PCI ISA Exam Practice Questions and Answers Complete 2023/2024 (Already Graded A+)
PCI ISA Exam Practice Questions and Answers Complete 2023/2024 (Already Graded A+) ASV - ANSWER-Acronym for "approved Scanning Vendor". Company approved by the PCI SSC to conduct external vulnerability scanning services. Audit Log - ANSWER-Also referred to as audit trail. Chronological record of system activities. Provides an independently verifiable trail sufficient to permit reconstruction, review, and examination of sequence of environments and activities surrounding or leading to operation, procedure, or event in a transaction from inception to final results. Authentication - ANSWER-Process of verifying identity of an individual, device, or process. Authentication Credentials - ANSWER-Combination of the user ID or account ID plus the authentication factors used to authenticate and individual, device, or process Authorization - ANSWER-In the context of access controls, authorization is the granting of access or other rights to a user, program, or process. In the context of a a payment card transaction, authorization occurs when a merchant receives transaction approval after the acquirer to validates the transaction with the issuer/processor. Backup - ANSWER-A copy of data that is made in case the original data is lost or damaged. The backup can be used to restore the original data. BAU - ANSWER-An acronym for "business as usual". Bluetoot - ANSWER-_____ is a wireless protocol designed for transmitting data over short distances, replacing cables. Buffer Overflow - ANSWER-This attack occurs when an attacker leverages a vulnerability in an application, causing data to be written to a memory area (that is, a buffer) that's being used by a different application. Card Skimmer - ANSWER-A physical device, often attached to legitimate card-reading device, designed to illegitimately capture and/or store the information from a payment card. Compensating Controls - ANSWER-may be considered when an entity cannot meet a requirement explicitly as stated, due to legitimate technical or documented business constraints, but has sufficiently mitigated the risk associated with the requirement through implementation of other controls. Cross-Site Scripting (XSS) - ANSWER-Vulnerability that is created from insecure coding techniques, resulting in improper input validation. Egress Filtering - ANSWER-Method of filtering outbound network traffic such that only explicitly allowed traffic is permitted to leave the network. File Integrity Monitoring - ANSWER-Technique or technology under which certain files or logs are monitored to detect if they are modified. Index Token - ANSWER-A cryptographic token that replaces the PAN, based on a given index for an unpredicatable value. Ingress Filtering - ANSWER-Method of filtering inbound network traffic such that only explicitly allowed traffic is permitted to enter the network Injection Flaws - ANSWER-Vulnerability that is created from insecure coding techniques resulting in improper input validation, which allows attackers to relay malicious code through a web application to the underlying system. Issuer - ANSWER-Entity that issues payment cards or performs, facilitates, or supports issuing services including but not limited to issuing banks and issuing processors. Issuing Services - ANSWER-may include but are not limited to authorization and card personalization. Lightweight Directory Access Protocol -LDAP - ANSWER-Authentication and authorization data repository utilized for querying and modifying user permissions and granting access to protected resources. Message Authentication Code (MAC) - ANSWER-a small piece of information used to authenticate a message MAC Address - ANSWER-Unique identifying value assigned by manufacturers to network adapters and network interface cards. Masking - ANSWER-a method of concealing a segment of data when displayed or printed Memory Scraping Attacks - ANSWER-Malware activity that examines and extracts data that resides in memory as it is being processed or which is has not been properly flushed or overwritten Merchant - ANSWER-defined as any entity that accepts payment cards bearing the logos of any of the five members of PCISSC as payment for goods or services.
Document information
- Uploaded on
- May 29, 2023
- Number of pages
- 7
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers