PCIP Certification Exam Ultimate Study Guide &
Real Exam Practice Test Bank
Information
Cannot be stored after authorization as defined in
Requirement 3 -
,,,answer,,,..Sensitive Authentication Data: full track / CVV
/ PIN
Scope of PCI DSS Requirements - ,,,answer,,,..cardholder data
environment (CDE) / System components, people, and
processes that could impact the security of the CDE
is segmentation a requirement? - ,,,answer,,,..No but it can
greatly reduce the scope, cost, difficulty, and risk involving
processing and compliance..
,"Flat Network" - ,,,answer,,,..entire network is in scope for the
PCI DSS
assessment ( no
segmentation)
Encrypted Cardholder Data and Impact on PCI DSS Scope -
,,,answer,,,..Encryption of cardholder data with strong
cryptography is an acceptable method of rendering the data
unreadable according to PCI DSS Requirement 3.5. However,
encryption alone is generally insufficient to render the
cardholder data out of scope for PCI DSS and does not remove
the need for PCI DSS in that environment.
Compensating controls are part of which
approach? -
,,,answer,,,..Defined
Approach
Network security controls (NSCs) - ,,,answer,,,..firewalls and
other
network security tech - control network traffic between two
or more
,logical or physical network
segments
data-flow diagram(s) - ,,,answer,,,..should include all
connection points where account data is received into and sent
out of the network, including connections to open, public
networks, application processing flows, storage, transmissions
between systems and networks, and file backups.
PAN is rendered unreadable anywhere it is stored by using any
of the
following approaches: - ,,,answer,,,..hashes
Cardholder Data includes: - ,,,answer,,,..• Primary Account
Number
(PAN) • Cardholder Name • Expiration Date • Service
Code
Sensitive Authentication Data includes: - ,,,answer,,,..• Full track
data
(magnetic-stripe data or equivalent on a chip) • Card verification
code •
PINs/PIN blocks
, account data covers the following: - ,,,answer,,,..the full PAN, any
other
elements of cardholder data that are present with the PAN,
and any
elements of sensitive authentication
data.
Configurations of NSCs are reviewed at least once every -
,,,answer,,,..six
months
Inbound traffic to the CDE is restricted as follows: -
,,,answer,,,..To only
traffic that is necessary. • All other traffic is specifically
denied
NSCs are implemented between - ,,,answer,,,..trusted and
untrusted
networks.
Real Exam Practice Test Bank
Information
Cannot be stored after authorization as defined in
Requirement 3 -
,,,answer,,,..Sensitive Authentication Data: full track / CVV
/ PIN
Scope of PCI DSS Requirements - ,,,answer,,,..cardholder data
environment (CDE) / System components, people, and
processes that could impact the security of the CDE
is segmentation a requirement? - ,,,answer,,,..No but it can
greatly reduce the scope, cost, difficulty, and risk involving
processing and compliance..
,"Flat Network" - ,,,answer,,,..entire network is in scope for the
PCI DSS
assessment ( no
segmentation)
Encrypted Cardholder Data and Impact on PCI DSS Scope -
,,,answer,,,..Encryption of cardholder data with strong
cryptography is an acceptable method of rendering the data
unreadable according to PCI DSS Requirement 3.5. However,
encryption alone is generally insufficient to render the
cardholder data out of scope for PCI DSS and does not remove
the need for PCI DSS in that environment.
Compensating controls are part of which
approach? -
,,,answer,,,..Defined
Approach
Network security controls (NSCs) - ,,,answer,,,..firewalls and
other
network security tech - control network traffic between two
or more
,logical or physical network
segments
data-flow diagram(s) - ,,,answer,,,..should include all
connection points where account data is received into and sent
out of the network, including connections to open, public
networks, application processing flows, storage, transmissions
between systems and networks, and file backups.
PAN is rendered unreadable anywhere it is stored by using any
of the
following approaches: - ,,,answer,,,..hashes
Cardholder Data includes: - ,,,answer,,,..• Primary Account
Number
(PAN) • Cardholder Name • Expiration Date • Service
Code
Sensitive Authentication Data includes: - ,,,answer,,,..• Full track
data
(magnetic-stripe data or equivalent on a chip) • Card verification
code •
PINs/PIN blocks
, account data covers the following: - ,,,answer,,,..the full PAN, any
other
elements of cardholder data that are present with the PAN,
and any
elements of sensitive authentication
data.
Configurations of NSCs are reviewed at least once every -
,,,answer,,,..six
months
Inbound traffic to the CDE is restricted as follows: -
,,,answer,,,..To only
traffic that is necessary. • All other traffic is specifically
denied
NSCs are implemented between - ,,,answer,,,..trusted and
untrusted
networks.