PCIP STUDY EXAM SCRIPT 2026 QUESTIONS
WITH ANSWERS GRADED A+
◉ PCI DSS Requirement One. Answer: Install and maintain a firewall
configuration to protect cardholder data
◉ PCI DSS Requirement 1.1. Answer: Establish and implement
firewall and router configuration standards that include the
following:
1-A Formal Process for Change Management
2-A Current Network Diagram, process to keep current
3-A Cardholder Data Flows
4-Firewall at all access points to the network (DMZ or Internet
Connections)
5-Groups, Roles, and Responsibilities for managing network
components
6-Documentation of business justification for all open ports
7-Review Firewall rules every 6 months
◉ PCI DSS Requirement 1.2. Answer: Build firewall and router
configurations that restrict connections between untrusted
networks and any system components in the cardholder data
environment.
,1-Deny any inbound or outbound traffic that is not required for CDE
2-Router configuration should be secured and startup configuration
should be synchronized with going config.
3-Install firewall between all wireless networks and the CDE
◉ PCI DSS Requirement 1.3. Answer: Prohibit direct public access
between the Internet and any system component in the cardholder
data environment.
1-Implement a DMZ
2-limit inbound traffic to only those systems in the DMZ
3-Implement anti-spoof techniques
4-outboard traffic from CDE to internet should be explicitly
authorized
5-Only allow established connections
6-Store systems holding cardholder data separate from the DMZ and
other untrusted networks
7-Do not disclose network configuration (e.g. private IPs and routing
information)
◉ PCI DSS Requirement 1.4. Answer: Install personal firewall
software or equivalent functionality on any portable computing
devices (including company and/or employee-owned) that connect
to the Internet when outside the network (for example, laptops used
by employees), and which are also used to access the CDE.
,◉ PCI DSS Requirement 1.5. Answer: Ensure that security policies
and operational procedures for managing firewalls are documented,
in use, and known to all affected parties.
◉ PCI DSS Requirement Two. Answer: Do not use vendor-supplied
defaults for system passwords and other security parameters
◉ PCI DSS Requirement 2.1. Answer: Always change vendor-
supplied defaults and remove or disable unnecessary default
accounts before installing a system on the network.
1-Change ALL wireless vendor defaults at installation, including but
not limited to default wireless encryption keys, passwords, and
SNMP community strings.
◉ PCI DSS Requirement 2.2. Answer: Develop configuration
standards for all system components and apply appropriate
hardening
1-Implement one primary function per server to prevent co-
existence of services that require different security levels
2- Enable only necessary services
3- Implement additional security features for required services that
are considered insecure (e.g. SSL/Early TLS)
4- Systems should be configured
5-Remove all unnecessary functionality
, ◉ PCI DSS Requirement 2.3. Answer: Encrypt all non-console
administrative access using strong cryptography.
◉ PCI DSS Requirement 2.4. Answer: Maintain an inventory of
system components that are in scope for PCI DSS.
◉ PCI DSS Requirement 2.5. Answer: Ensure that security policies
and operational procedures for managing vendor defaults and other
security parameters are documented, in use, and known to all
affected parties.
◉ PCI DSS Requirement 2.6. Answer: Shared hosting providers must
protect each entity's hosted environment and cardholder data.
These providers must meet specific requirements as detailed in
Appendix A: Additional PCI DSS Requirements for Shared Hosting
Providers.
◉ PCI DSS Area 2. Answer: Protect Cardholder Data
◉ PCI DSS Requirement Three. Answer: Protect Stored Cardholder
Data
◉ PCI DSS Requirement 3.1. Answer: Keep cardholder data storage
to a minimum by implementing data retention and disposal policies,
WITH ANSWERS GRADED A+
◉ PCI DSS Requirement One. Answer: Install and maintain a firewall
configuration to protect cardholder data
◉ PCI DSS Requirement 1.1. Answer: Establish and implement
firewall and router configuration standards that include the
following:
1-A Formal Process for Change Management
2-A Current Network Diagram, process to keep current
3-A Cardholder Data Flows
4-Firewall at all access points to the network (DMZ or Internet
Connections)
5-Groups, Roles, and Responsibilities for managing network
components
6-Documentation of business justification for all open ports
7-Review Firewall rules every 6 months
◉ PCI DSS Requirement 1.2. Answer: Build firewall and router
configurations that restrict connections between untrusted
networks and any system components in the cardholder data
environment.
,1-Deny any inbound or outbound traffic that is not required for CDE
2-Router configuration should be secured and startup configuration
should be synchronized with going config.
3-Install firewall between all wireless networks and the CDE
◉ PCI DSS Requirement 1.3. Answer: Prohibit direct public access
between the Internet and any system component in the cardholder
data environment.
1-Implement a DMZ
2-limit inbound traffic to only those systems in the DMZ
3-Implement anti-spoof techniques
4-outboard traffic from CDE to internet should be explicitly
authorized
5-Only allow established connections
6-Store systems holding cardholder data separate from the DMZ and
other untrusted networks
7-Do not disclose network configuration (e.g. private IPs and routing
information)
◉ PCI DSS Requirement 1.4. Answer: Install personal firewall
software or equivalent functionality on any portable computing
devices (including company and/or employee-owned) that connect
to the Internet when outside the network (for example, laptops used
by employees), and which are also used to access the CDE.
,◉ PCI DSS Requirement 1.5. Answer: Ensure that security policies
and operational procedures for managing firewalls are documented,
in use, and known to all affected parties.
◉ PCI DSS Requirement Two. Answer: Do not use vendor-supplied
defaults for system passwords and other security parameters
◉ PCI DSS Requirement 2.1. Answer: Always change vendor-
supplied defaults and remove or disable unnecessary default
accounts before installing a system on the network.
1-Change ALL wireless vendor defaults at installation, including but
not limited to default wireless encryption keys, passwords, and
SNMP community strings.
◉ PCI DSS Requirement 2.2. Answer: Develop configuration
standards for all system components and apply appropriate
hardening
1-Implement one primary function per server to prevent co-
existence of services that require different security levels
2- Enable only necessary services
3- Implement additional security features for required services that
are considered insecure (e.g. SSL/Early TLS)
4- Systems should be configured
5-Remove all unnecessary functionality
, ◉ PCI DSS Requirement 2.3. Answer: Encrypt all non-console
administrative access using strong cryptography.
◉ PCI DSS Requirement 2.4. Answer: Maintain an inventory of
system components that are in scope for PCI DSS.
◉ PCI DSS Requirement 2.5. Answer: Ensure that security policies
and operational procedures for managing vendor defaults and other
security parameters are documented, in use, and known to all
affected parties.
◉ PCI DSS Requirement 2.6. Answer: Shared hosting providers must
protect each entity's hosted environment and cardholder data.
These providers must meet specific requirements as detailed in
Appendix A: Additional PCI DSS Requirements for Shared Hosting
Providers.
◉ PCI DSS Area 2. Answer: Protect Cardholder Data
◉ PCI DSS Requirement Three. Answer: Protect Stored Cardholder
Data
◉ PCI DSS Requirement 3.1. Answer: Keep cardholder data storage
to a minimum by implementing data retention and disposal policies,