PCI ISA Exam Questions and Correct Answers
Page 1 of 146
,Question 1
Which of the following best describes requirements for issuers regarding the retention of sensitive authentication
data?
Correct Answer
Issuers are permitted to retain sensitive authentication data only if there is a business need to do so, to support the
issuing function
Question 1
Which of the following is an effective way to reduce the scope of PCI DSS assessment?
- Not store cardholder data
- Encrypt cardholder data
- Mask cardholder data
- Store cardholder data in databases
Correct Answer
Not store cardholder data
Question 2
What types of payment applications does PA DSS apply to?
- Applications developed in-house by an entity to manage their storage of cardholder data during authorization
- Applications offered as an online "software as a service" subscription
- Applications individually designed and customized for each customer
- Applications that are typically sold and installed "of the shelf"
Correct Answer
Applications that are typically sold and installed "of the shelf"
Page 2 of 146
,Question 3
Which of the following is an example of multi-factor authentication?
- A token that must be presented twice during the login process
- A user passphrase and an application-level password
- A user password and a PIN-activated smart card
- A user fingerprint and a user thumbprint
Correct Answer
A user password and a PIN-activated smart card
Question 4
Which of these is a responsibility of an acquirer?
- Maintain list of complaint merchant and service providers
- Determine fines and liability for each card brand compliance program
- Provide the compliance status of their merchants to PCI SSC
- Incur any liability that may result from their merchants' noncompliance with card brand compliance programs
Correct Answer
Incur any liability that may result from their merchants' noncompliance with card brand compliance programs
Page 3 of 146
, Question 5
What should be included in an organization's procedures for managing visitors?
- Visitors are escorted at all times within areas where cardholder data is processed or maintained
- Visitor badges are identical to badges used by onsite personnel
- Visitor log includes visitor name, address, and contact phone number
- Visitors retain their identification (for example, a visitor badge) for 30 days after completion of the visit
Correct Answer
Visitors are escorted at all times within areas where cardholder data is processed or maintained
Question 6
Viewing of audit trails should be limited to:
- Individuals with user privileges
- Individuals with read/write access
- Individuals with administrator privileges
- Individuals with a job-related need
Correct Answer
Individuals with a job-related need
Page 4 of 146
Page 1 of 146
,Question 1
Which of the following best describes requirements for issuers regarding the retention of sensitive authentication
data?
Correct Answer
Issuers are permitted to retain sensitive authentication data only if there is a business need to do so, to support the
issuing function
Question 1
Which of the following is an effective way to reduce the scope of PCI DSS assessment?
- Not store cardholder data
- Encrypt cardholder data
- Mask cardholder data
- Store cardholder data in databases
Correct Answer
Not store cardholder data
Question 2
What types of payment applications does PA DSS apply to?
- Applications developed in-house by an entity to manage their storage of cardholder data during authorization
- Applications offered as an online "software as a service" subscription
- Applications individually designed and customized for each customer
- Applications that are typically sold and installed "of the shelf"
Correct Answer
Applications that are typically sold and installed "of the shelf"
Page 2 of 146
,Question 3
Which of the following is an example of multi-factor authentication?
- A token that must be presented twice during the login process
- A user passphrase and an application-level password
- A user password and a PIN-activated smart card
- A user fingerprint and a user thumbprint
Correct Answer
A user password and a PIN-activated smart card
Question 4
Which of these is a responsibility of an acquirer?
- Maintain list of complaint merchant and service providers
- Determine fines and liability for each card brand compliance program
- Provide the compliance status of their merchants to PCI SSC
- Incur any liability that may result from their merchants' noncompliance with card brand compliance programs
Correct Answer
Incur any liability that may result from their merchants' noncompliance with card brand compliance programs
Page 3 of 146
, Question 5
What should be included in an organization's procedures for managing visitors?
- Visitors are escorted at all times within areas where cardholder data is processed or maintained
- Visitor badges are identical to badges used by onsite personnel
- Visitor log includes visitor name, address, and contact phone number
- Visitors retain their identification (for example, a visitor badge) for 30 days after completion of the visit
Correct Answer
Visitors are escorted at all times within areas where cardholder data is processed or maintained
Question 6
Viewing of audit trails should be limited to:
- Individuals with user privileges
- Individuals with read/write access
- Individuals with administrator privileges
- Individuals with a job-related need
Correct Answer
Individuals with a job-related need
Page 4 of 146