PCI DSS 4.0 Exam Questions With
100% Verified Answers
Requirements not Eligible for Customized Approach -
correct answer ✅You can't use a custom control to store SAD after
authorization
Two approaches entities can take in PCI DSS 4.0 -
correct answer ✅Defined Approach, Customized Approach
What are traits of Customized approach -
correct answer ✅Build a customized control that meets the
customized control objective
the entity must perform a targeted risk analysis for each
customized control, as well as perform testing, monitoring and
provide extra documentation for the assessor.
No compensating controls are an option for meeting the
compensating control objective.
Steps for using Customized Approach (Entity) -
correct answer ✅Document and maintain evidence about each
customized control
,PCI DSS 4.0 Exam Questions With
100% Verified Answers
Perform targeted risk analysis
Test and monitor the control
Steps for using customized approach (Assessor) -
correct answer ✅Review Entity's evidence
Derive the testing procedures
Test the control
Sample Templates to Support Customized Approach -
correct answer ✅Controls Matrix Template
Targeted Risk Analysis template
Customized Control Matrix in Appendix E for Customized Approach
-
correct answer ✅Entity completes it, assessor reviews for accuracy
, PCI DSS 4.0 Exam Questions With
100% Verified Answers
Customized Targeted Risk Analysis Appendix E2 for Customized
Approach -
correct answer ✅Entity fills it out, Assessor reviews it.
Mischief -
correct answer ✅Refers to an occurence or an event that
negatively affects the security posture of the entity
1.2 (NSC's) Review of configurations occur: -
correct answer ✅Every 6 months
3.2 (Storage of Data is kept at a minimum) Verify data has been
deleted at least once every: -
correct answer ✅3 months
3.4 (Access to displays of full PAN and ability to copy cardholder
data are restricted) Masking PAN: -
correct answer ✅First 6, last 4 displayed
5.2 (Malicious software is prevented, or detected and addressed)
Anti-malware is deployed on all system components, except: -
100% Verified Answers
Requirements not Eligible for Customized Approach -
correct answer ✅You can't use a custom control to store SAD after
authorization
Two approaches entities can take in PCI DSS 4.0 -
correct answer ✅Defined Approach, Customized Approach
What are traits of Customized approach -
correct answer ✅Build a customized control that meets the
customized control objective
the entity must perform a targeted risk analysis for each
customized control, as well as perform testing, monitoring and
provide extra documentation for the assessor.
No compensating controls are an option for meeting the
compensating control objective.
Steps for using Customized Approach (Entity) -
correct answer ✅Document and maintain evidence about each
customized control
,PCI DSS 4.0 Exam Questions With
100% Verified Answers
Perform targeted risk analysis
Test and monitor the control
Steps for using customized approach (Assessor) -
correct answer ✅Review Entity's evidence
Derive the testing procedures
Test the control
Sample Templates to Support Customized Approach -
correct answer ✅Controls Matrix Template
Targeted Risk Analysis template
Customized Control Matrix in Appendix E for Customized Approach
-
correct answer ✅Entity completes it, assessor reviews for accuracy
, PCI DSS 4.0 Exam Questions With
100% Verified Answers
Customized Targeted Risk Analysis Appendix E2 for Customized
Approach -
correct answer ✅Entity fills it out, Assessor reviews it.
Mischief -
correct answer ✅Refers to an occurence or an event that
negatively affects the security posture of the entity
1.2 (NSC's) Review of configurations occur: -
correct answer ✅Every 6 months
3.2 (Storage of Data is kept at a minimum) Verify data has been
deleted at least once every: -
correct answer ✅3 months
3.4 (Access to displays of full PAN and ability to copy cardholder
data are restricted) Masking PAN: -
correct answer ✅First 6, last 4 displayed
5.2 (Malicious software is prevented, or detected and addressed)
Anti-malware is deployed on all system components, except: -