Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 24 pages
Exam (elaborations)

PCI ISA CERTIFICATION PRACTICE EXAM 2026 QUESTIONS AND ANSWERS

Document preview thumbnail
Preview 3 out of 24 pages

PCI ISA CERTIFICATION PRACTICE EXAM 2026 QUESTIONS AND ANSWERS

Content preview

PCI ISA CERTIFICATION PRACTICE
EXAM 2026 QUESTIONS AND ANSWERS




1. According to PCI DSS v4.0, what is the minimum frequency for performing a formal risk

assessment?

A. Every six months


B. Annually


C. At least once every 12 months and upon significant changes


D. Every two years


Answer: C


Conceptual Explanation: PCI DSS v4.0 requires organizations to perform a formal risk

assessment at least once every 12 months and following any significant changes to the

environment.


2. Under PCI DSS Requirement 8.4.2, multi-factor authentication (MFA) is required for:

A. Only remote access to the CDE


B. All non-console access to the CDE for administrators


C. All access into the CDE for all personnel

,D. Only for third-party vendors


Answer: C


Conceptual Explanation: PCI DSS v4.0 mandates MFA for all access into the CDE, not just

for remote access or administrative access.


3. Which Self-Assessment Questionnaire (SAQ) is appropriate for merchants who outsource

all payment processing to PCI DSS validated third parties and have no electronic storage of

cardholder data?

A. SAQ B


B. SAQ A-EP


C. SAQ A


D. SAQ D


Answer: C


Conceptual Explanation: SAQ A is for card-not-present merchants (e-commerce,

mail/telephone order) who have fully outsourced all cardholder data functions to validated

third-party service providers.


4. What is the maximum time allowed for a security patch to be installed for ‘Critical’

vulnerabilities?

A. Within 24 hours


B. Within 7 days

, C. Within 90 days


D. Within one month of release


Answer: D


Conceptual Explanation: Requirement 6.3.3 requires that all critical security patches are

installed within one month of release.


5. Which of the following data elements must NOT be stored after authorization, even if

encrypted?

A. Primary Account Number (PAN)


B. Cardholder Name


C. Service Code


D. Sensitive Authentication Data (SAD)


Answer: D


Conceptual Explanation: Sensitive Authentication Data (SAD), which includes CVV2,

CVC2, and CID, must not be stored after authorization.


6. What is the primary role of an Internal Security Assessor (ISA)?

A. To perform external ASV scans for their organization


B. To audit other companies as a third-party consultant


C. To provide legal advice on PCI DSS compliance failures

Document information

Uploaded on
August 12, 2026
Number of pages
24
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Brightstars
3.3
(40)
Sold
266
Followers
7
Items
14493
Last sold
3 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions