PCI - ISA Exam Actual Questions and
Answers 2026
What makes up SAD? -
correct answer ✅- Track Data
- CAV2/CVC2/CVV2/CID)
- PINs & PIN Blocks
Track 1 -
correct answer ✅Contains all fields of both Track 1 and Track 2, up
to 79 characters long
11.2 Internal Scans - Frequency and performed by who? -
correct answer ✅Quarterly and after significant changes in the
network - Performed by qualified, internal or external, resource
11.3 Penetration Tests (SERVICE PROVIDERS) - Frequency and
performed by who? -
correct answer ✅Every 6 months by a qualified, internal or
external, resource
11.2 External Scans - Frequency and performed by who? -
correct answer ✅Quarterly and after significant changes in the
network - Performed by PCI SSC Approved Scanning Vendor (ASV)
,PCI - ISA Exam Actual Questions and
Answers 2026
11.3 Penetration Tests - Frequency and performed by who? -
correct answer ✅At least annually and after significant changes in
the network - Performed by qualified, internal or external, resource
11.2 Review scan reports and verify scan process includes rescans
until: -
correct answer ✅- External scans: no vulnerabilities exists that
scored 4.0 or higher by the CVSS
- Internal scans: all high-risk vulnerabilities as defined in PCI DSS
requirement 6.1 are resolved
Who decides if a ROC or SAQ is required? -
correct answer ✅Payment Brands / Acquirers
10.2 Implement audit trails for all system components to
reconstruct the following events: -
correct answer ✅- All individual accesses to CHD
- Actions taken by any individual with root or admin privileges
- Access to all audit trails
- Invalid logical access attempts
- Use of, and changes to, identification and authentication
mechanisms
, PCI - ISA Exam Actual Questions and
Answers 2026
- Initialization, stopping, or pausing of the audit logs
- Creation and deleting of system-level objects
How long must QSA's retain work papers? -
correct answer ✅3 years, recommend the same for ISAs
Firewall and router rule sets must be reviewed every
_____________________. -
correct answer ✅6 months
Things to consider when assessing: -
correct answer ✅People, processes, technology
How often should an entity undergo a process to securely delete
stored CHD that exceeds defined retention requirements? -
correct answer ✅At least quarterly
3.6 Key-management operations Dual Control vs Split Knowledge -
correct answer ✅Dual Control: At least two people are required to
perform any key-management operations and no one person has
access to the authentication materials (e.g., passwords, keys) of
another
Answers 2026
What makes up SAD? -
correct answer ✅- Track Data
- CAV2/CVC2/CVV2/CID)
- PINs & PIN Blocks
Track 1 -
correct answer ✅Contains all fields of both Track 1 and Track 2, up
to 79 characters long
11.2 Internal Scans - Frequency and performed by who? -
correct answer ✅Quarterly and after significant changes in the
network - Performed by qualified, internal or external, resource
11.3 Penetration Tests (SERVICE PROVIDERS) - Frequency and
performed by who? -
correct answer ✅Every 6 months by a qualified, internal or
external, resource
11.2 External Scans - Frequency and performed by who? -
correct answer ✅Quarterly and after significant changes in the
network - Performed by PCI SSC Approved Scanning Vendor (ASV)
,PCI - ISA Exam Actual Questions and
Answers 2026
11.3 Penetration Tests - Frequency and performed by who? -
correct answer ✅At least annually and after significant changes in
the network - Performed by qualified, internal or external, resource
11.2 Review scan reports and verify scan process includes rescans
until: -
correct answer ✅- External scans: no vulnerabilities exists that
scored 4.0 or higher by the CVSS
- Internal scans: all high-risk vulnerabilities as defined in PCI DSS
requirement 6.1 are resolved
Who decides if a ROC or SAQ is required? -
correct answer ✅Payment Brands / Acquirers
10.2 Implement audit trails for all system components to
reconstruct the following events: -
correct answer ✅- All individual accesses to CHD
- Actions taken by any individual with root or admin privileges
- Access to all audit trails
- Invalid logical access attempts
- Use of, and changes to, identification and authentication
mechanisms
, PCI - ISA Exam Actual Questions and
Answers 2026
- Initialization, stopping, or pausing of the audit logs
- Creation and deleting of system-level objects
How long must QSA's retain work papers? -
correct answer ✅3 years, recommend the same for ISAs
Firewall and router rule sets must be reviewed every
_____________________. -
correct answer ✅6 months
Things to consider when assessing: -
correct answer ✅People, processes, technology
How often should an entity undergo a process to securely delete
stored CHD that exceeds defined retention requirements? -
correct answer ✅At least quarterly
3.6 Key-management operations Dual Control vs Split Knowledge -
correct answer ✅Dual Control: At least two people are required to
perform any key-management operations and no one person has
access to the authentication materials (e.g., passwords, keys) of
another