QIR Practice TEST Complete 2022
PIN Block What is an example of sensitive authentication data? Expiration Date What is an example of cardholder data? PCI SSC The __________________ is an independent industry standards body providing oversight of the development and management of Payment Card Industry Data Security Standards on a global basis. Covers secure payment environments that store, process or transmit account data What does PCI DSS cover? covers secure payment applications to support PCI DSS compliance What is PCI PA-DSS? True True or False: PCI PTS PIN Security covers secure management, processing and transmission of personal identification number (PIN) data during online and office payment transaction processing. False PCI PTS - POI True or False: PCI PTS - HSM covers device tamper detection, cryptographic processes, and other mechanisms used to protect the PIN and other sensitive data, such as cryptographic keys. - Install payment application in a manner which supports the customer's PCI DSS compliance using PA-DSS implementation Guide - Document for the customer any potential risks to PCI DSS compliance - Explain any changes made to the customer's system(s) and any potential risks to the customer - Provide a Feedback Form to the customer - Support PCI Forensic Investigator (PFI) investigations in the event of a breach Core responsibilities as a QIR include: Merchant Who is responsible for a Merchant's PCI Compliance? Implementation Statement Summary The PCI SSC Listing Number, Payment Application Vendor, Payment Application Name and Application Version Number are found in what part of the Implementation Statement? covers encryption, decryption and key management requirements for point-to-point encryption. What is P2PE? Settlement What is the last step in the payment processing workflow? Clearing What is the 2nd step in the payment processing workflow? Merchant requests and receives authorization What tapes place in the Authorization portion of the payment processing workfolw? Also called Visa and/or Mastercard Which of the following is not true of acquirers? True True or False: Compliance validation requirements vary by payment bread. QSA Who is responsible for validating the scope of a PCI DSS assessment? Maintaining an internal PA-QSA Which of the following is not a responsibility of the ASV? True True or False: The QIR program aims to assume quality and provide effective feedback among QIRs, their customers and the PCI SSC. True True or False: The Implementation Guide and Implementation Statement are to be used together on each Qualified Installation. True True or False: PAN should be rendered unreadable anywhere it's stored. - Statement Summary - QIR Employee Observations - Statement Details What are the Implementation Statement sections True True or False: PCI DSS requirements are applicable wherever primary account number (PAN) or sensitive authentication data (SAD) is stored, processed or transmitted. True True or False: Account Data includes cardholder data and/or sensitive authentication data. False True or False: PCI DSS Requirements do not apply to systems that provide security services or could impact the security of account data. True True or False: Account data includes all of the information printed on the physical card as well as the data on the magnetic stripe or chip Internal Security Assessor What does ISA stand for? True True or False: Sensitive authentication data is not stored post-authorization. Implementation Statement Summary Records details about the customer, the QIR company and the QIR Employees and the payment application. Implementation Statement Summary Includes required signatures for the customer acceptance and the QIR Employee affirmation of the Qualified Installation. Implementation Statement Details Records details about the activities performed by the QIR Employee during the Qualified Installation. QIR Employee Additional Observations. Records observations or details that the customer should be aware of. QIR Employee Additional Obeservations. Includes items identified in the Details section that require explanation. False True or False: Sensitive authentication data can be stored after authorization, if encrypted. Annually. How often does each validated payment application undergo attestation, until Expiry Date is reached?
Document information
- Uploaded on
- October 8, 2022
- Number of pages
- 11
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers