PCI DSS Fundamentals Exam with all Correct & 100%
Verified Answers |Latest Version |Already Graded A+
A Sustainable Compliance Program must: ✔Correct Answer-Be implemented into Business-as-usual
(BAU) activities as part of the organizations overall security strategy.
True or False: The driving objective behind all PCI DSS compliance activities is to attain a compliant
report. ✔Correct Answer-False ongoing security of cardholder data is the driving objective which
will lead to a compliant report
Effective metrics program can provide useful data for: ✔Correct Answer-Allocation of resources to
minimize risk occurrence and measure the business consequences of security events.
Security Goals should include: ✔Correct Answer-Continuous monitoring, testing, documenting
implementation, effectiveness, efficiency, impact, and status of controls and activities.
Control-failure response processes should include: ✔Correct Answer-minimizing the impact of the
incident, restoring controls, performing root-cause analysis and remediation, implementing
hardening standards and enhancing monitoring.
True or False: 3rd party providers are monitored by issuers ✔Correct Answer-False, Organizations
should develop and implement processes to monitor the compliance status of its service providers to
determine whether a change in status requires a change in the relationship.
True or False: Organizations should evolve their controls with the threat landscape, changes in
organizations structure, new business initiatives, and changes in business processes and technologies
✔Correct Answer-True Evolving security reduces the negative impact on an organizations security
posture.
How can organizations prevent "fall-off" between assessments ✔Correct Answer-Develop a well
designed program of security controls and monitoring practices.
True or False: Network segmentation is one method that can help reduce the number of system
components in scope for PCI DSS ✔Correct Answer-True, outsourcing to a 3rd party service
provider and using P2PE are other methods of reducing scope.
Who is ultimately responsible for making its own PCI DSS scoping decisions, designing effective
segmentation and ensuring its own PCI DSS compliance and related validation requirements are met
✔Correct Answer-Each entity is responsible for themselves.
What does segmentation involve ✔Correct Answer-additional controls to separate systems with
different security needs.
Segmentation can consist of: ✔Correct Answer-logical controls, physical controls or a combination
of both
Name some commonly used segmentation methods ✔Correct Answer-Firewalls and router
configurations (preventing traffic in & out), network configurations (preventing communication) and
physical controls
, E-commerce Payment Gateway/Payment Processor ✔Correct Answer-may facilitate payment
authorization by forwarding transactions to the processors/acquirers that perform the actual
payment authorization.
E-Commerce infrastructure may include: ✔Correct Answer-consumers browser, application
servers, database servers and any other underlying servers or devices such as network devices.
Merchants infrastructure may include: ✔Correct Answer-networking and operating system,
firewalls, switches, routers and any virtual infrastructure such as hypervisors.
E-commerce infrastructure typically follows what 3-tier computing model ✔Correct Answer-1)
Presentation layer (web) 2) processing layer (application) 3) data-storage layer
Requirements for firewall configuration standards are: ✔Correct Answer-a firewall at each internet
connection and between any demilitarized zone (DMZ) and the internal network zone.
Examine firewall and router configurations to verify that a DMZ is implemented to limit ✔Correct
Answer-inbound traffic to only a system components that provide authorized publicly accessible
services, protocols, and ports
Examine firewall and router configurations to verify that inbound internet traffic is limited to
✔Correct Answer-IP addresses within the DMZ
How often should information security policies and risk assessments be completed ✔Correct
Answer-Annually and with any changes
Which items are included in a risk assessment ✔Correct Answer-Identify critical assets, threats,
vulnerabilities, formal documented analysis.
National Institute of Standards and Technology (NIST) proposes what 3 security metrics ✔Correct
Answer-1) implementation measures 2) efficiency and effectiveness measures, 3) impact measures
Access to queries and actions on data bases are through ✔Correct Answer-programmatic methods
only
Direct access to data bases are restricted to ✔Correct Answer-database administrators
True or False: In a flat network, all systems are in scope if any single system stores, processes, or
transmits account data ✔Correct Answer-True this is why network segmentation is important
Network segmentation (isolating) the cardholder data environment from the remainder of the
entity's network may reduce ✔Correct Answer-scope, cost, difficulty of implementing and
maintaining PCI DSS controls, risk to the organization
Which 3 servers are in scope for PCI DSS ✔Correct Answer-1) Web servers 2) Application Servers 3)
Database Servers
True or False: There are no solutions or technologies that eliminates all PCI DSS requirements.
