PCI-DSS Week 5 - Exam Questions
With 100% Verified Answers
PCI-DSS -
correct answer ✅Payment Card Industry - Data Security Standard
was developed to encourage and enhance cardholder data security
and facilitate broad adoption of consistent data security measures
globally. PCI-DSS provides baseline of technical and operational
requirements designed to protect cardholder data
Applies wherever account data is stored, processed or transmitted.
Within PCI DSS standards, account data consists of cardholder data
plus sensitive authentication data
PCI-DSS Categories -
correct answer ✅Each category contains requirements (in later
flashcards)
Build and maintain a secure network and systems
Protect cardholder data
Maintain vulnerability management program
Implement strong access control measures
Regularly monitor and test networks
Maintain information security policy
, PCI-DSS Week 5 - Exam Questions
With 100% Verified Answers
Build and maintain a secure network and systems -
correct answer ✅Install and maintain a firewall configuration to
protect cardholder data - controls compute traffic allowed between
entity's networks (internal) and untrusted networks (external). eg.
requirement= = firewall should be at each Internet connection
Don't use vendor-supplied defaults for system passwords and other
security parameters - Malicious individuals often use vendor default
passwords to compromise systems (well-known by hacker
communities) eg. requirement = remove unnecessary
functionalities like file systems, unnecessary web servers
Protect cardholder data -
correct answer ✅Protect stored cardholder data - Encryption,
truncation, masking, hashing essential eg. requirement = don't
store sensitive authentication data after authorisation
Encrypt transmission of cardholder data across open, public
networks - Sensitive info must be encrypted during transmission
over networks to prevent interception eg. requirement = never
send unprotected PANs by end-user messaging technologies like
SMS and email
With 100% Verified Answers
PCI-DSS -
correct answer ✅Payment Card Industry - Data Security Standard
was developed to encourage and enhance cardholder data security
and facilitate broad adoption of consistent data security measures
globally. PCI-DSS provides baseline of technical and operational
requirements designed to protect cardholder data
Applies wherever account data is stored, processed or transmitted.
Within PCI DSS standards, account data consists of cardholder data
plus sensitive authentication data
PCI-DSS Categories -
correct answer ✅Each category contains requirements (in later
flashcards)
Build and maintain a secure network and systems
Protect cardholder data
Maintain vulnerability management program
Implement strong access control measures
Regularly monitor and test networks
Maintain information security policy
, PCI-DSS Week 5 - Exam Questions
With 100% Verified Answers
Build and maintain a secure network and systems -
correct answer ✅Install and maintain a firewall configuration to
protect cardholder data - controls compute traffic allowed between
entity's networks (internal) and untrusted networks (external). eg.
requirement= = firewall should be at each Internet connection
Don't use vendor-supplied defaults for system passwords and other
security parameters - Malicious individuals often use vendor default
passwords to compromise systems (well-known by hacker
communities) eg. requirement = remove unnecessary
functionalities like file systems, unnecessary web servers
Protect cardholder data -
correct answer ✅Protect stored cardholder data - Encryption,
truncation, masking, hashing essential eg. requirement = don't
store sensitive authentication data after authorisation
Encrypt transmission of cardholder data across open, public
networks - Sensitive info must be encrypted during transmission
over networks to prevent interception eg. requirement = never
send unprotected PANs by end-user messaging technologies like
SMS and email