PRACTICE EXAM – 200+ QUESTIONS &
ANSWERS WITH DETAILED RATIONALES (PCI
DSS V4.0 ALIGNED STUDY GUIDE) A+ VERIFIED
LATEST VERSION
Questions 1–50 with Detailed Answers & Rationales
1. What is the primary goal of PCI DSS?
A. Increase transaction speed
B. Protect cardholder data
C. Reduce hardware costs
D. Eliminate all cyber threats
Answer: B
Rationale: PCI DSS was developed to protect cardholder data and reduce payment card fraud through
standardized security controls.
2. Which organization maintains PCI DSS?
A. NIST
B. ISO
C. PCI Security Standards Council
D. FTC
Answer: C
Rationale: The PCI Security Standards Council (PCI SSC) develops and maintains PCI DSS and related
standards.
3. Which data element is considered cardholder data?
A. Employee ID
B. PAN
C. IP Address
D. Username
,Answer: B
Rationale: The Primary Account Number (PAN) is the core component of cardholder data.
4. What does CDE stand for?
A. Card Data Encryption
B. Cardholder Data Environment
C. Compliance Data Evaluation
D. Customer Data Encryption
Answer: B
Rationale: The CDE includes people, processes, and technologies that store, process, or transmit
cardholder data.
5. PCI DSS Requirement 1 focuses on:
A. Passwords
B. Encryption
C. Network Security Controls
D. Training
Answer: C
Rationale: Requirement 1 requires installation and maintenance of network security controls to protect
the CDE.
6. Which is an example of strong cryptography?
A. DES
B. MD5
C. TLS 1.2+
D. SHA-1
Answer: C
Rationale: TLS 1.2 and newer versions are considered strong cryptographic protocols.
7. The principle of least privilege means:
A. All users receive administrator access.
B. Users receive only access necessary for their job.
C. Access is unrestricted.
D. Passwords never expire.
,Answer: B
Rationale: Least privilege minimizes risk by limiting access rights.
8. Which PCI DSS requirement addresses access control?
A. Requirement 7
B. Requirement 2
C. Requirement 4
D. Requirement 12
Answer: A
Rationale: Requirement 7 restricts access to system components and cardholder data by business need-
to-know.
9. Multifactor authentication requires:
A. Two passwords
B. At least two different authentication factors
C. Two usernames
D. Two administrators
Answer: B
Rationale: MFA combines factors such as something you know, have, or are.
10. Why is network segmentation important?
A. Eliminates audits
B. Reduces PCI DSS scope
C. Removes firewalls
D. Increases storage
Answer: B
Rationale: Effective segmentation can reduce the number of systems in PCI scope.
11. Which is Sensitive Authentication Data (SAD)?
A. Merchant ID
B. Cardholder Name
C. CVV
D. Expiration Date
, Answer: C
Rationale: CVV is classified as Sensitive Authentication Data.
12. PCI DSS prohibits storage of:
A. PAN
B. Expiration date
C. Cardholder name
D. Full track data after authorization
Answer: D
Rationale: Full track data cannot be retained after authorization.
13. The purpose of vulnerability scanning is to:
A. Increase bandwidth
B. Identify known weaknesses
C. Replace penetration testing
D. Encrypt data
Answer: B
Rationale: Vulnerability scans identify known security vulnerabilities.
14. External vulnerability scans must generally occur:
A. Daily
B. Weekly
C. Quarterly
D. Every two years
Answer: C
Rationale: PCI DSS requires quarterly ASV scans.
15. Penetration testing differs from vulnerability scanning because it:
A. Identifies only missing patches
B. Simulates real-world exploitation
C. Requires no credentials
D. Is fully automated
Answer: B