PCI ISA EXAM QUESTIONS AND
ANSWERS 2026
1. According to PCI DSS v4.0.1, what is the mandatory requirement for an entity choosing to
use the Customized Approach for a specific requirement?
A. They must obtain prior approval from the PCI SSC.
B. They must perform a Targeted Risk Analysis (TRA) for each customized control.
C. They must prove that the Defined Approach is technically impossible to implement.
D. They must be a Level 1 Service Provider.
Answer: B
Conceptual Explanation: The Customized Approach requires a Targeted Risk Analysis
(TRA) to justify how the custom control meets the objective and provides the same level of
security as the Defined Approach.
2. Which of the following describes a ‘Security Impacting’ system in the context of scoping?
A. A system that provides security services to the CDE, such as an NTP server or Anti-Virus
server.
B. A system that stores, processes, or transmits encrypted PAN.
,C. A system located in a completely different physical building from the CDE.
D. A system used only for marketing purposes with no network connection to the CDE.
Answer: A
Conceptual Explanation: Security impacting systems are those that provide security
services (like DNS, NTP, or IAM) or can impact the security of the CDE, even if they do not
handle account data directly.
3. How often must an entity perform a review of firewall and router rule sets according to
Requirement 1.2.7?
A. Every 90 days.
B. Annually.
C. At least once every six months.
D. Only after a significant change to the network.
Answer: C
Conceptual Explanation: PCI DSS Requirement 1.2.7 (v4.0.1) requires a review of
configuration settings for network security symbols and firewall/router rule sets at least
once every six months.
4. Under Requirement 3.4.2, when using disk-level encryption to protect PAN on a laptop,
what must also be true?
A. The encryption must be hardware-based only.
, B. Access must be controlled via a mechanism other than the operating system’s local
authentication.
C. The PAN must also be hashed within the database.
D. Disk encryption is not an acceptable method for protecting PAN on removable media.
Answer: B
Conceptual Explanation: For disk-level encryption, access must be managed
independently of the OS authentication (e.g., a pre-boot password) to ensure the data is
protected if the device is stolen.
5. Which of the following is true regarding the storage of Sensitive Authentication Data (SAD)
after authorization?
A. Merchants may store the CVV if it is encrypted with a strong key.
B. Issuers may store SAD if there is a documented business justification.
C. Service providers may store the PIN block if they are also the processor.
D. SAD can be stored if it is hashed using a non-reversible algorithm.
Answer: B
Conceptual Explanation: Only issuers (and those providing support to issuers) with a
legitimate business need may store SAD after authorization; for all other entities, storage is
prohibited.
ANSWERS 2026
1. According to PCI DSS v4.0.1, what is the mandatory requirement for an entity choosing to
use the Customized Approach for a specific requirement?
A. They must obtain prior approval from the PCI SSC.
B. They must perform a Targeted Risk Analysis (TRA) for each customized control.
C. They must prove that the Defined Approach is technically impossible to implement.
D. They must be a Level 1 Service Provider.
Answer: B
Conceptual Explanation: The Customized Approach requires a Targeted Risk Analysis
(TRA) to justify how the custom control meets the objective and provides the same level of
security as the Defined Approach.
2. Which of the following describes a ‘Security Impacting’ system in the context of scoping?
A. A system that provides security services to the CDE, such as an NTP server or Anti-Virus
server.
B. A system that stores, processes, or transmits encrypted PAN.
,C. A system located in a completely different physical building from the CDE.
D. A system used only for marketing purposes with no network connection to the CDE.
Answer: A
Conceptual Explanation: Security impacting systems are those that provide security
services (like DNS, NTP, or IAM) or can impact the security of the CDE, even if they do not
handle account data directly.
3. How often must an entity perform a review of firewall and router rule sets according to
Requirement 1.2.7?
A. Every 90 days.
B. Annually.
C. At least once every six months.
D. Only after a significant change to the network.
Answer: C
Conceptual Explanation: PCI DSS Requirement 1.2.7 (v4.0.1) requires a review of
configuration settings for network security symbols and firewall/router rule sets at least
once every six months.
4. Under Requirement 3.4.2, when using disk-level encryption to protect PAN on a laptop,
what must also be true?
A. The encryption must be hardware-based only.
, B. Access must be controlled via a mechanism other than the operating system’s local
authentication.
C. The PAN must also be hashed within the database.
D. Disk encryption is not an acceptable method for protecting PAN on removable media.
Answer: B
Conceptual Explanation: For disk-level encryption, access must be managed
independently of the OS authentication (e.g., a pre-boot password) to ensure the data is
protected if the device is stolen.
5. Which of the following is true regarding the storage of Sensitive Authentication Data (SAD)
after authorization?
A. Merchants may store the CVV if it is encrypted with a strong key.
B. Issuers may store SAD if there is a documented business justification.
C. Service providers may store the PIN block if they are also the processor.
D. SAD can be stored if it is hashed using a non-reversible algorithm.
Answer: B
Conceptual Explanation: Only issuers (and those providing support to issuers) with a
legitimate business need may store SAD after authorization; for all other entities, storage is
prohibited.