Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 6 pages
Exam (elaborations)

pci isa Latest Version Updated 2024

Document preview thumbnail
Preview 2 out of 6 pages

A (time) ______ process for identifying and securely deleting stored cardholder data that exceeds defined retention requirements. - ANSWER-quarterly According to PCI DSS requirement 1, Firewall and router rule sets need to be reviewed every _____ months. - ANSWER-6 At least ______________ and prior to the annual assessment the assessed entity: - Identifies all locations and flows of cardholder data to verify they are included in the CDE - Confirms the accuracy of their PCI DSS scope - Retains their scoping documentation for assessor reference - ANSWER-annually Contains all fields of both Track 1 and Track 2 - ANSWER-track 1 (Length up to 79 characters) DESV User accounts and access privileges are reviewed at least every _________ - ANSWER-six months Do not store SAD after ____________ (even if encrypted). (track data / cvc / pin) - ANSWERauthorization Dual control - ANSWER-least two people are required to perform any key-management operations and no one person has access to the authentication materials (for example, passwords or keys) of another Ensure that all system components and software are protected from known vulnerabilities by installing applicable vendor-supplied security patches. Install critical security patches within _____ of release. - ANSWER-one month entities monitor its service providers' PCI DSS compliance status at least ________ - ANSWER-annually

Content preview

pci isa Latest V ersion Updated 2024 A (time) ______ process for identifying and securely deleting stored cardholder data that exceeds defined retention requirements. - ANSWER -quarterly According to PCI DSS requirement 1, Firewall and router rule sets need to be reviewed every _____ months. - ANSWER -6 At least ______________ and prior to the annual assessment the assessed entity: - Identifies all locations and flows of cardholder data to verify they are included in the CDE - Confirms the accuracy of their PCI DSS scope - Retains their scoping documentation for assessor reference - ANSWER -annually Contains all fields of both Track 1 and Track 2 - ANSWER -track 1 (Length up to 79 characters ) DESV User accounts and access privileges are reviewed at least every _________ - ANSWER -six months Do not store SAD after ____________ (even if encrypted). (track data / cvc / pin) - ANSWER -
authorization Dual control - ANSWER -least two people are required to perform any key -management operations and no one person has access to the authentication materials (for example, passwords or keys) of another Ensure that all system components and software are protected from known vulnerabilities by installing applicable vendor -supplied security patches. Install critical security patches within _____ of release. - ANSWER -one month entities monitor its service providers' PCI DSS compliance status at least ________ - ANSWER -
annually Evidence Retention It is recommended that the ISA secure and maintain digital and/or hard copies of case logs, audit results and work papers, notes, and any technical information that was created and/or obtained during the PCI Data Security Assessment for a minimum of ________ or as applicable to company data retention policies - ANSWER -of three (3) years Examine documented results of scope reviews and interview personnel to verify that the reviews are performed: - ANSWER -At least quarterly After significant changes to the in -scope environment For a sample of system components, inspect system configuration settings to verify that authentication parameters are set to require that user accounts be locked out after not more than ___________ invalid logon attempts. - ANSWER -6 For a sample of system components, inspect system configuration settings to verify that user password/passphrase parameters are set to require users to change passwords at least once every ______. - ANSWER -90 days idle time out features have been set to ________ - ANSWER -15 mins or less IDS/IPS where? - ANSWER -at perimeter of CDE and at crit points in CDE If you find a potential card number, you can use a ________ check to see if it is a valid card number - ANSWER -mod 10 (luhn) Implement processes to test for the presence of wireless access points (802.11), and detect and identify all authorized and unauthorized wireless access points on a _______________ basis - ANSWER -quarterly incident response plan tested when? - ANSWER -annually information security policy reviewed when? - ANSWER -annually and sig changes Installation of all applicable vendor -supplied security patches within an ___________________ - ANSWER -appropriate time frame (for example, within three months)

Document information

Uploaded on
July 9, 2024
Number of pages
6
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers
$8.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
89
Last sold
-


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions