PCIP STUDY PRACTICE EXAM 2026
QUESTIONS WITH SOLUTIONS GRADED A+
◉ PCI DSS Requirement 6.2. Answer: Ensure that all system
components and software are protected from known vulnerabilities
by applying patches. Install critical patches within one month of
release.
◉ PCI DSS Requirement 6.3. Answer: Ensure Application
Development practices are secure by:
1-Removing development, test, custom accounts before the software
becomes active
2-Reviewing custom code changes prior to release, by people who
did not develop code and are familiar with testing procedures
◉ PCI DSS Requirement 6.4. Answer: Implement Strong Access
Control Measures
1- Separate Test and Development environments with separate
access controls
2- Separate duties between test and dev environments
3- Do not use live PANs for testing
4- Remove test data before system goes live
,◉ PCI DSS Requirement 6.4.5. Answer: Strong Change Control
Procedures must be in place and must include the following:
1. Documentation of Impact
2. Documentation of approval by authorized party
3. Functionality Testing to verify that the change does not adversely
impact security
4. Back out procedure
◉ PCI DSS Requirement 6.4.6. Answer: For significant changes, all
relevant PCI DSS requirements must be implemented on all new or
changes systems and networks and documentation updated.
(Guideline until 2018
◉ PCI DSS Requirement 6.5. Answer: Address common coding
vulnerabilities
1-Injection Flaws, SWL Injection, OS Injections, LDAP, XPath
2-Buffer Overflow
3-Insure Crypto Storage
4-Insecure Communications
5-Improper Error Handling
6-High Risk Vulnerabilities IDed in Vulnerability Scan
7-XSS
8-Improper Access Control
, 9-Cross-Site Script Forgery (CSRF)
10- Broken Authentication and Session Management
◉ PCI DSS Requirement 6.6. Answer: For Public Facing Web
Applications, address new threats and vulnerabilities on a ongoing
basis
◉ PCI DSS Requirement 6.7. Answer: Enxure Security Policies and
operational procedures are documented, in use, and known to all
parties
◉ PCI DSS Area 4. Answer: Implement Strong Access Control
Measures
◉ PCI DSS Requirement Seven. Answer: Restrict access to
cardholder data by business need to know
◉ PCI DSS Requirement 7.1. Answer: Limit access to those whose
job requires such access
1-Define access needs according to each role
2- Restrict access to privileged user IDS to least needed to perform
job
3-Assign access based on a individual person's job classification and
function
QUESTIONS WITH SOLUTIONS GRADED A+
◉ PCI DSS Requirement 6.2. Answer: Ensure that all system
components and software are protected from known vulnerabilities
by applying patches. Install critical patches within one month of
release.
◉ PCI DSS Requirement 6.3. Answer: Ensure Application
Development practices are secure by:
1-Removing development, test, custom accounts before the software
becomes active
2-Reviewing custom code changes prior to release, by people who
did not develop code and are familiar with testing procedures
◉ PCI DSS Requirement 6.4. Answer: Implement Strong Access
Control Measures
1- Separate Test and Development environments with separate
access controls
2- Separate duties between test and dev environments
3- Do not use live PANs for testing
4- Remove test data before system goes live
,◉ PCI DSS Requirement 6.4.5. Answer: Strong Change Control
Procedures must be in place and must include the following:
1. Documentation of Impact
2. Documentation of approval by authorized party
3. Functionality Testing to verify that the change does not adversely
impact security
4. Back out procedure
◉ PCI DSS Requirement 6.4.6. Answer: For significant changes, all
relevant PCI DSS requirements must be implemented on all new or
changes systems and networks and documentation updated.
(Guideline until 2018
◉ PCI DSS Requirement 6.5. Answer: Address common coding
vulnerabilities
1-Injection Flaws, SWL Injection, OS Injections, LDAP, XPath
2-Buffer Overflow
3-Insure Crypto Storage
4-Insecure Communications
5-Improper Error Handling
6-High Risk Vulnerabilities IDed in Vulnerability Scan
7-XSS
8-Improper Access Control
, 9-Cross-Site Script Forgery (CSRF)
10- Broken Authentication and Session Management
◉ PCI DSS Requirement 6.6. Answer: For Public Facing Web
Applications, address new threats and vulnerabilities on a ongoing
basis
◉ PCI DSS Requirement 6.7. Answer: Enxure Security Policies and
operational procedures are documented, in use, and known to all
parties
◉ PCI DSS Area 4. Answer: Implement Strong Access Control
Measures
◉ PCI DSS Requirement Seven. Answer: Restrict access to
cardholder data by business need to know
◉ PCI DSS Requirement 7.1. Answer: Limit access to those whose
job requires such access
1-Define access needs according to each role
2- Restrict access to privileged user IDS to least needed to perform
job
3-Assign access based on a individual person's job classification and
function