PCI QSR Module Questions with all Correct & 100%
Verified Answers |Latest Version |Already Graded A+
In your role as a QIR, your primary interaction will be with which payment card payment industry
participant? ✔Correct Answer-The Merchant
The set of requirements that a merchant must adhere to in order to be authorized to accept card
card payments is know as the ________. ✔Correct Answer-PCI DSS
Which is the independent body providing oversight of PCI standards? ✔Correct Answer-PCI SSC
The term _________ is used to describe an entity accepting payment cards for payment during a
purchase. ✔Correct Answer-Merchant
The term ________ is used to describe an entity that actually approves the transaction when a
purchase is made. ✔Correct Answer-Issuer
True of False: The PCI Security Stands Council is responsible for enforcing the brand compliance
programs. ✔Correct Answer-False
Which entity is responsible for forensic investigations of account data compromise? ✔Correct
Answer-Payment Brands
Which statements are true? ✔Correct Answer-- Approving Scanning Vendors (ASVS) perform
external vulnerability scans in accordance with PCI DSS Requirements 11.2
- All PA-QSAs are quality security assessorts
Account Data consists of ______________ and ______________. ✔Correct Answer-Cardholder
Data and Sensitive Authentication Data
How many tracks of payment data are typically on a magnetic strip of a payment card? ✔Correct
Answer-2
The standard for validating off-the-shelf software involved in authorization and settlement is:
✔Correct Answer-PA-DSS
The Implementation Guide must be supplied to: ✔Correct Answer-- PA-QSA
- Merchants
- Resellers and Integrators
What are the QIRs responsibilities with regard to the PA-DSS Implementation Guide (IG) ✔Correct
Answer-- Support customer awareness of the IG
- Ensure you are using the latest IG with updates
- Train QIR employees in use of the IG
- Follow the IG instructions for installation
True or False: Merchants using a PA-DSS validated payment applications are automatically in
compliance with PCI DSS? ✔Correct Answer-False
, Which statements are true? ✔Correct Answer-If a QIR employee fails an exam training, the QIR
employee must not lead or manage a Qualified Installation until successfully passing the exam on a
future attempt
PCI SSC Qualified Integrators and Resellers (QIRs) are companies, organizations or other legal entities
that are in compliance with all QIR company requirements as defined in the: ✔Correct Answer-QIR
Qualification Requirements
True or False: QIR employees are required to have a back checks such as previous employment
history, criminal record, credit history and reference checks. ✔Correct Answer-True
QIR access credentials must be: ✔Correct Answer-Unique per QIR employee and per customer site
In preparation for a Qualified Installation, you should provide a customer with the: ✔Correct
Answer-- Lead QIR Name
- Estimate of work to be performed
- Link to QIR Feedback Form
- Expected duration of the work
You are the Lead QIR at a customer site. You notice the conditions within the customer's system, but
outside of the cape of your Qualified Installation, that could lead to a breach. What are your
responsibilities? ✔Correct Answer-- Document all conditions in Part 3 of the Implementation
Statement
- Advice the customer of the issues found
You are completing a Qualified Installation, the customer wants to perform some tasks. Is this
allowed? ✔Correct Answer-Yes
When a QIR has access into a customer's system to provide ongoing support: ✔Correct Answer--
The QIR instructs the merchant on disabling accounts.
- Unique payment application accounts and passwords for each customer location are required.
- The merchant is advised of all accounts set up.
If the QIR access the customer's site remotely then: ✔Correct Answer-- The access must be
deactivated immediately after use.
- Two-factor authentication must be used.
- A secure connection should be used.
- The customer network should only be accessed when needed.
True or False: You are the QIR at a customer engagement. The customer asks you to encrypt sensitive
authentication data. Therefore, the payment application may be configured to store this data after
authorization. ✔Correct Answer-False
You conduct a Qualified Installation for a customer whose payment application stores cardholder
data. Therefore: ✔Correct Answer-- The Primary Account Number must be rendered unreadable
anywhere it is stored.
- The customer must be advised not to store cardholder data on Internet-accessible systems.
