PCI QSA Exam with all Correct & 100% Verified Answers
|Latest Version |Already Graded A+
PAN ✔Correct Answer-Primary account numbers
Cardholder Data (CHD) ✔Correct Answer-Any type of personally identifiable information (PII)
associated with a person who has a payment card, such as a credit or debit card.
PAN, cardholder name, expiration date, service code
Sensitive Authentication Data (SAD) ✔Correct Answer-Full track data, card verification code, PIN
and PIN blocks
Can cardholder data or SAD be stored after authorization if protected? ✔Correct Answer-
Cardholder data can, SAD cannot.
cardholder ✔Correct Answer-Person to whom a financial transaction card is issued, or an
additional person authorized to use the card.
merchant ✔Correct Answer-The organization accepting payment
acquirer ✔Correct Answer-The merchant's bank
Issuer ✔Correct Answer-The cardholder's bank
service provider ✔Correct Answer-a company or organization that is directly involved in
processing, storage, or transmission of cardholder data on behalf of another entity
i.e. hosting provider, service gateway, software provider
Describe the authorization process ✔Correct Answer-1. Cardholder requests the purchase from
the merchant
2. Merchant contacts acquirer
3. Acquirer contacts payment brand network
4. Payment brand network contacts issuer
5. Issuer approves or declines and sends the response back through the same chain
6. Cardholder receives the receipt of transaction from the merchant
Describe the clearing process ✔Correct Answer-1. Acquirer sends purchase information to
payment brand network
2. Payment brand network sends that info to issuer
3. Issuer prepares data for the cardholder's statement
4. Payment brand network provides complete reconciliation information to acquirer
This is usually completed within 1 business day.
Describe the settlement process. ✔Correct Answer-1. Issuer determines who the acquirer is using
the payment brand network
2. Issuer sends payment directly to acquirer
, 3. Acquirer pays merchant for purchase
4. Issued bills cardholder for purchase
This generally occurs within 2 business days.
PCI SSF ✔Correct Answer-PCI Software Security Framework. Includes secure SDLC and
maintenance for software.
Describe the steps in the PCI DSS Assessment process. ✔Correct Answer-1. Entity defines the
scope, which the assessor then validates prior to the formal assessment start
2. Assessor assesses the entity
3. QSA completes the ROC or the entity completes a SAQ
4. Assessor completes the AOC
5. AOC and applicable documentation are submitted to the requesting organization
ROC ✔Correct Answer-Report on Compliance; the full report completed by an assessor.
AOC ✔Correct Answer-Attestation of Compliance; a document created to share with other
organizations that gives the relevant information but limits the exposure of all details. Akin to an
Executive Summary.
SAQ ✔Correct Answer-Self Assessment Questionnaire. An alternative to the ROC; an entity usually
fills this one out themselves.
PCIP ✔Correct Answer-PCI Professional. Entry level certification; all QSAs qualify, but a PCIP does
not need to be an assessor.
QIR ✔Correct Answer-Qualified Integrator or Reseller. QIRs install payment software and correctly
configure them.
ASV ✔Correct Answer-Approved Scanning Vendor; eligible to perform external vulnerability scans
for a PCI engagement.
SSF Assessor ✔Correct Answer-An assessor for the secure software framework.
PFI ✔Correct Answer-PCI Forensic Investigator
TPSP ✔Correct Answer-Third-Party Service Provider
Defined approach ✔Correct Answer-The explicitly defined requirements on a PCI DSS assessment.
These must be assessed using the defined testing procedure unless there is a legitimate business or
legal limitation, in which a compensating control can be designed.
Customized approach ✔Correct Answer-The entity builds their own control using the customized
approach guidance to fill the spirit of the control. This is predefined, and must be documented with a
TRA performed to show the mischief is properly managed.
