PCI ISA EXAM LATEST
How many invalid user ID attempts in how much time? - ANSWERS-10
attempts in a minimum of 30 minutes
What is the password requirement (8.1.1 Best practice until March 31st,
2025, till it's a requirement) - ANSWERS-a minimum of 12 characters
(of IF the system does not support 12 characters, a minimum length of 8
characters) and contains both numeric and alphabetic characters
Individuals are not allowed to submit a new password that is the same as
the last ___ passwords - ANSWERS-last 4 passwords
How often are passwords changed if that is the only authentication? -
ANSWERS-90 days
How many types of authentication factors must be used? 8.1.1 (Best
practice until March 31st, 2025, till it's a requirement) - ANSWERS-2
different types
Individual physical access to sensitive areas within the CDE is
monitored with either video cameras or physical access controls from
both entry and exit points, monitoring devices from tampering, collected
data is reviewed and stored for ____ months. - ANSWERS-3 months
END OF
PAGE 1
, PCI ISA EXAM LATEST
Visitor badge log is recorded and logged for __ months. - ANSWERS-3
months
The security of the offline media backup location with cardholder data is
reviewed at least every ____months - ANSWERS-12 months
Inventories of electronic media with cardholder data are conducted at
least once every ____months - ANSWERS-12 Months
What must audit logs contain? - ANSWERS-user, type of event, date
and time, success or failure identification, organization of event, identity
or name of system, component, etc.
Retain audit log history for at least ___months. The most recent ___
months immediately available for analysis - ANSWERS-12 ; 3
Testing, detection and identification occurs at least once every ___
months and if automated monitoring is used, personnel are notified via
generated alerts - ANSWERS-3 months
How often are internal vulnerability scans? - ANSWERS-3 months
END OF
PAGE 2
How many invalid user ID attempts in how much time? - ANSWERS-10
attempts in a minimum of 30 minutes
What is the password requirement (8.1.1 Best practice until March 31st,
2025, till it's a requirement) - ANSWERS-a minimum of 12 characters
(of IF the system does not support 12 characters, a minimum length of 8
characters) and contains both numeric and alphabetic characters
Individuals are not allowed to submit a new password that is the same as
the last ___ passwords - ANSWERS-last 4 passwords
How often are passwords changed if that is the only authentication? -
ANSWERS-90 days
How many types of authentication factors must be used? 8.1.1 (Best
practice until March 31st, 2025, till it's a requirement) - ANSWERS-2
different types
Individual physical access to sensitive areas within the CDE is
monitored with either video cameras or physical access controls from
both entry and exit points, monitoring devices from tampering, collected
data is reviewed and stored for ____ months. - ANSWERS-3 months
END OF
PAGE 1
, PCI ISA EXAM LATEST
Visitor badge log is recorded and logged for __ months. - ANSWERS-3
months
The security of the offline media backup location with cardholder data is
reviewed at least every ____months - ANSWERS-12 months
Inventories of electronic media with cardholder data are conducted at
least once every ____months - ANSWERS-12 Months
What must audit logs contain? - ANSWERS-user, type of event, date
and time, success or failure identification, organization of event, identity
or name of system, component, etc.
Retain audit log history for at least ___months. The most recent ___
months immediately available for analysis - ANSWERS-12 ; 3
Testing, detection and identification occurs at least once every ___
months and if automated monitoring is used, personnel are notified via
generated alerts - ANSWERS-3 months
How often are internal vulnerability scans? - ANSWERS-3 months
END OF
PAGE 2