QUALYS PCI EXAM WITH ALL CORRECT & 100%
VERIFIED ANSWERS |ALREADY GRADED A+
1. Which of the following best describes the recommended process for achieving the PCI DSS 11.2.2
external scanning requirement? ✔Correct Answer-A)Scan, Remediate, Report
2. Sensitive authentication data should never be: ✔Correct Answer-B)Stored
3. PCI Security Standards Council is made up of: ✔Correct Answer-A)Major Credit Card Companies
4. The "stakeholder that is required to hold the Scan Customer responsible for compliance is:
✔Correct Answer-D)QSA
5. vulnerability scan report that was created using the PCI Scan Report Template (in Qualys VM), will
display each detected vulnerability, along with its______________. ✔Correct Answer-A)PASS/FAIL
status
6. PCI DSS 11.2.1 (internal scanning) requires the resolution of_________
vulnerabilities. ✔Correct Answer-B)High-risk
7. When viewing vulnerability details from an external PCI scan, you can view the following data
(choose 3): ✔Correct Answer-A)solution
B)results
D)threat
8. Which PCI DSS "Stakeholder" does Qualys represent? ✔Correct Answer-A)Approved Scanning
Vendor (ASV)
9. Which of the twelve (12) PCI DSS requirements are covered or addressed by the Qualys PCI
Compliance application? (choose 3) ✔Correct Answer-A)6
C)1
D11
10. Automated "Fault Injection" testing can typically detect ___________of Web application
vulnerabilities. ✔Correct Answer-D)80 to 85%
11. Cardholder Data includes (choose 2): ✔Correct Answer-A)Cardholder name
C)Primary Account number
12. The stakeholders who are part of the external scanning requirement of PCI are (choose all that
apply): ✔Correct Answer-B)Scan Customer
C)Payment Brands
D)Approved Scanning Vendor
13. Vulnerabilities that typically cause a fail in PCI have a CVSS base score of______or above.
✔Correct Answer-D)4
14.Of the following______is NOT a valid status of a report generated from the PCI user interface.
✔Correct Answer-B)Generated
VERIFIED ANSWERS |ALREADY GRADED A+
1. Which of the following best describes the recommended process for achieving the PCI DSS 11.2.2
external scanning requirement? ✔Correct Answer-A)Scan, Remediate, Report
2. Sensitive authentication data should never be: ✔Correct Answer-B)Stored
3. PCI Security Standards Council is made up of: ✔Correct Answer-A)Major Credit Card Companies
4. The "stakeholder that is required to hold the Scan Customer responsible for compliance is:
✔Correct Answer-D)QSA
5. vulnerability scan report that was created using the PCI Scan Report Template (in Qualys VM), will
display each detected vulnerability, along with its______________. ✔Correct Answer-A)PASS/FAIL
status
6. PCI DSS 11.2.1 (internal scanning) requires the resolution of_________
vulnerabilities. ✔Correct Answer-B)High-risk
7. When viewing vulnerability details from an external PCI scan, you can view the following data
(choose 3): ✔Correct Answer-A)solution
B)results
D)threat
8. Which PCI DSS "Stakeholder" does Qualys represent? ✔Correct Answer-A)Approved Scanning
Vendor (ASV)
9. Which of the twelve (12) PCI DSS requirements are covered or addressed by the Qualys PCI
Compliance application? (choose 3) ✔Correct Answer-A)6
C)1
D11
10. Automated "Fault Injection" testing can typically detect ___________of Web application
vulnerabilities. ✔Correct Answer-D)80 to 85%
11. Cardholder Data includes (choose 2): ✔Correct Answer-A)Cardholder name
C)Primary Account number
12. The stakeholders who are part of the external scanning requirement of PCI are (choose all that
apply): ✔Correct Answer-B)Scan Customer
C)Payment Brands
D)Approved Scanning Vendor
13. Vulnerabilities that typically cause a fail in PCI have a CVSS base score of______or above.
✔Correct Answer-D)4
14.Of the following______is NOT a valid status of a report generated from the PCI user interface.
✔Correct Answer-B)Generated