PCI DSS 4.0 Exam with all Correct & 100% Verified
Answers |Latest Version |Already Graded A+
Requirements not Eligible for Customized Approach ✔Correct Answer-You can't use a custom
control to store SAD after authorization
Two approaches entities can take in PCI DSS 4.0 ✔Correct Answer-Defined Approach, Customized
Approach
What are traits of Customized approach ✔Correct Answer-Build a customized control that meets
the customized control objective
the entity must perform a targeted risk analysis for each customized control, as well as perform
testing, monitoring and provide extra documentation for the assessor.
No compensating controls are an option for meeting the compensating control objective.
Steps for using Customized Approach (Entity) ✔Correct Answer-Document and maintain evidence
about each customized control
Perform targeted risk analysis
Test and monitor the control
Steps for using customized approach (Assessor) ✔Correct Answer-Review Entity's evidence
Derive the testing procedures
Test the control
Sample Templates to Support Customized Approach ✔Correct Answer-Controls Matrix Template
Targeted Risk Analysis template
Customized Control Matrix in Appendix E for Customized Approach ✔Correct Answer-Entity
completes it, assessor reviews for accuracy
Customized Targeted Risk Analysis Appendix E2 for Customized Approach ✔Correct Answer-Entity
fills it out, Assessor reviews it.
Mischief ✔Correct Answer-Refers to an occurence or an event that negatively affects the security
posture of the entity
1.2 (NSC's) Review of configurations occur: ✔Correct Answer-Every 6 months
3.2 (Storage of Data is kept at a minimum) Verify data has been deleted at least once every:
✔Correct Answer-3 months
, 3.4 (Access to displays of full PAN and ability to copy cardholder data are restricted) Masking PAN:
✔Correct Answer-First 6, last 4 displayed
5.2 (Malicious software is prevented, or detected and addressed) Anti-malware is deployed on all
system components, except: ✔Correct Answer-For those systems components identified in
periodic evaluations
6.3 (Security Vulnerabilities are identified and addressed) Software Patching-critical or high-security
patches installed: ✔Correct Answer-Within 1 month of release
6.4 (Public-facing web applications are protected against attacks) Security Assessment- at least every:
✔Correct Answer-12 months or automated technical solutions
Who must review the report before it is finalized? ✔Correct Answer-The assessed entity
7.2 (Access to system components and data is appropriately defined and assigned) User accounts
review at least: ✔Correct Answer-Every 6 months
8.2 (User identification and related accounts for users and administrators are strictly managed
throughout an account lifecycle) Revoked User Accounts revoked: ✔Correct Answer-Immediately
8.2 Inactive user accounts removed or disabled within ✔Correct Answer-90 days
8.2 Session idle timeout after no more than ✔Correct Answer-15 min
8.3 (Strong authentication for users and administrators is established and managed) Locking out after
no more than and for at least: ✔Correct Answer-10 attempts and for at least 30 min
8.3 Password/passphrases character minimum: ✔Correct Answer-12 with 8
8.3 New Passwords not the same as the last ✔Correct Answer-4
8.3 Passwords in single-factor authentication changed: ✔Correct Answer-every 90 days
10.3 (Audit Logs are protected from destruction and unauthorized modifications) Logs are protected
and backed up: ✔Correct Answer-Promptly
10.5 (Audit log history is retained and available for analysis) Retain log history for at least, with at
least available: ✔Correct Answer-1 year, with 3 months available for immediate analysis
11.2 (wireless access points are identified and monitored, and unauthorized wireless access points
are addressed) All authorized and unauthorized wireless access points are detected and identified at
least once every: ✔Correct Answer-3 months
11.3. Internal and ASV scans are performed at least once every: ✔Correct Answer-3 months
11.4 (External and internal penetration testing is regularly performed and exploitable vulnerabilities
and security weaknesses are corrected) Testing performed at least once every: ✔Correct Answer-
12 months and/or after significant changes
Answers |Latest Version |Already Graded A+
Requirements not Eligible for Customized Approach ✔Correct Answer-You can't use a custom
control to store SAD after authorization
Two approaches entities can take in PCI DSS 4.0 ✔Correct Answer-Defined Approach, Customized
Approach
What are traits of Customized approach ✔Correct Answer-Build a customized control that meets
the customized control objective
the entity must perform a targeted risk analysis for each customized control, as well as perform
testing, monitoring and provide extra documentation for the assessor.
