QIR (well answered) latest updated
already passed
Which of the following items are included in the Compensating Controls worksheet? - ANS
✔✔Constraints, objectives, identified risks and definition of compensating controls.
Which of the following items CANNOT be stores? - ANS ✔✔PIN
The process of isolating the cardholder data environment from the remainder of an entity's
network is called? - ANS ✔✔Network segmentation
For those entities that outsource storage, processing or transmission of cardholder data to third
party service providers which of the following must be completed? - ANS ✔✔Report on
Compliance (ROC)
Which of the following are NOT a part of the Report on Compliance? - ANS ✔✔None of the
above
The first step of a PCI assessment is to: - ANS ✔✔Determine the scope of the review
Steps to reducing the scope of the cardholder data environment may include all items below
EXCEPT: - ANS ✔✔Purge all data that is older than 1 week
Before wireless technology is implemented: - ANS ✔✔An entity should carefully evaluate the
need for the technology against the risk
, The P2PE Standard covers: - ANS ✔✔Encryption, decryption, and key management within
secure cryptographic devices
The PCI DSS applied to any entity that ____, _____, or _____ cardholder data. - ANS ✔✔stores,
processes, transmits
The PCI DSS standard follows a defined ________ lifecycle. - ANS ✔✔36 month
Which of the below functions is associated with Acquirers? - ANS ✔✔All of the options
Which of the following entities will actually approve a purchase? - ANS ✔✔Issuing Bank
Which of the following lists the correct "order" for the flow of a payment card transaction? -
ANS ✔✔Authorization, Clearing, Settlement
Service providers include companies which ______ or could _______ the security of cardholder
data. - ANS ✔✔control, impact
Cardholder Data may be stored in "KNOWN" and "UNKNOWN" locations. - ANS ✔✔True
Storing Track Data "Long-term" or "persistently" may be permitted if _________. - ANS ✔✔it is
being stored by issuers
PCI DSS Requirements 3.4 states the PAN must be rendered unreadable when stored, using
_________. - ANS ✔✔Encryption, Hashing, or Truncation
Requirement 2.2.2 states "Enable only necessary and secure services, protocols, daemons, etc.,
as required for the function of the system". Which of the following is considered secure? - ANS
✔✔SSH
already passed
Which of the following items are included in the Compensating Controls worksheet? - ANS
✔✔Constraints, objectives, identified risks and definition of compensating controls.
Which of the following items CANNOT be stores? - ANS ✔✔PIN
The process of isolating the cardholder data environment from the remainder of an entity's
network is called? - ANS ✔✔Network segmentation
For those entities that outsource storage, processing or transmission of cardholder data to third
party service providers which of the following must be completed? - ANS ✔✔Report on
Compliance (ROC)
Which of the following are NOT a part of the Report on Compliance? - ANS ✔✔None of the
above
The first step of a PCI assessment is to: - ANS ✔✔Determine the scope of the review
Steps to reducing the scope of the cardholder data environment may include all items below
EXCEPT: - ANS ✔✔Purge all data that is older than 1 week
Before wireless technology is implemented: - ANS ✔✔An entity should carefully evaluate the
need for the technology against the risk
, The P2PE Standard covers: - ANS ✔✔Encryption, decryption, and key management within
secure cryptographic devices
The PCI DSS applied to any entity that ____, _____, or _____ cardholder data. - ANS ✔✔stores,
processes, transmits
The PCI DSS standard follows a defined ________ lifecycle. - ANS ✔✔36 month
Which of the below functions is associated with Acquirers? - ANS ✔✔All of the options
Which of the following entities will actually approve a purchase? - ANS ✔✔Issuing Bank
Which of the following lists the correct "order" for the flow of a payment card transaction? -
ANS ✔✔Authorization, Clearing, Settlement
Service providers include companies which ______ or could _______ the security of cardholder
data. - ANS ✔✔control, impact
Cardholder Data may be stored in "KNOWN" and "UNKNOWN" locations. - ANS ✔✔True
Storing Track Data "Long-term" or "persistently" may be permitted if _________. - ANS ✔✔it is
being stored by issuers
PCI DSS Requirements 3.4 states the PAN must be rendered unreadable when stored, using
_________. - ANS ✔✔Encryption, Hashing, or Truncation
Requirement 2.2.2 states "Enable only necessary and secure services, protocols, daemons, etc.,
as required for the function of the system". Which of the following is considered secure? - ANS
✔✔SSH