PCI DSS Extra Questions with all Correct & 100%
Verified Answers |Latest Version |Already Graded A+
Compensating controls can be documented in which section of the SAQ? ✔Correct Answer-
Appendix B
The following are examples of common PCI DSS control failures except: ✔Correct Answer-a)
Inadequate access controls due to improperly installed point-of-sale (POS) systems, allowing
malicious users in via paths intended for POS vendors (Requirements 7.1, &.2, *.2, and *.3).
b) Storage of sensitive authentication data (SAD), such as track data, after authorization
(Requirement 3.2).
c) Unnecessary and insecure services not removed or secured when the system was installed
(Requirements 2.2.2 and 2.2.3).
d) Missing and outdated security patches (Requirement 6.2)
e) Ensuring audit Logging is running (Requirement 10)
A common error in scoping a PCI DSS assessment includes: ✔Correct Answer-Assuming encrypted
data is out-of-scope
GPRS Refers to: ✔Correct Answer-Acronym for "General Radio Service." Mobile data service
available to users of GSM mobile phones.
The PCI DSS Self-Assessment Questionnaires (SAQs) are validation tools intended to assist merchants
and service providers in self-evaluating their compliance with PCI DSS. ✔Correct Answer-True
The purpose of a Qualified Integrator and Reseller (QIR) reseller does not include: ✔Correct
Answer-Being qualified to assess payment applications against the PA-DSS standard.
This is hardware and/or software used to process payment card transactions at merchant locations.
✔Correct Answer-POS/POI - Point-of-Sale/Point-of-Interaction
When assessing if a cardholder data should be stored, which should not be considered? ✔Correct
Answer-If Payment brand rules allow for the storage of primary account number(PAN)
ECC is an acronym for: ✔Correct Answer-"Elliptic Curve Cryptography." Approach to public-key
cryptography based on elliptic curves over finite fields.
A security subsequent compromise of payment card data has far-reaching consequences for affected
organizations, including:
(select all that apply) ✔Correct Answer-a) Loss of customers
b) Potential financial liabilities (for example, regulatory and other fees and fines)
c) Litigation
d) Regulatory notification requirements
e) Loss of reputation
A Card Verification Code or Value: ✔Correct Answer-Is a data element on a card's magnetic stripe
that uses secure cryptographic processes to protect data integrity.
, This SAQ should never be used for Merchants with Only Imprint Machines or Standalone, Dial-out
Terminals - No Electronic Cardholder Data Storage ✔Correct Answer-SAQ B
This SAQ should be used for Merchants with Standalone, IP-Connected PTS Point-of-Interaction (POI)
Terminals - No Electronic Cardholder Data Storage. ✔Correct Answer-SAQ B-IP
As an ISA, where can you go for professional assistance and training?
(select all that apply) ✔Correct Answer-a) PCI SSC Training Programs (PCI Awareness, the PCI
Professional (PCIP) program, and the Internal Security Assessor (ISA) program).
b) Contact a Qualified Security Assessor (QSA)
c) Payment-related training programs available from payment brands and/or your merchant acquirer
d) The PCI SSC website
The purpose of the Data Flow Diagram is for: ✔Correct Answer-Unique diagram that specifically
describes the flow of card data elements through the system.
Documents for your PCI DSS Self-Assessment does not include: ✔Correct Answer-NIST 800-53
guidelines
Who should receive the completed SAQ? ✔Correct Answer-The acquiring bank or payment
brand(s).
PCI DSS is not applicable to: ✔Correct Answer-Acquiring Banks and Brands
Typically, these accounts have elevated or increased privileges with more rights than a standard user
account. ✔Correct Answer-Privileged User
PA-DSS is applicable to: ✔Correct Answer-Payment applications that are sold "off-the-shelf" by
software vendors.
A compensating control is used when: ✔Correct Answer-An entity cannot meet a requirement
explicitly as stated.
Requirement 8.3.1 requiring multi-factor authentication for all non-console access into the CDE for
personnel with administrative access is no longer required in version 3.2.1 ✔Correct Answer-False
Which aspect of PCI DSS is not required of an ISA? ✔Correct Answer-Development and
enforcement of compliance programs
The purpose for the payment brands compliance programs are for: ✔Correct Answer-Tracking and
enforcement, Levy penalties, fees, compliance deadlines, establish a validation process, define
merchant and service provider levels.
