PCIP Questions with Correct Answers (Grade A+)
Question 1: PCI DSS Requirement 1
Answer: Install and maintain a firewall configuration to protect cardholder data
Question 2: PCI DSS Requirement 2
Answer: Do not use vendor supplied defaults for system passwords and other security parameters
Question 3: PCI DSS Requirement 3
Answer: Protect stored cardholder data by enacting a formal data retention policy and implement secure
deletion methods
Question 4: PCI DSS Requirement 4
Answer: Protected Cardholder Data during transmission over the internet, wireless networks or other open
access networks or systems (GSM, GPRS, etc.)
Question 5: PCI DSS Requirement 5
Answer: Use and regularly update anti-virus software or programs
Question 6: PCI DSS Requirement 6
Answer: Develop and maintain secure systems and applications
Question 7: PCI DSS Requirement 7
Answer: Restrict access to cardholder data by business need to know
Question 8: PCI DSS Requirement 8
Answer: Assign a unique ID to each person with computer access
Question 9: PCI DSS Requirement 9
Answer: Restrict physical access to cardholder data
Question 10: PCI DSS Requirement 10
Answer: Track and monitor all access to network resources and cardholder data
Page 1
,Question 11: PCI DSS Requirement 11
Answer: Regularly test secuirty systems and processes with wireless scans, vulnerability scnas, log audits,
ASV (Approved Scanning Vendor)
Question 12: PCI DSS Requirement 12
Answer: Maintain a policy that addresses information security for all personnel
Question 13: ASV (Approved Scanning Vendor)
Answer: Company approved by the PCI SSC to conduct external vulnerability scanning services.
Question 14: PCI Data Security Standards (PCI DSS)
Answer: Covers the security of the environments that store, process or transmit account data. Environments
receive account data from payment applications and other sources (e.g. acquirers)
Question 15: PCI Payment Application Data Security Standards (PCI PA-DSS)
Answer: Covers secure payment applications to support PCI DSS compliance. Applies to Third Party
payment applications if the application performs authorization and/or settlement (POS, shopping carts, etc.)
Ensures a payment application can function in a PCI DSS compliant manner PA-DSS applications are in
scope for PCI DSS Payment application receives account data from PIN Entry Devices (PED) or other
devices and begins payment transaction
Question 16: PCI PIN Transaction Security (PCI PTS)
Answer: Covers device tamper detection, cryptographic processes and other mechanisms to protect the
Personal Identification Number (PIN). Encrypted PIN is passed to payment application or hardware
terminal.
Question 17: PCI-PTS - PIN Security
Answer: Covers secure management, processing and transmission of personal identification number data
during online and offline payment card transaction processing
Question 18: PCI-PTS - HSM (Hardware Security Module or Host Security Module)
Answer: A physically and logically protected hardware device that provides a secure set of cryptographic
services, used for cryptographic key-management functions and/or the decryption of account data. Not
required by DSS, but may help with the management of keys.
Page 2
, Question 19: PCI Point to Point Encryption (PCI P2PE)
Answer: Covers encryption, decryption and key management within secure cryptographic devices (SCD).
Not a requirement but may result in reduction of scope.
Question 20: Secure Cryptographic Device (SCD)
Answer: A set of hardware, software and firmware that implements cryptographic processes (including
cryptographic algorithms and key generation) and is contained within a defined cryptographic boundary.
Examples of secure cryptographic devices include host/hardware security modules (HSMs) and
point-of-interaction devices (POIs) that have been validated to PCI PTS.
Question 21: POI - Point of Interaction
Answer: The initial point where data is read from a card. An electronic transaction-acceptance product, a
POI consists of hardware and software and is hosted in acceptance equipment to enable a cardholder to
perform a card transaction. The POI may be attended or unattended. POI transactions are typically
integrated circuit (chip) and/or magnetic-stripe card-based payment transactions.
Question 22: PCI Card Production
Answer: Covers physical and logical security requirements for systems and business processes associated
with card personalization, PIN generation, PIN mailers, and card carriers and distribution.
Question 23: CDE - Cardholder Data Environment
Answer: The people, processes and technology that store, process, or transmit cardholder data or sensitive
authentication data.
Question 24: Relationship between PTS and PCI DSS
Answer: DSS prevents the storage of encrypted PIN blocks. PTS supports the PIN encryption so there's no
overlap.
Question 25: Relationship between PCI DSS and PA-DSS
Answer: Payment applications must support and not hinder PCI DSS compliance PCI DSS requirements
mirrored in many payment application requirements in PA-DSS
Question 26: Relationship between PCI DSS and P2PE
Answer: Incorporates requirements from Pin Transaction Security, PCI DSS, PA-DSS and PCI PIN to
protect CHD from the point of capture until it reaches the payment processor. Properly implemented,
validated P2PE solutions may help reduce the scope of a merchant's PCI DSS assessment.