TRA ✔Correct Answer-Targeted risk analysis
Mischief ✔Correct Answer-Risk or bad event that would be prevented with implantation of a
control.
|Latest Version |Already Graded A+
PAN ✔Correct Answer-Primary account numbers
Cardholder Data (CHD) ✔Correct Answer-Any type of personally identifiable information (PII)
associated with a person who has a payment card, such as a credit or debit card.
PAN, cardholder name, expiration date, service code
Sensitive Authentication Data (SAD) ✔Correct Answer-Full track data, card verification code, PIN
and PIN blocks
Can cardholder data or SAD be stored after authorization if protected? ✔Correct Answer-
Cardholder data can, SAD cannot.
cardholder ✔Correct Answer-Person to whom a financial transaction card is issued, or an
additional person authorized to use the card.
merchant ✔Correct Answer-The organization accepting payment
acquirer ✔Correct Answer-The merchant's bank
Issuer ✔Correct Answer-The cardholder's bank
service provider ✔Correct Answer-a company or organization that is directly involved in
processing, storage, or transmission of cardholder data on behalf of another entity
i.e. hosting provider, service gateway, software provider
Describe the authorization process ✔Correct Answer-1. Cardholder requests the purchase from
the merchant
2. Merchant contacts acquirer
3. Acquirer contacts payment brand network
4. Payment brand network contacts issuer
5. Issuer approves or declines and sends the response back through the same chain
6. Cardholder receives the receipt of transaction from the merchant
Describe the clearing process ✔Correct Answer-1. Acquirer sends purchase information to
payment brand network
2. Payment brand network sends that info to issuer
3. Issuer prepares data for the cardholder's statement
4. Payment brand network provides complete reconciliation information to acquirer
This is usually completed within 1 business day.
Describe the settlement process. ✔Correct Answer-1. Issuer determines who the acquirer is using
the payment brand network
2. Issuer sends payment directly to acquirer
, 3. Acquirer pays merchant for purchase
4. Issued bills cardholder for purchase
This generally occurs within 2 business days.
PCI SSF ✔Correct Answer-PCI Software Security Framework. Includes secure SDLC and
maintenance for software.
Describe the steps in the PCI DSS Assessment process. ✔Correct Answer-1. Entity defines the
scope, which the assessor then validates prior to the formal assessment start
2. Assessor assesses the entity
3. QSA completes the ROC or the entity completes a SAQ
4. Assessor completes the AOC
5. AOC and applicable documentation are submitted to the requesting organization
ROC ✔Correct Answer-Report on Compliance; the full report completed by an assessor.
AOC ✔Correct Answer-Attestation of Compliance; a document created to share with other
organizations that gives the relevant information but limits the exposure of all details. Akin to an
Executive Summary.
SAQ ✔Correct Answer-Self Assessment Questionnaire. An alternative to the ROC; an entity usually
fills this one out themselves.
PCIP ✔Correct Answer-PCI Professional. Entry level certification; all QSAs qualify, but a PCIP does
not need to be an assessor.
QIR ✔Correct Answer-Qualified Integrator or Reseller. QIRs install payment software and correctly
configure them.
ASV ✔Correct Answer-Approved Scanning Vendor; eligible to perform external vulnerability scans
for a PCI engagement.
SSF Assessor ✔Correct Answer-An assessor for the secure software framework.
PFI ✔Correct Answer-PCI Forensic Investigator
TPSP ✔Correct Answer-Third-Party Service Provider
Defined approach ✔Correct Answer-The explicitly defined requirements on a PCI DSS assessment.
These must be assessed using the defined testing procedure unless there is a legitimate business or
legal limitation, in which a compensating control can be designed.
Customized approach ✔Correct Answer-The entity builds their own control using the customized
approach guidance to fill the spirit of the control. This is predefined, and must be documented with a
TRA performed to show the mischief is properly managed.
TRA ✔Correct Answer-Targeted risk analysis
Mischief ✔Correct Answer-Risk or bad event that would be prevented with implantation of a
control.