No compensating controls are an option for meeting the compensating control objective.
Steps for using Customized Approach (Entity) ✔Correct Answer-Document and maintain evidence
about each customized control
Perform targeted risk analysis
Test and monitor the control
Steps for using customized approach (Assessor) ✔Correct Answer-Review Entity's evidence
Derive the testing procedures
Test the control
Sample Templates to Support Customized Approach ✔Correct Answer-Controls Matrix Template
Targeted Risk Analysis template
Customized Control Matrix in Appendix E for Customized Approach ✔Correct Answer-Entity
completes it, assessor reviews for accuracy
Customized Targeted Risk Analysis Appendix E2 for Customized Approach ✔Correct Answer-Entity
fills it out, Assessor reviews it.
Mischief ✔Correct Answer-Refers to an occurence or an event that negatively affects the security
posture of the entity
1.2 (NSC's) Review of configurations occur: ✔Correct Answer-Every 6 months
3.2 (Storage of Data is kept at a minimum) Verify data has been deleted at least once every:
✔Correct Answer-3 months
, 3.4 (Access to displays of full PAN and ability to copy cardholder data are restricted) Masking PAN:
✔Correct Answer-First 6, last 4 displayed
5.2 (Malicious software is prevented, or detected and addressed) Anti-malware is deployed on all
system components, except: ✔Correct Answer-For those systems components identified in
periodic evaluations
6.3 (Security Vulnerabilities are identified and addressed) Software Patching-critical or high-security
patches installed: ✔Correct Answer-Within 1 month of release
6.4 (Public-facing web applications are protected against attacks) Security Assessment- at least every:
✔Correct Answer-12 months or automated technical solutions
Who must review the report before it is finalized? ✔Correct Answer-The assessed entity
7.2 (Access to system components and data is appropriately defined and assigned) User accounts
review at least: ✔Correct Answer-Every 6 months
8.2 (User identification and related accounts for users and administrators are strictly managed
throughout an account lifecycle) Revoked User Accounts revoked: ✔Correct Answer-Immediately
8.2 Inactive user accounts removed or disabled within ✔Correct Answer-90 days
8.2 Session idle timeout after no more than ✔Correct Answer-15 min
8.3 (Strong authentication for users and administrators is established and managed) Locking out after
no more than and for at least: ✔Correct Answer-10 attempts and for at least 30 min
8.3 Password/passphrases character minimum: ✔Correct Answer-12 with 8
8.3 New Passwords not the same as the last ✔Correct Answer-4
8.3 Passwords in single-factor authentication changed: ✔Correct Answer-every 90 days
10.3 (Audit Logs are protected from destruction and unauthorized modifications) Logs are protected
and backed up: ✔Correct Answer-Promptly
10.5 (Audit log history is retained and available for analysis) Retain log history for at least, with at
least available: ✔Correct Answer-1 year, with 3 months available for immediate analysis
11.2 (wireless access points are identified and monitored, and unauthorized wireless access points
are addressed) All authorized and unauthorized wireless access points are detected and identified at
least once every: ✔Correct Answer-3 months
11.3. Internal and ASV scans are performed at least once every: ✔Correct Answer-3 months
11.4 (External and internal penetration testing is regularly performed and exploitable vulnerabilities
and security weaknesses are corrected) Testing performed at least once every: ✔Correct Answer-
12 months and/or after significant changes