QIR testing 2 questions with correct
answers
Qualified Installation - ANS ✔✔where the installation and configuration of a validated PA-DSS
payment application is undertaken in accordance with the applicable PA-DSS Implementation
Guide, and the QIR Program Guide in a manner which supports the merchant's PCI DSS
compliance and does not introduce any security weaknesses or errors
Core responsibilities as a QIR - ANS ✔✔Install payment applications in a manner which supports
the customer's PCI DSS compliance using the PA-DSS Implementation Guide
Provide the customer with a completed Implementation Statement after installation
Document for the customer any potential risks to PCI DSS compliance
Explain any changes made to the customer's system(s) and any potential risks to the customer
Provide a Feedback Form to the customer
Confirm that the installation and application protects confidential and sensitive information
In the case of a breach, QIR and QIR company must support - ANS ✔✔PCI Forensic Investiagtor
(PFI)
Lead QIR responsibilities - ANS ✔✔Lead the engagement for the QIR company
, Document all tasks that both the QIR and customer are going to perform
Understand how each item within the Implementation Statement applies to the particular
implementation
Accept accountability for all tasks in the QIR Implementation Statement
Confirm the responsibilities of the QIR and the customer both during the implementation and
afterwards
Sign the Implementation Statement
Two type of PA-DSS validated payment applications - ANS ✔✔Acceptable for New Deployments
Acceptable only for Pre-Existing Deployments
Revalidation date - ANS ✔✔
Annual attestation - ANS ✔✔
The expiry date - ANS ✔✔
The operating system, hardware, and software requirements associated with the validated
payment application - ANS ✔✔
What the QIR should give the customer - ANS ✔✔provide the name of the lead QIR who will be
responsible for the engagement and their role responsibility
answers
Qualified Installation - ANS ✔✔where the installation and configuration of a validated PA-DSS
payment application is undertaken in accordance with the applicable PA-DSS Implementation
Guide, and the QIR Program Guide in a manner which supports the merchant's PCI DSS
compliance and does not introduce any security weaknesses or errors
Core responsibilities as a QIR - ANS ✔✔Install payment applications in a manner which supports
the customer's PCI DSS compliance using the PA-DSS Implementation Guide
Provide the customer with a completed Implementation Statement after installation
Document for the customer any potential risks to PCI DSS compliance
Explain any changes made to the customer's system(s) and any potential risks to the customer
Provide a Feedback Form to the customer
Confirm that the installation and application protects confidential and sensitive information
In the case of a breach, QIR and QIR company must support - ANS ✔✔PCI Forensic Investiagtor
(PFI)
Lead QIR responsibilities - ANS ✔✔Lead the engagement for the QIR company
, Document all tasks that both the QIR and customer are going to perform
Understand how each item within the Implementation Statement applies to the particular
implementation
Accept accountability for all tasks in the QIR Implementation Statement
Confirm the responsibilities of the QIR and the customer both during the implementation and
afterwards
Sign the Implementation Statement
Two type of PA-DSS validated payment applications - ANS ✔✔Acceptable for New Deployments
Acceptable only for Pre-Existing Deployments
Revalidation date - ANS ✔✔
Annual attestation - ANS ✔✔
The expiry date - ANS ✔✔
The operating system, hardware, and software requirements associated with the validated
payment application - ANS ✔✔
What the QIR should give the customer - ANS ✔✔provide the name of the lead QIR who will be
responsible for the engagement and their role responsibility