PCIP Practice Questions with Correct Answers (Grade A+)
Question 1: Which of the below functions is associated with Acquirers?
A. Provide settlement services to a merchant
B. Provide authorization services to a merchant
C. Provide clearing services to a merchant
D. All of the options
Answer: D. All of the options
Question 2: Which of the following entities will actually approve a purchase?
A. Non-Issuing Merchant Bank
B. Issuing Bank
C. Payment Transaction Gateway
D. Acquiring Bank
Answer: B. Issuing Bank
Question 3: Which of the following lists the correct "order" for the flow of a payment card transaction?
A. Clearing, Settlement, Authorization
B. Clearing, Authorization, Settlement
C. Authorization, Clearing, Settlement
D. Authorization, Settlement, Clearing
Answer: C. Authorization, Clearing, Settlement
Question 4: Service Providers include companies which_____________or could______________the
security of cardholder data.
A. are PCI compliant, prove effective controls for
B. control, impact
C. manage, test
D. control, subrogate
Answer: B. control, impact
Question 5: QUESTION 16 Cardholder Data may be stored in "KNOWN" and "UN- KNOWN"
locations.
A. True
B. False
Answer: A. True
Page 1
, Question 6: Storing Track Data "Long-Term" or "persistently" may be permitted if_______________.
A. it is being stored by issuers
B. it is reported to the PCI SSC annually in a RoC
C. it is encrypted by the merchant storing it
D. it is hashed by the merchant storing it
Answer: A. it is being stored by issuers
Question 7: PCI DSS Requirement 3.4 states the PAN must be rendered unreadable when stored,
using___________.
A. Encryption, Truncation, or Obfuscating
B. Hashing, Scrambling, or Encrypting
C. Encryption, Hashing, or Truncation
D. Truncation, Scrambling, or Encrypting
Answer: C. Encryption, Hashing, or Truncation
Question 8: Requirement 2.2.2 states "Enable only necessary and secure services, protocols, daemons,
etc., as required for the function of the system". Which of the following is considered secure?
A. SSH
B. RLogon
C. Telnet
D. FTP
Answer: A. SSH
Question 9: When scoping an environment for a PCI DSS assessment, it is important to identify
_______________.
A. All flows of cardholder data
B. All of the options
C. Components that store cardholder data
D. Business facilities involved in processing transactions
Answer: B. All of the options
Question 10: QUESTION 21 Merchants involved with only e-commerce transactions that are
completely outsourced to a PCI DSS compliant service provider would use which SAQ?
A. SAQ C/VT
B. SAQ B
C. SAQ D
D. SAQ A
Answer: D. SAQ A
Page 2
Question 1: Which of the below functions is associated with Acquirers?
A. Provide settlement services to a merchant
B. Provide authorization services to a merchant
C. Provide clearing services to a merchant
D. All of the options
Answer: D. All of the options
Question 2: Which of the following entities will actually approve a purchase?
A. Non-Issuing Merchant Bank
B. Issuing Bank
C. Payment Transaction Gateway
D. Acquiring Bank
Answer: B. Issuing Bank
Question 3: Which of the following lists the correct "order" for the flow of a payment card transaction?
A. Clearing, Settlement, Authorization
B. Clearing, Authorization, Settlement
C. Authorization, Clearing, Settlement
D. Authorization, Settlement, Clearing
Answer: C. Authorization, Clearing, Settlement
Question 4: Service Providers include companies which_____________or could______________the
security of cardholder data.
A. are PCI compliant, prove effective controls for
B. control, impact
C. manage, test
D. control, subrogate
Answer: B. control, impact
Question 5: QUESTION 16 Cardholder Data may be stored in "KNOWN" and "UN- KNOWN"
locations.
A. True
B. False
Answer: A. True
Page 1
, Question 6: Storing Track Data "Long-Term" or "persistently" may be permitted if_______________.
A. it is being stored by issuers
B. it is reported to the PCI SSC annually in a RoC
C. it is encrypted by the merchant storing it
D. it is hashed by the merchant storing it
Answer: A. it is being stored by issuers
Question 7: PCI DSS Requirement 3.4 states the PAN must be rendered unreadable when stored,
using___________.
A. Encryption, Truncation, or Obfuscating
B. Hashing, Scrambling, or Encrypting
C. Encryption, Hashing, or Truncation
D. Truncation, Scrambling, or Encrypting
Answer: C. Encryption, Hashing, or Truncation
Question 8: Requirement 2.2.2 states "Enable only necessary and secure services, protocols, daemons,
etc., as required for the function of the system". Which of the following is considered secure?
A. SSH
B. RLogon
C. Telnet
D. FTP
Answer: A. SSH
Question 9: When scoping an environment for a PCI DSS assessment, it is important to identify
_______________.
A. All flows of cardholder data
B. All of the options
C. Components that store cardholder data
D. Business facilities involved in processing transactions
Answer: B. All of the options
Question 10: QUESTION 21 Merchants involved with only e-commerce transactions that are
completely outsourced to a PCI DSS compliant service provider would use which SAQ?
A. SAQ C/VT
B. SAQ B
C. SAQ D
D. SAQ A
Answer: D. SAQ A
Page 2