PCI Knowledge Check v2 with all Correct & 100%
Verified Answers |Latest Version |Already Graded A+
Methods for stealing payment card data ✔Correct Answer-Includes physical skimming, malware
and weak passwords.
The PCI DSS applies to: ✔Correct Answer-Any entity that stores, processes, or transmitts payment
card account data.
The P2PE standard covers: ✔Correct Answer-Encryption, decryption, key management
requirements for point to point encryption solutions.
The standard for validating off-the-self payment applications used in authorization and settlement
✔Correct Answer-PA-DSS (Payment Application Data Security Standard) PA-DSS is the standard used
by PA-QSAs to validate payment applications.
Merchants using PA-DSS validated payment applications are automatically PCI DSS compliant
✔Correct Answer-False - Using PA-DSS validated applications is not the only requirement for a
merchant to become PCI DSS Compliant.
Which of the below functions is associated with acquirers? ✔Correct Answer-Acquirers are
involved in authentication, clearing and settlement for their merchant.
Which of the following entities will ultimately approve a purchase? ✔Correct Answer-The issuer
In which step does the payment brand network provide complete recognition to the merchant's
bank. ✔Correct Answer-During clearing, the processor provides complete reconciliation to the
merchant's bank.
A company that (blank) is considered to be a service to be a service provider. ✔Correct Answer-
controls impact the security of cardholder data.
Which of the following are parts of the examples of service providers? ✔Correct Answer-Data
Center Hosting Provides, Payment Gateways. and Independent Sales Organizations (ISOs) or External
Sales Agents (ESAs).
Which of the following are parts of the Payment Brand role? ✔Correct Answer-Developing and
enforcing compliance programs, accepting validation documentation from approved QSA, PA-QSA,
and ASV companies and their employees, and endorsing QSA, PA-QSA, and ASV company
qualification criteria.
Merchant obligation may include submitting their compliance status to multiple entities. ✔Correct
Answer-True - Merchants may have to submit to multiple entities.
Level 1 and Level 2 merchants must include (blank) as part of their PCI DSS compliance validation
reporting process? ✔Correct Answer-Quarterly external vulnerability scans to be performed by an
(ASV) Approved Scanning Vendor. Level 2 merchants may use SAQ validate compliance.
SAQ D ✔Correct Answer-Service provider using only web based virtual terminal
, SAQ A ✔Correct Answer-MO/TO merchant with all payment functions outsourced to a compliant
service provider
SAQ C ✔Correct Answer-Merchant with standalone payment application connected to the internet
SAQ B ✔Correct Answer-Merchant with only card-present dial-out terminals.
SAQ P2PE ✔Correct Answer-Merchant who is using a validated P2PE solution listed on the PCI SSC
Website
SAQ A-EP ✔Correct Answer-An online merchant with a payment page that accepts cardholder
data, but transmits the data to a PCI DSS-compliant service provider
SAQ A ✔Correct Answer-An online merchant that displays a PCI DSS compliant service providers
payment page IFRAME, All page content is from the PSP.
SAQ B-IP ✔Correct Answer-Merchants using an end-to-end encryption solution (E2EE) that utilizes
PCI PTS-Approved POI devices with communicate with acquirer over an IP Network.
Which of the following could PA-DSS apply to? ✔Correct Answer-Third party - off-the-self payment
application - PA-DSS only applies to applications that store, process, or transmits cardholder data for
authorization or settlement, and are sold, licensed or distributed off-the-self to third parties.
Use of Qualified Integrator/Reseller(QIR) : ✔Correct Answer-A good step toward PCI DSS
compliance.
The presumption of P2PE is that: ✔Correct Answer-Data cannot be decrypted between the source
and the destination point
Which entity is responsible for developing and enforcing compliance programs? ✔Correct Answer-
Payment Brands.
Which entity is responsible for forensic investigations of account data? ✔Correct Answer-The
Payment Brands.
Account data consists of (blank) and (blank)? ✔Correct Answer-Cardholders data and Sensitive
Authentication Data (SAD).
Storing track data is permitted when(blank) ✔Correct Answer-It is being stored by issuers.
When scoping an environment for PCI DSS, it is important to identify (blank) ✔Correct Answer-The
role played by Payment Brands include developing and enforcing compliance programs, accepting
validation documentation from QSA, PA-QSA, ASV companies and their employees and endorsing
QSA, PA-QSA, and ASV company criteria.
Which of these devices can be used to provide network segmentation controls? ✔Correct Answer-
Routers, switches and firewalls all provide controls which could be used to properly segment.
If virtualization technology are used in cardholder data environment: ✔Correct Answer-Then they
are included in scope of PCI DSS.