- The customer must be advised cryptographic keys must be securely stored and managed
Verified Answers |Latest Version |Already Graded A+
In your role as a QIR, your primary interaction will be with which payment card payment industry
participant? ✔Correct Answer-The Merchant
The set of requirements that a merchant must adhere to in order to be authorized to accept card
card payments is know as the ________. ✔Correct Answer-PCI DSS
Which is the independent body providing oversight of PCI standards? ✔Correct Answer-PCI SSC
The term _________ is used to describe an entity accepting payment cards for payment during a
purchase. ✔Correct Answer-Merchant
The term ________ is used to describe an entity that actually approves the transaction when a
purchase is made. ✔Correct Answer-Issuer
True of False: The PCI Security Stands Council is responsible for enforcing the brand compliance
programs. ✔Correct Answer-False
Which entity is responsible for forensic investigations of account data compromise? ✔Correct
Answer-Payment Brands
Which statements are true? ✔Correct Answer-- Approving Scanning Vendors (ASVS) perform
external vulnerability scans in accordance with PCI DSS Requirements 11.2
- All PA-QSAs are quality security assessorts
Account Data consists of ______________ and ______________. ✔Correct Answer-Cardholder
Data and Sensitive Authentication Data
How many tracks of payment data are typically on a magnetic strip of a payment card? ✔Correct
Answer-2
The standard for validating off-the-shelf software involved in authorization and settlement is:
✔Correct Answer-PA-DSS
The Implementation Guide must be supplied to: ✔Correct Answer-- PA-QSA
- Merchants
- Resellers and Integrators
What are the QIRs responsibilities with regard to the PA-DSS Implementation Guide (IG) ✔Correct
Answer-- Support customer awareness of the IG
- Ensure you are using the latest IG with updates
- Train QIR employees in use of the IG
- Follow the IG instructions for installation
True or False: Merchants using a PA-DSS validated payment applications are automatically in
compliance with PCI DSS? ✔Correct Answer-False
, Which statements are true? ✔Correct Answer-If a QIR employee fails an exam training, the QIR
employee must not lead or manage a Qualified Installation until successfully passing the exam on a
future attempt
PCI SSC Qualified Integrators and Resellers (QIRs) are companies, organizations or other legal entities
that are in compliance with all QIR company requirements as defined in the: ✔Correct Answer-QIR
Qualification Requirements
True or False: QIR employees are required to have a back checks such as previous employment
history, criminal record, credit history and reference checks. ✔Correct Answer-True
QIR access credentials must be: ✔Correct Answer-Unique per QIR employee and per customer site
In preparation for a Qualified Installation, you should provide a customer with the: ✔Correct
Answer-- Lead QIR Name
- Estimate of work to be performed
- Link to QIR Feedback Form
- Expected duration of the work
You are the Lead QIR at a customer site. You notice the conditions within the customer's system, but
outside of the cape of your Qualified Installation, that could lead to a breach. What are your
responsibilities? ✔Correct Answer-- Document all conditions in Part 3 of the Implementation
Statement
- Advice the customer of the issues found
You are completing a Qualified Installation, the customer wants to perform some tasks. Is this
allowed? ✔Correct Answer-Yes
When a QIR has access into a customer's system to provide ongoing support: ✔Correct Answer--
The QIR instructs the merchant on disabling accounts.
- Unique payment application accounts and passwords for each customer location are required.
- The merchant is advised of all accounts set up.
If the QIR access the customer's site remotely then: ✔Correct Answer-- The access must be
deactivated immediately after use.
- Two-factor authentication must be used.
- A secure connection should be used.
- The customer network should only be accessed when needed.
True or False: You are the QIR at a customer engagement. The customer asks you to encrypt sensitive
authentication data. Therefore, the payment application may be configured to store this data after
authorization. ✔Correct Answer-False
You conduct a Qualified Installation for a customer whose payment application stores cardholder
data. Therefore: ✔Correct Answer-- The Primary Account Number must be rendered unreadable
anywhere it is stored.
- The customer must be advised not to store cardholder data on Internet-accessible systems.
- The customer must be advised cryptographic keys must be securely stored and managed