PCI ISA EXAM QUESTIONS AND
ANSWERS
1. According to PCI DSS v4.0, how often must a targeted risk analysis be performed for any
PCI DSS requirement that provides flexibility for the frequency of a control?
A. Every six months
B. Annually
C. At least once every 12 months and upon significant changes
D. Every two years
Answer: C
Conceptual Explanation: PCI DSS v4.0 introduces the Targeted Risk Analysis (TRA), which
must be performed at least once every 12 months for requirements that allow for a flexible
frequency, ensuring the chosen frequency is appropriate for the risk.
2. Which of the following is considered ‘Sensitive Authentication Data’ that must not be
stored after authorization even if encrypted?
A. Primary Account Number (PAN)
B. Cardholder Name
C. Card Verification Value (CVV2)
,D. Expiration Date
Answer: C
Conceptual Explanation: Sensitive Authentication Data (SAD), such as the three-digit or
four-digit security code printed on the card, must not be stored after the authorization
process is complete.
3. Under Requirement 6.4.3 of PCI DSS v4.0, what must be done regarding scripts loaded and
executed in the consumer’s browser?
A. An inventory of scripts must be maintained and each script must be authorized.
B. Scripts must be approved by the PCI SSC.
C. All scripts must be encrypted using AES-256.
D. Scripts are only permitted if they originate from the primary domain.
Answer: A
Conceptual Explanation: Requirement 6.4.3 requires that all payment page scripts are
managed by maintaining an inventory, ensuring they are authorized, and ensuring their
integrity.
4. A merchant using a fully outsourced e-commerce solution where the consumer is
redirected to a third-party service provider for payment is typically eligible for which SAQ?
A. SAQ A
B. SAQ A-EP
, C. SAQ C-VT
D. SAQ D
Answer: A
Conceptual Explanation: SAQ A is for merchants with all cardholder data functions fully
outsourced to PCI DSS-compliant service providers, and where the merchant has no
electronic storage, processing, or transmission of cardholder data.
5. Which entity is responsible for managing the PCI DSS compliance of a Third-Party Service
Provider (TPSP)?
A. The TPSP itself and its clients (Merchants)
B. The Merchant’s acquiring bank
C. The PCI Security Standards Council (SSC)
D. The Card Brands (Visa/Mastercard) exclusively
Answer: A
Conceptual Explanation: TPSPs are responsible for their own compliance, but merchants
are responsible for ensuring the TPSPs they use are compliant and for managing the
relationship per Requirement 12.8.
6. Requirement 8.4.2 of PCI DSS v4.0 mandates multi-factor authentication (MFA) for which
of the following?
A. Only for remote access from outside the network
ANSWERS
1. According to PCI DSS v4.0, how often must a targeted risk analysis be performed for any
PCI DSS requirement that provides flexibility for the frequency of a control?
A. Every six months
B. Annually
C. At least once every 12 months and upon significant changes
D. Every two years
Answer: C
Conceptual Explanation: PCI DSS v4.0 introduces the Targeted Risk Analysis (TRA), which
must be performed at least once every 12 months for requirements that allow for a flexible
frequency, ensuring the chosen frequency is appropriate for the risk.
2. Which of the following is considered ‘Sensitive Authentication Data’ that must not be
stored after authorization even if encrypted?
A. Primary Account Number (PAN)
B. Cardholder Name
C. Card Verification Value (CVV2)
,D. Expiration Date
Answer: C
Conceptual Explanation: Sensitive Authentication Data (SAD), such as the three-digit or
four-digit security code printed on the card, must not be stored after the authorization
process is complete.
3. Under Requirement 6.4.3 of PCI DSS v4.0, what must be done regarding scripts loaded and
executed in the consumer’s browser?
A. An inventory of scripts must be maintained and each script must be authorized.
B. Scripts must be approved by the PCI SSC.
C. All scripts must be encrypted using AES-256.
D. Scripts are only permitted if they originate from the primary domain.
Answer: A
Conceptual Explanation: Requirement 6.4.3 requires that all payment page scripts are
managed by maintaining an inventory, ensuring they are authorized, and ensuring their
integrity.
4. A merchant using a fully outsourced e-commerce solution where the consumer is
redirected to a third-party service provider for payment is typically eligible for which SAQ?
A. SAQ A
B. SAQ A-EP
, C. SAQ C-VT
D. SAQ D
Answer: A
Conceptual Explanation: SAQ A is for merchants with all cardholder data functions fully
outsourced to PCI DSS-compliant service providers, and where the merchant has no
electronic storage, processing, or transmission of cardholder data.
5. Which entity is responsible for managing the PCI DSS compliance of a Third-Party Service
Provider (TPSP)?
A. The TPSP itself and its clients (Merchants)
B. The Merchant’s acquiring bank
C. The PCI Security Standards Council (SSC)
D. The Card Brands (Visa/Mastercard) exclusively
Answer: A
Conceptual Explanation: TPSPs are responsible for their own compliance, but merchants
are responsible for ensuring the TPSPs they use are compliant and for managing the
relationship per Requirement 12.8.
6. Requirement 8.4.2 of PCI DSS v4.0 mandates multi-factor authentication (MFA) for which
of the following?
A. Only for remote access from outside the network