Page 3
Question 1: PCI DSS Requirement 1
Answer: Install and maintain a firewall configuration to protect cardholder data
Question 2: PCI DSS Requirement 2
Answer: Do not use vendor supplied defaults for system passwords and other security parameters
Question 3: PCI DSS Requirement 3
Answer: Protect stored cardholder data by enacting a formal data retention policy and implement secure
deletion methods
Question 4: PCI DSS Requirement 4
Answer: Protected Cardholder Data during transmission over the internet, wireless networks or other open
access networks or systems (GSM, GPRS, etc.)
Question 5: PCI DSS Requirement 5
Answer: Use and regularly update anti-virus software or programs
Question 6: PCI DSS Requirement 6
Answer: Develop and maintain secure systems and applications
Question 7: PCI DSS Requirement 7
Answer: Restrict access to cardholder data by business need to know
Question 8: PCI DSS Requirement 8
Answer: Assign a unique ID to each person with computer access
Question 9: PCI DSS Requirement 9
Answer: Restrict physical access to cardholder data
Question 10: PCI DSS Requirement 10
Answer: Track and monitor all access to network resources and cardholder data
Page 1
,Question 11: PCI DSS Requirement 11
Answer: Regularly test secuirty systems and processes with wireless scans, vulnerability scnas, log audits,
ASV (Approved Scanning Vendor)
Question 12: PCI DSS Requirement 12
Answer: Maintain a policy that addresses information security for all personnel
Question 13: ASV (Approved Scanning Vendor)
Answer: Company approved by the PCI SSC to conduct external vulnerability scanning services.
Question 14: PCI Data Security Standards (PCI DSS)
Answer: Covers the security of the environments that store, process or transmit account data. Environments
receive account data from payment applications and other sources (e.g. acquirers)
Question 15: PCI Payment Application Data Security Standards (PCI PA-DSS)
Answer: Covers secure payment applications to support PCI DSS compliance. Applies to Third Party
payment applications if the application performs authorization and/or settlement (POS, shopping carts, etc.)
Ensures a payment application can function in a PCI DSS compliant manner PA-DSS applications are in
scope for PCI DSS Payment application receives account data from PIN Entry Devices (PED) or other
devices and begins payment transaction
Question 16: PCI PIN Transaction Security (PCI PTS)
Answer: Covers device tamper detection, cryptographic processes and other mechanisms to protect the
Personal Identification Number (PIN). Encrypted PIN is passed to payment application or hardware
terminal.
Question 17: PCI-PTS - PIN Security
Answer: Covers secure management, processing and transmission of personal identification number data
during online and offline payment card transaction processing
Question 18: PCI-PTS - HSM (Hardware Security Module or Host Security Module)
Answer: A physically and logically protected hardware device that provides a secure set of cryptographic
services, used for cryptographic key-management functions and/or the decryption of account data. Not
required by DSS, but may help with the management of keys.
Page 2
, Question 19: PCI Point to Point Encryption (PCI P2PE)
Answer: Covers encryption, decryption and key management within secure cryptographic devices (SCD).
Not a requirement but may result in reduction of scope.
Question 20: Secure Cryptographic Device (SCD)
Answer: A set of hardware, software and firmware that implements cryptographic processes (including
cryptographic algorithms and key generation) and is contained within a defined cryptographic boundary.
Examples of secure cryptographic devices include host/hardware security modules (HSMs) and
point-of-interaction devices (POIs) that have been validated to PCI PTS.
Question 21: POI - Point of Interaction
Answer: The initial point where data is read from a card. An electronic transaction-acceptance product, a
POI consists of hardware and software and is hosted in acceptance equipment to enable a cardholder to
perform a card transaction. The POI may be attended or unattended. POI transactions are typically
integrated circuit (chip) and/or magnetic-stripe card-based payment transactions.
Question 22: PCI Card Production
Answer: Covers physical and logical security requirements for systems and business processes associated
with card personalization, PIN generation, PIN mailers, and card carriers and distribution.
Question 23: CDE - Cardholder Data Environment
Answer: The people, processes and technology that store, process, or transmit cardholder data or sensitive
authentication data.
Question 24: Relationship between PTS and PCI DSS
Answer: DSS prevents the storage of encrypted PIN blocks. PTS supports the PIN encryption so there's no
overlap.
Question 25: Relationship between PCI DSS and PA-DSS
Answer: Payment applications must support and not hinder PCI DSS compliance PCI DSS requirements
mirrored in many payment application requirements in PA-DSS
Question 26: Relationship between PCI DSS and P2PE
Answer: Incorporates requirements from Pin Transaction Security, PCI DSS, PA-DSS and PCI PIN to
protect CHD from the point of capture until it reaches the payment processor. Properly implemented,
validated P2PE solutions may help reduce the scope of a merchant's PCI DSS assessment.
Page 3