1. Scope - determine which system components and networks are in scope for PCI DSS 2. Assess -
examine the compliance of system components in scope following the testing procedures for each PCI DSS
requirement 3. Report - assessor and/or entity completes required documentation (e.g. Self-Assessment
Questionnaire (SAQ) or Report on Compliance (ROC)), including documentation of all compensating
controls 4. Attest - complete the appropriate Attestation of Compliance (AOC) 5. Submit - submit the SAQ,
ROC, AOC and other requested supporting documentation such as ASV scan reports to the acquirer (for
merchants) or to the payment brand/requestor (for service providers) 6. Remediate - if required, perform
remediation to address requirements that are not in place, and
Question 18: Who can complete a Self Assessment Questionnaire (SAQ)?
Answer: i) the organization themselves, or ii) by a third party (e.g. IBM)
Question 19: Who MUST complete a Report on Compliance?
Answer: It MUST be completed by an approved Qualified Security Assessor (QSA) through the PCI
Security Standards Council
Question 20: What is included in PCI Scope Review?
Answer: 1) Document the cardholder data flow; 2)develop a network diagram that documents all of the
firewalls, routers, switches, access points, servers and other network devices and how they are architected;
3) scan your entire network to confirm that cardholder data is not stored anywhere outside of the CDE
(Generally, you need to identify all locations and flows and ensure that they are included in scope.)
Page 3
Question 1: PCI Data Security Standard (PCI DSS)
Answer: The PCI DSS applies to all entities that store, process, and/or transmit cardholder data. It covers
technical and operational system components included in or connected to cardholder data. If you accept or
process payment cards, PCI DSS applies to you.
Question 2: Sensitive Authentication Data
Answer: Merchants, service providers, and other entities involved with payment card processing must never
store sensitive authentication data after authorization. This includes the 3- or 4- digit security code printed
on the front or back of a card (CVD), the data stored on a card's magnetic stripe or chip (also called "Full
Track Data") - and personal identification numbers (PIN) entered by the cardholder.
Question 3: Card Verification Data Codes (CVD)
Answer: 3 or 4 digit code that further authenticates a not-present cardholder Visa-CVV2 MC- CVC2
Discover- CVD JCB-CAV2 AmEx- CID
Question 4: Requirement 1
Answer: Install and maintain a firewall configuration to protect cardholder data
Question 5: Network devices in scope for Requirement 1
Answer: Firewalls and Routers- Routers connect traffic between networks, Firewalls control the traffic
between networks and within internal network
Page 1
,Question 6: QIR Qualified Integrators & Resellers
Answer: Qualified Integrators & Resellersauthorized by the SSC to implement, configure and/or support
PA-DSS payment applications. Visa requires all level 4 merchants use QIRs for POS application and
terminal installation and servicing
Question 7: Compensating Controls
Answer: An alternative control, put in place to satisfy the requirement for a security measure that is deemed
too difficult or impractical to implement at the present time.
Question 8: Permitted reasons for using Compensating Controls
Answer: Organizations needing an alternative to security requirements that could not be met due to
legitimate technological OR documented business constraints, but has sufficiently mitigated the risk
associated with the requirement through implementation of other compensating controls
Question 9: Examples of Compensating Controls
Answer: (i) Segregation of Duties (SOD) and (ii) Encryption
Question 10: Compensating Controls must:
Answer: 1) Meet the intent and rigor of the original stated requirement; 2) Provide a similar level of defense
as the original stated requirement; 3) Be "above and beyond" other PCI DSS requirements (not simply in
compliance with other PCI DSS requirements); and 4) Be commensurate with the additional risk imposed
by not adhering to the original stated requirement.
Question 11: Compensating Controls Worksheet
Answer: 1) Constraint; 2) Objective; 3) Identified Risk; 4) Define Compensating Control; 5)Validate
Controls; 6) Maintenance (COIDVM)
Question 12: Card Data that cannot be stored by Merchants, Service providers after authorization
Answer: Sensitive Authentication Data. i) 3- or 4- digit security code printed on the front or back of a card,
ii) data stored on a card's magnetic stripe or chip (also called "Full Track Data"), and iii) personal
identification numbers (PIN) entered by the cardholder
Question 13: Card Data that MAY be stored
Answer: i) cardholder name, ii) service code (identifies industry iii) Personal Account Number (PAN) iv)
expiration date may be stored.
Page 2
, Question 14: Network Segmentation
Answer: The process of isolating the cardholder data environment from the remainder of an entity's network
Not a requirement but strongly recommended.
Question 15: Report on Compliance (ROC)
Answer: Prepared at the time of the assessment of PCI compliance and comprehensively provides details
about the assessment approach and compliance standing against each PCI DSS requirement
Question 16: What is included in the Report on Compliance (ROC)?
Answer: ROC includes (1) Executive summary, (2) description of scope of work and approach taken, (3)
details about reviewed environment, (4) contact information and report date, (5) quarterly scan results and
(6) findings and observations.
Question 17: Steps to take for a PCI Assessment (hint: SARA's Remediation)
Answer: 1. Scope - determine which system components and networks are in scope for PCI DSS 2. Assess -
examine the compliance of system components in scope following the testing procedures for each PCI DSS
requirement 3. Report - assessor and/or entity completes required documentation (e.g. Self-Assessment
Questionnaire (SAQ) or Report on Compliance (ROC)), including documentation of all compensating
controls 4. Attest - complete the appropriate Attestation of Compliance (AOC) 5. Submit - submit the SAQ,
ROC, AOC and other requested supporting documentation such as ASV scan reports to the acquirer (for
merchants) or to the payment brand/requestor (for service providers) 6. Remediate - if required, perform
remediation to address requirements that are not in place, and
Question 18: Who can complete a Self Assessment Questionnaire (SAQ)?
Answer: i) the organization themselves, or ii) by a third party (e.g. IBM)
Question 19: Who MUST complete a Report on Compliance?
Answer: It MUST be completed by an approved Qualified Security Assessor (QSA) through the PCI
Security Standards Council
Question 20: What is included in PCI Scope Review?
Answer: 1) Document the cardholder data flow; 2)develop a network diagram that documents all of the
firewalls, routers, switches, access points, servers and other network devices and how they are architected;
3) scan your entire network to confirm that cardholder data is not stored anywhere outside of the CDE
(Generally, you need to identify all locations and flows and ensure that they are included in scope.)
Page 3