Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 7 pages
Exam (elaborations)

PCI-DSS ISA Exam Questions and Verified Answers.

Document preview thumbnail
Preview 2 out of 7 pages

PCI-DSS ISA Exam Questions and Verified Answers.

Content preview

PCI-DSS ISA Exam Questions and
Verified Answers
What is considered "Sensitive Authentication Data"? - ANSWER-Card verification value


When a PAN is displayed to an employee who does NOT need to see the full PAN, the
minimum digits to be masked are: All digits between the ___________ and the
__________. - ANSWER-first 6; last 4


Regarding protection of PAN... - ANSWER-PAN must be rendered unreadable during
the transmission over public and wireless networks.


Under requirement 3.4, what method must be used to render the PAN unreadable? -
ANSWER-Hashing the entire PAN using strong cryptography


Weak security controls that should NOT be used - ANSWER-WEP, SSL, and TLS 1.0 or
earlier


If disk encryption is used - ANSWER-logical access must be managed separately and
independently of native operating system authentication and access control
mechanisms


Manual clear-text key-management procedures specify processes for the use of the
following: - ANSWER-Split knowledge AND Dual control of keys


Perimeter firewalls installed ______________________________. - ANSWER-between
all wireless networks and the CHD environment.


Where should firewalls be installed? - ANSWER-At each Internet connection and
between any DMZ and the internal network.

, Review of firewall and router rule sets at least every __________________. -
ANSWER-6 months


Per requirement 5, anti-virus technology must be deployed_________________ -
ANSWER-on all system components commonly affected by malicious software.


Key functions for anti-vius program per Requirement 5: - ANSWER-1) Detect
2) Remove
3) Protect


Anti-virus solutions may be temporarily disabled only if - ANSWER-there is legitimate
technical need, as authorized by management on a case-by-case basis


When to install "critical" applicable vendor-supplied security patches? ---> within
_________ of release. - ANSWER-1 month


When to install applicable vendor-supplied security patches? - ANSWER-within an
appropriate time frame (for example, within three months).


When assessing requirement 6.5, testing to verify secure coding techniques are in place
to address common coding vulnerabilities includes: - ANSWER-Reviewing software
development policies and procedures


Requirements 7 restricted access controls by: - ANSWER-Need-to-know and least
privilege


Inactive accounts over _____________days need to be removed or disabled. -
ANSWER-90 days

Document information

Uploaded on
November 1, 2025
Number of pages
7
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$11.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
LeeErickson
1.5
(2)
Sold
12
Followers
1
Items
3554
Last sold
1 month ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions