Exam
An online merchant that displays a PCI-DSS-compliant service
provider's payment page in a IFRAME, all page content is from PSP.
SAQ-A
Merchant using an end-to-end encryption solution (E2EE) that utilizes
PCI PTC-approved POI devices which communicate with the acquirer
over an IP network.
SAQ B-IP
Which of the following could PA-DSS apply to?
a) Custom payment application endorsed by the PCI SSC
b) Third-party payment application designed for one company
,c) Third-party, "off-the-shelf" payment application
d) Custom payment application used by one company - Correct
Answer ✔ ✔ c) Third-party, "off-the-shelf" payment application
The presumption of P2PE is that:
a) The data connect be decrypted between the source and the
destination points
b) The data can never be decrypted
c) The data can be decrypted between the source and the destination
points
, d) Any entity in possession of the ciphertext can easily reversed the
encryption process. - Correct Answer ✔ ✔ a) The data connect be
decrypted between the source and the destination points
Merchants using P2PE solutions are still required to validate to PCI-
DSS
a) True
b) False - Correct Answer ✔ ✔ a) True
Which entity is responsible for developing and enforcing compliance
programs?
a) Issuers
b) Acquirers
c) PCI SSC