During an assessment you find shared user accounts in CBE of a
compliant organization. What is true?
- POS personnel without access to multiple cards can share
- User without remote access privileges can share accounts
- Shared user accounts are never allowed in a compliant environment.
- Only DBAs and system administrators may be shared accounts -
Correct Answer ✔ ✔ Shared user accounts are never allowed in a
compliant environment.
When a PAN is displayed to an employee who does NOT need to see
full PAN , the minimum digits to be masked are:
- Only the last four
- All digits between the first six and last four
,- The first six and last four
- First four and last four digits - Correct Answer ✔ ✔ The first 6
and last 4
Merchants using P2PE solutions are still required to validate to PCI
DSS.
- TRUE
- FALSE - Correct Answer ✔ ✔ TRUE
The standard for validating off-the-shelf payment used in
authorization and settlement is:
- PCI DSS
- PCI P2PE
- PCI PTS
- PA-DSS - Correct Answer ✔ ✔ PA-DSS
, Merchants using PA-DSS validated payment applications are
automatically PCI-DSS compliant.
- FALSE
- TRUE - Correct Answer ✔ ✔ FALSE
The presumption of P2PE is that:
- Any entity in possession of the ciphertext can easily reversed the
encryption process
- The data can be decrypted
- The data cannot be decrypted between the source and the
destination point
- The data can be decrypted between the source and the destination
point - Correct Answer ✔ ✔ The data cannot be decrypted
between the source and the destination point