It is permissible to store track data only if: ✔Correct Answer-An issuer has a business reason
Upon completion of a significant change, all relevant PCI DSS requirements must be implemented on
all new or changed systems and networks ✔Correct Answer-True
With respect to Requirement 11.2, when working with an approved scanning vendor, an ISA must:
✔Correct Answer-Provide all IP ranges and domains of the external scanned environment
Verified Answers |Latest Version |Already Graded A+
Compensating controls can be documented in which section of the SAQ? ✔Correct Answer-
Appendix B
The following are examples of common PCI DSS control failures except: ✔Correct Answer-a)
Inadequate access controls due to improperly installed point-of-sale (POS) systems, allowing
malicious users in via paths intended for POS vendors (Requirements 7.1, &.2, *.2, and *.3).
b) Storage of sensitive authentication data (SAD), such as track data, after authorization
(Requirement 3.2).
c) Unnecessary and insecure services not removed or secured when the system was installed
(Requirements 2.2.2 and 2.2.3).
d) Missing and outdated security patches (Requirement 6.2)
e) Ensuring audit Logging is running (Requirement 10)
A common error in scoping a PCI DSS assessment includes: ✔Correct Answer-Assuming encrypted
data is out-of-scope
GPRS Refers to: ✔Correct Answer-Acronym for "General Radio Service." Mobile data service
available to users of GSM mobile phones.
The PCI DSS Self-Assessment Questionnaires (SAQs) are validation tools intended to assist merchants
and service providers in self-evaluating their compliance with PCI DSS. ✔Correct Answer-True
The purpose of a Qualified Integrator and Reseller (QIR) reseller does not include: ✔Correct
Answer-Being qualified to assess payment applications against the PA-DSS standard.
This is hardware and/or software used to process payment card transactions at merchant locations.
✔Correct Answer-POS/POI - Point-of-Sale/Point-of-Interaction
When assessing if a cardholder data should be stored, which should not be considered? ✔Correct
Answer-If Payment brand rules allow for the storage of primary account number(PAN)
ECC is an acronym for: ✔Correct Answer-"Elliptic Curve Cryptography." Approach to public-key
cryptography based on elliptic curves over finite fields.
A security subsequent compromise of payment card data has far-reaching consequences for affected
organizations, including:
(select all that apply) ✔Correct Answer-a) Loss of customers
b) Potential financial liabilities (for example, regulatory and other fees and fines)
c) Litigation
d) Regulatory notification requirements
e) Loss of reputation
A Card Verification Code or Value: ✔Correct Answer-Is a data element on a card's magnetic stripe
that uses secure cryptographic processes to protect data integrity.
, This SAQ should never be used for Merchants with Only Imprint Machines or Standalone, Dial-out
Terminals - No Electronic Cardholder Data Storage ✔Correct Answer-SAQ B
This SAQ should be used for Merchants with Standalone, IP-Connected PTS Point-of-Interaction (POI)
Terminals - No Electronic Cardholder Data Storage. ✔Correct Answer-SAQ B-IP
As an ISA, where can you go for professional assistance and training?
(select all that apply) ✔Correct Answer-a) PCI SSC Training Programs (PCI Awareness, the PCI
Professional (PCIP) program, and the Internal Security Assessor (ISA) program).
b) Contact a Qualified Security Assessor (QSA)
c) Payment-related training programs available from payment brands and/or your merchant acquirer
d) The PCI SSC website
The purpose of the Data Flow Diagram is for: ✔Correct Answer-Unique diagram that specifically
describes the flow of card data elements through the system.
Documents for your PCI DSS Self-Assessment does not include: ✔Correct Answer-NIST 800-53
guidelines
Who should receive the completed SAQ? ✔Correct Answer-The acquiring bank or payment
brand(s).
PCI DSS is not applicable to: ✔Correct Answer-Acquiring Banks and Brands
Typically, these accounts have elevated or increased privileges with more rights than a standard user
account. ✔Correct Answer-Privileged User
PA-DSS is applicable to: ✔Correct Answer-Payment applications that are sold "off-the-shelf" by
software vendors.
A compensating control is used when: ✔Correct Answer-An entity cannot meet a requirement
explicitly as stated.
Requirement 8.3.1 requiring multi-factor authentication for all non-console access into the CDE for
personnel with administrative access is no longer required in version 3.2.1 ✔Correct Answer-False
Which aspect of PCI DSS is not required of an ISA? ✔Correct Answer-Development and
enforcement of compliance programs
The purpose for the payment brands compliance programs are for: ✔Correct Answer-Tracking and
enforcement, Levy penalties, fees, compliance deadlines, establish a validation process, define
merchant and service provider levels.
It is permissible to store track data only if: ✔Correct Answer-An issuer has a business reason
Upon completion of a significant change, all relevant PCI DSS requirements must be implemented on
all new or changed systems and networks ✔Correct Answer-True
With respect to Requirement 11.2, when working with an approved scanning vendor, an ISA must:
✔Correct Answer-Provide all IP ranges and domains of the external scanned environment