✔Correct Answer-True encryption or tokenization may help reduce risk
Verified Answers |Latest Version |Already Graded A+
A Sustainable Compliance Program must: ✔Correct Answer-Be implemented into Business-as-usual
(BAU) activities as part of the organizations overall security strategy.
True or False: The driving objective behind all PCI DSS compliance activities is to attain a compliant
report. ✔Correct Answer-False ongoing security of cardholder data is the driving objective which
will lead to a compliant report
Effective metrics program can provide useful data for: ✔Correct Answer-Allocation of resources to
minimize risk occurrence and measure the business consequences of security events.
Security Goals should include: ✔Correct Answer-Continuous monitoring, testing, documenting
implementation, effectiveness, efficiency, impact, and status of controls and activities.
Control-failure response processes should include: ✔Correct Answer-minimizing the impact of the
incident, restoring controls, performing root-cause analysis and remediation, implementing
hardening standards and enhancing monitoring.
True or False: 3rd party providers are monitored by issuers ✔Correct Answer-False, Organizations
should develop and implement processes to monitor the compliance status of its service providers to
determine whether a change in status requires a change in the relationship.
True or False: Organizations should evolve their controls with the threat landscape, changes in
organizations structure, new business initiatives, and changes in business processes and technologies
✔Correct Answer-True Evolving security reduces the negative impact on an organizations security
posture.
How can organizations prevent "fall-off" between assessments ✔Correct Answer-Develop a well
designed program of security controls and monitoring practices.
True or False: Network segmentation is one method that can help reduce the number of system
components in scope for PCI DSS ✔Correct Answer-True, outsourcing to a 3rd party service
provider and using P2PE are other methods of reducing scope.
Who is ultimately responsible for making its own PCI DSS scoping decisions, designing effective
segmentation and ensuring its own PCI DSS compliance and related validation requirements are met
✔Correct Answer-Each entity is responsible for themselves.
What does segmentation involve ✔Correct Answer-additional controls to separate systems with
different security needs.
Segmentation can consist of: ✔Correct Answer-logical controls, physical controls or a combination
of both
Name some commonly used segmentation methods ✔Correct Answer-Firewalls and router
configurations (preventing traffic in & out), network configurations (preventing communication) and
physical controls
, E-commerce Payment Gateway/Payment Processor ✔Correct Answer-may facilitate payment
authorization by forwarding transactions to the processors/acquirers that perform the actual
payment authorization.
E-Commerce infrastructure may include: ✔Correct Answer-consumers browser, application
servers, database servers and any other underlying servers or devices such as network devices.
Merchants infrastructure may include: ✔Correct Answer-networking and operating system,
firewalls, switches, routers and any virtual infrastructure such as hypervisors.
E-commerce infrastructure typically follows what 3-tier computing model ✔Correct Answer-1)
Presentation layer (web) 2) processing layer (application) 3) data-storage layer
Requirements for firewall configuration standards are: ✔Correct Answer-a firewall at each internet
connection and between any demilitarized zone (DMZ) and the internal network zone.
Examine firewall and router configurations to verify that a DMZ is implemented to limit ✔Correct
Answer-inbound traffic to only a system components that provide authorized publicly accessible
services, protocols, and ports
Examine firewall and router configurations to verify that inbound internet traffic is limited to
✔Correct Answer-IP addresses within the DMZ
How often should information security policies and risk assessments be completed ✔Correct
Answer-Annually and with any changes
Which items are included in a risk assessment ✔Correct Answer-Identify critical assets, threats,
vulnerabilities, formal documented analysis.
National Institute of Standards and Technology (NIST) proposes what 3 security metrics ✔Correct
Answer-1) implementation measures 2) efficiency and effectiveness measures, 3) impact measures
Access to queries and actions on data bases are through ✔Correct Answer-programmatic methods
only
Direct access to data bases are restricted to ✔Correct Answer-database administrators
True or False: In a flat network, all systems are in scope if any single system stores, processes, or
transmits account data ✔Correct Answer-True this is why network segmentation is important
Network segmentation (isolating) the cardholder data environment from the remainder of the
entity's network may reduce ✔Correct Answer-scope, cost, difficulty of implementing and
maintaining PCI DSS controls, risk to the organization
Which 3 servers are in scope for PCI DSS ✔Correct Answer-1) Web servers 2) Application Servers 3)
Database Servers
True or False: There are no solutions or technologies that eliminates all PCI DSS requirements.
✔Correct Answer-True encryption or tokenization may help reduce risk