PCI ISA EXAM 2026 PREPARATION
QUESTIONS AND ANSWERS
1. What is the primary role of an Internal Security Assessor (ISA)?
A. To help their own organization achieve PCI DSS compliance and perform internal
assessments.
B. To manage the payment brand compliance programs for the industry.
C. To perform external audits for any merchant or service provider.
D. To provide Approved Scanning Vendor (ASV) services to the general public.
Answer: A
Conceptual Explanation: An ISA is an employee of a PCI-qualified organization who is
trained to perform internal assessments and help their company manage compliance.
2. Which of the following is considered ‘Sensitive Authentication Data’ (SAD)?
A. Primary Account Number (PAN)
B. Full track data (from the magnetic stripe or chip)
C. Cardholder Name
D. Expiration Date
,Answer: B
Conceptual Explanation: Sensitive Authentication Data includes full track data,
CAV2/CVC2/CVV2/CID, and PINs/PIN blocks. PAN and Expiration Date are Cardholder
Data, not SAD.
3. Under PCI DSS Requirement 3, what must happen to Sensitive Authentication Data (SAD)
after authorization?
A. It must not be stored, even if encrypted.
B. It must be rendered unreadable using a one-way hash.
C. It must be encrypted using strong cryptography.
D. It can be stored if it is needed for loyalty programs.
Answer: A
Conceptual Explanation: PCI DSS prohibits the storage of Sensitive Authentication Data
after authorization, regardless of whether it is encrypted.
4. Which version of the PCI DSS introduced the ‘Customized Approach’ for meeting
requirements?
A. v2.0
B. v4.0
C. v3.2.1
D. v5.0
, Answer: B
Conceptual Explanation: PCI DSS v4.0 introduced the Customized Approach, allowing
entities to implement alternative security controls to meet a requirement’s objective.
5. What is the minimum frequency for performing internal vulnerability scans under
Requirement 11?
A. Monthly
B. Bi-annually
C. Quarterly
D. Annually
Answer: C
Conceptual Explanation: Requirement 11 specifies that internal vulnerability scans must
be performed at least once every three months (quarterly).
6. Who is responsible for determining whether a merchant is required to submit a ROC or an
SAQ?
A. The PCI Security Standards Council (SSC)
B. The Internal Security Assessor (ISA)
C. The individual payment brands or the acquirer
D. The Approved Scanning Vendor (ASV)
Answer: C
QUESTIONS AND ANSWERS
1. What is the primary role of an Internal Security Assessor (ISA)?
A. To help their own organization achieve PCI DSS compliance and perform internal
assessments.
B. To manage the payment brand compliance programs for the industry.
C. To perform external audits for any merchant or service provider.
D. To provide Approved Scanning Vendor (ASV) services to the general public.
Answer: A
Conceptual Explanation: An ISA is an employee of a PCI-qualified organization who is
trained to perform internal assessments and help their company manage compliance.
2. Which of the following is considered ‘Sensitive Authentication Data’ (SAD)?
A. Primary Account Number (PAN)
B. Full track data (from the magnetic stripe or chip)
C. Cardholder Name
D. Expiration Date
,Answer: B
Conceptual Explanation: Sensitive Authentication Data includes full track data,
CAV2/CVC2/CVV2/CID, and PINs/PIN blocks. PAN and Expiration Date are Cardholder
Data, not SAD.
3. Under PCI DSS Requirement 3, what must happen to Sensitive Authentication Data (SAD)
after authorization?
A. It must not be stored, even if encrypted.
B. It must be rendered unreadable using a one-way hash.
C. It must be encrypted using strong cryptography.
D. It can be stored if it is needed for loyalty programs.
Answer: A
Conceptual Explanation: PCI DSS prohibits the storage of Sensitive Authentication Data
after authorization, regardless of whether it is encrypted.
4. Which version of the PCI DSS introduced the ‘Customized Approach’ for meeting
requirements?
A. v2.0
B. v4.0
C. v3.2.1
D. v5.0
, Answer: B
Conceptual Explanation: PCI DSS v4.0 introduced the Customized Approach, allowing
entities to implement alternative security controls to meet a requirement’s objective.
5. What is the minimum frequency for performing internal vulnerability scans under
Requirement 11?
A. Monthly
B. Bi-annually
C. Quarterly
D. Annually
Answer: C
Conceptual Explanation: Requirement 11 specifies that internal vulnerability scans must
be performed at least once every three months (quarterly).
6. Who is responsible for determining whether a merchant is required to submit a ROC or an
SAQ?
A. The PCI Security Standards Council (SSC)
B. The Internal Security Assessor (ISA)
C. The individual payment brands or the acquirer
D. The Approved Scanning Vendor (ASV)
Answer: C