1 | Page
PCI ISA Exam Questions and Correct
Answers
Types of Account Data - Cardholder Data Ans: PAN, Cardholder
Name, Expiration Datee
Types of Account Data - Sensitive Authentication Data (SAD) Ans:
Full track data (magnetic strip or chip), card verification code, and
PINS
Cardholder Ans: Purchaser
Merchant Ans: accepts the cardholder information for purchase;
merchant levels based on payment brand
Acquirer Ans: Merchants Bank
Payment Brand Network Ans: Facilities the transfer
Issuer Ans: Cardholders Bank
Service Providers (TPSPs) Ans: Directly involved in the processing,
storage, or transmission of cardholder data on behalf of another
entity. If the TPSP can decrypt the data or has access to decryption
keys, that it is in scope
© 2025 All rights reserved
, 2 | Page
Requirement #1 Ans: Install and Maintain Network Security
Controls
Requirement #2 Ans: Apply secure configurations to all system
components
Requirement #3 Ans: Protect Stored Account Data
Requirement #4 Ans: Protect cardholder Data with strong
cryptography
Requirement #5 Ans: Protect all systems and networks from
Malicious Software
Requirement #6 Ans: Develop and maintain secure systems and
software
Requirement #7 Ans: Restrict Access to system components and
cardholder data by business need to know
Requirement #8 Ans: Identify users and authenticate access to
system components
Requirement #9 Ans: Restrict physical access to cardholder data
Requirement #10 Ans: Log and monitor all access to system
components and cardholder data
Requirement #11 Ans: Test security and networks regularly
© 2025 All rights reserved
PCI ISA Exam Questions and Correct
Answers
Types of Account Data - Cardholder Data Ans: PAN, Cardholder
Name, Expiration Datee
Types of Account Data - Sensitive Authentication Data (SAD) Ans:
Full track data (magnetic strip or chip), card verification code, and
PINS
Cardholder Ans: Purchaser
Merchant Ans: accepts the cardholder information for purchase;
merchant levels based on payment brand
Acquirer Ans: Merchants Bank
Payment Brand Network Ans: Facilities the transfer
Issuer Ans: Cardholders Bank
Service Providers (TPSPs) Ans: Directly involved in the processing,
storage, or transmission of cardholder data on behalf of another
entity. If the TPSP can decrypt the data or has access to decryption
keys, that it is in scope
© 2025 All rights reserved
, 2 | Page
Requirement #1 Ans: Install and Maintain Network Security
Controls
Requirement #2 Ans: Apply secure configurations to all system
components
Requirement #3 Ans: Protect Stored Account Data
Requirement #4 Ans: Protect cardholder Data with strong
cryptography
Requirement #5 Ans: Protect all systems and networks from
Malicious Software
Requirement #6 Ans: Develop and maintain secure systems and
software
Requirement #7 Ans: Restrict Access to system components and
cardholder data by business need to know
Requirement #8 Ans: Identify users and authenticate access to
system components
Requirement #9 Ans: Restrict physical access to cardholder data
Requirement #10 Ans: Log and monitor all access to system
components and cardholder data
Requirement #11 Ans: Test security and networks regularly
© 2025 All rights reserved