Verified Answers |Latest Version |Already Graded A+
Methods for stealing payment card data ✔Correct Answer-Includes physical skimming, malware
and weak passwords.
The PCI DSS applies to: ✔Correct Answer-Any entity that stores, processes, or transmitts payment
card account data.
The P2PE standard covers: ✔Correct Answer-Encryption, decryption, key management
requirements for point to point encryption solutions.
The standard for validating off-the-self payment applications used in authorization and settlement
✔Correct Answer-PA-DSS (Payment Application Data Security Standard) PA-DSS is the standard used
by PA-QSAs to validate payment applications.
Merchants using PA-DSS validated payment applications are automatically PCI DSS compliant
✔Correct Answer-False - Using PA-DSS validated applications is not the only requirement for a
merchant to become PCI DSS Compliant.
Which of the below functions is associated with acquirers? ✔Correct Answer-Acquirers are
involved in authentication, clearing and settlement for their merchant.
Which of the following entities will ultimately approve a purchase? ✔Correct Answer-The issuer
In which step does the payment brand network provide complete recognition to the merchant's
bank. ✔Correct Answer-During clearing, the processor provides complete reconciliation to the
merchant's bank.
A company that (blank) is considered to be a service to be a service provider. ✔Correct Answer-
controls impact the security of cardholder data.
Which of the following are parts of the examples of service providers? ✔Correct Answer-Data
Center Hosting Provides, Payment Gateways. and Independent Sales Organizations (ISOs) or External
Sales Agents (ESAs).
Which of the following are parts of the Payment Brand role? ✔Correct Answer-Developing and
enforcing compliance programs, accepting validation documentation from approved QSA, PA-QSA,
and ASV companies and their employees, and endorsing QSA, PA-QSA, and ASV company
qualification criteria.
Merchant obligation may include submitting their compliance status to multiple entities. ✔Correct
Answer-True - Merchants may have to submit to multiple entities.
Level 1 and Level 2 merchants must include (blank) as part of their PCI DSS compliance validation
reporting process? ✔Correct Answer-Quarterly external vulnerability scans to be performed by an
(ASV) Approved Scanning Vendor. Level 2 merchants may use SAQ validate compliance.
SAQ D ✔Correct Answer-Service provider using only web based virtual terminal
, SAQ A ✔Correct Answer-MO/TO merchant with all payment functions outsourced to a compliant
service provider
SAQ C ✔Correct Answer-Merchant with standalone payment application connected to the internet
SAQ B ✔Correct Answer-Merchant with only card-present dial-out terminals.
SAQ P2PE ✔Correct Answer-Merchant who is using a validated P2PE solution listed on the PCI SSC
Website
SAQ A-EP ✔Correct Answer-An online merchant with a payment page that accepts cardholder
data, but transmits the data to a PCI DSS-compliant service provider
SAQ A ✔Correct Answer-An online merchant that displays a PCI DSS compliant service providers
payment page IFRAME, All page content is from the PSP.
SAQ B-IP ✔Correct Answer-Merchants using an end-to-end encryption solution (E2EE) that utilizes
PCI PTS-Approved POI devices with communicate with acquirer over an IP Network.
Which of the following could PA-DSS apply to? ✔Correct Answer-Third party - off-the-self payment
application - PA-DSS only applies to applications that store, process, or transmits cardholder data for
authorization or settlement, and are sold, licensed or distributed off-the-self to third parties.
Use of Qualified Integrator/Reseller(QIR) : ✔Correct Answer-A good step toward PCI DSS
compliance.
The presumption of P2PE is that: ✔Correct Answer-Data cannot be decrypted between the source
and the destination point
Which entity is responsible for developing and enforcing compliance programs? ✔Correct Answer-
Payment Brands.
Which entity is responsible for forensic investigations of account data? ✔Correct Answer-The
Payment Brands.
Account data consists of (blank) and (blank)? ✔Correct Answer-Cardholders data and Sensitive
Authentication Data (SAD).
Storing track data is permitted when(blank) ✔Correct Answer-It is being stored by issuers.
When scoping an environment for PCI DSS, it is important to identify (blank) ✔Correct Answer-The
role played by Payment Brands include developing and enforcing compliance programs, accepting
validation documentation from QSA, PA-QSA, ASV companies and their employees and endorsing
QSA, PA-QSA, and ASV company criteria.
Which of these devices can be used to provide network segmentation controls? ✔Correct Answer-
Routers, switches and firewalls all provide controls which could be used to properly segment.
If virtualization technology are used in cardholder data environment: ✔Correct Answer-Then they
are included in scope of PCI DSS.