PCI ISA Training Exam Questions and
Answers (Most Recent Version, Complete
Study Material)
Systems Providing Security Services - Correct Answers
✅Systems providing security services as required by PCI
DSS, or that may be contributing to how an entity meets PCI
DSS requirements may include:
-Authentication servers (e.g. LDAP)
-Time management (e.g. NTP) servers
-Patch deployment servers
-Audit log storage and correlation servers
-Anti-virus management servers
-Routers and firewalls filtering network traffic
-Systems performing cryptographic and/or key management
functions
-Systems controlling and/or monitoring physical access
PCI DSS scope includes: - Correct Answers ✅-People
-Processes
-Technology
Scoping: People - Correct Answers ✅Examples of roles that
may be included in scope of assessment:
-Cashiers and sales clerks
,PCI ISA Training Exam Questions and
Answers (Most Recent Version, Complete
Study Material)
-Back-office clerks
-Call center operators
-Systems and network administrators
-IT support personnel
-Application developers
-Key custodians
-Human resources
-Information security officers
-Physical security officers
-Customer support
-Accounting/finance personnel
-Supervisors/managers for each area
-Senior management and executives
Scoping: Processes - Correct Answers ✅Examples of
processes related to payment processing:
-Regular payment processing channels
-Payment cancellations and chargebacks
-Back-up and fail-over processes
-Reconciliation, periodic reporting
-Distribution and storage of paper reports and other physical
media
,PCI ISA Training Exam Questions and
Answers (Most Recent Version, Complete
Study Material)
-Legacy processes and data stores
-Onboarding processes for new personnel
Examples of supporting processes:
-Authorizations and approvals for system access
-Firewall review processes
-Change management
-Scheduling of security patch deployments
-System building and configuration
-Identifying and escorting visitors
-Performing log reviews
-Processes for reporting potential security incidents
-Security policy updates
Scoping: Technology - Correct Answers ✅Examples of
types of technologies:
-Servers, applications, networks, devices
-Physical security systems
-Logical security systems
-Payment terminals and point of sale systems
-Electronic communications
, PCI ISA Training Exam Questions and
Answers (Most Recent Version, Complete
Study Material)
-Backups and disaster recovery "hot" sites
-Telecommunications: POTS vs. VoIP
-Management systems
-Remote access systems
Sampling - Correct Answers ✅Sampling is an option for
assessors to facilitate the assessment process.
- Sampling is NOT used to implement PCI DSS requirements
or to select
requirements to be assessed
Principles of sampling:
- Sample must be representative of the entire population
- Consider business facilities and system components
- Samples of system components must include all
combinations
- Samples must be large enough to provide assurance that
controls are implemented as expected
- Assessor's sampling methodology documented in ROC
Planning for the Assessment - Correct Answers ✅Pre-
assessment planning may include:
Answers (Most Recent Version, Complete
Study Material)
Systems Providing Security Services - Correct Answers
✅Systems providing security services as required by PCI
DSS, or that may be contributing to how an entity meets PCI
DSS requirements may include:
-Authentication servers (e.g. LDAP)
-Time management (e.g. NTP) servers
-Patch deployment servers
-Audit log storage and correlation servers
-Anti-virus management servers
-Routers and firewalls filtering network traffic
-Systems performing cryptographic and/or key management
functions
-Systems controlling and/or monitoring physical access
PCI DSS scope includes: - Correct Answers ✅-People
-Processes
-Technology
Scoping: People - Correct Answers ✅Examples of roles that
may be included in scope of assessment:
-Cashiers and sales clerks
,PCI ISA Training Exam Questions and
Answers (Most Recent Version, Complete
Study Material)
-Back-office clerks
-Call center operators
-Systems and network administrators
-IT support personnel
-Application developers
-Key custodians
-Human resources
-Information security officers
-Physical security officers
-Customer support
-Accounting/finance personnel
-Supervisors/managers for each area
-Senior management and executives
Scoping: Processes - Correct Answers ✅Examples of
processes related to payment processing:
-Regular payment processing channels
-Payment cancellations and chargebacks
-Back-up and fail-over processes
-Reconciliation, periodic reporting
-Distribution and storage of paper reports and other physical
media
,PCI ISA Training Exam Questions and
Answers (Most Recent Version, Complete
Study Material)
-Legacy processes and data stores
-Onboarding processes for new personnel
Examples of supporting processes:
-Authorizations and approvals for system access
-Firewall review processes
-Change management
-Scheduling of security patch deployments
-System building and configuration
-Identifying and escorting visitors
-Performing log reviews
-Processes for reporting potential security incidents
-Security policy updates
Scoping: Technology - Correct Answers ✅Examples of
types of technologies:
-Servers, applications, networks, devices
-Physical security systems
-Logical security systems
-Payment terminals and point of sale systems
-Electronic communications
, PCI ISA Training Exam Questions and
Answers (Most Recent Version, Complete
Study Material)
-Backups and disaster recovery "hot" sites
-Telecommunications: POTS vs. VoIP
-Management systems
-Remote access systems
Sampling - Correct Answers ✅Sampling is an option for
assessors to facilitate the assessment process.
- Sampling is NOT used to implement PCI DSS requirements
or to select
requirements to be assessed
Principles of sampling:
- Sample must be representative of the entire population
- Consider business facilities and system components
- Samples of system components must include all
combinations
- Samples must be large enough to provide assurance that
controls are implemented as expected
- Assessor's sampling methodology documented in ROC
Planning for the Assessment - Correct Answers ✅Pre-
assessment planning may include: