PCI ISA EXAM 2026 QUESTIONS AND
ANSWERS
1. According to PCI DSS v4.0, which of the following is a requirement for the ‘Customized
Approach’?
A. It can be used by any entity that prefers it over the Defined Approach without
justification.
B. The QSA or ISA is responsible for designing the controls for the entity.
C. The entity must perform a targeted risk analysis for each requirement using the
customized approach.
D. It replaces the need for an Appendix C reporting template.
Answer: C
Conceptual Explanation: For each requirement met via the Customized Approach, the
entity must perform a targeted risk analysis to justify the approach and ensure the risk is
mitigated to the same level as the Defined Approach.
2. When is it permissible for a merchant to store Sensitive Authentication Data (SAD) after
authorization?
A. If the data is encrypted with AES-256.
,B. It is never permissible for a merchant to store SAD after authorization.
C. If the merchant is a Level 1 merchant with a valid business need.
D. If the merchant has been granted a specific waiver by the PCI SSC.
Answer: B
Conceptual Explanation: PCI DSS Requirement 3.2 explicitly prohibits the storage of SAD
after authorization, even if encrypted. Only issuers and some service providers may have a
legitimate business need to store it.
3. In PCI DSS v4.0, what is the minimum frequency for performing a Targeted Risk Analysis
(TRA) for any requirement that allows an entity to determine the frequency of a control?
A. Every six months.
B. Once every three years.
C. Only when a significant change occurs.
D. At least once every 12 months.
Answer: D
Conceptual Explanation: Requirement 12.3.1 specifies that for requirements where the
frequency is determined by the entity, a targeted risk analysis must be performed at least
once every 12 months.
, 4. Requirement 8.4.2 mandates Multi-Factor Authentication (MFA) for which of the
following?
A. Only for remote access from outside the corporate network.
B. All non-console administrative access to the CDE.
C. All user access to any system component.
D. All access to the CDE.
Answer: D
Conceptual Explanation: PCI DSS v4.0 expanded MFA requirements. Requirement 8.4.2
now requires MFA for all access into the Cardholder Data Environment (CDE).
5. Which of the following describes the ‘Time-of-Use’ requirement for administrative
passwords according to PCI DSS v4.0?
A. If passwords are the only factor for authentication, they must be changed at least once
every 90 days.
B. Application and system accounts must be limited to specific time windows.
C. Passwords must be unique for every login attempt.
D. Passwords must be changed every 90 days.
Answer: A
ANSWERS
1. According to PCI DSS v4.0, which of the following is a requirement for the ‘Customized
Approach’?
A. It can be used by any entity that prefers it over the Defined Approach without
justification.
B. The QSA or ISA is responsible for designing the controls for the entity.
C. The entity must perform a targeted risk analysis for each requirement using the
customized approach.
D. It replaces the need for an Appendix C reporting template.
Answer: C
Conceptual Explanation: For each requirement met via the Customized Approach, the
entity must perform a targeted risk analysis to justify the approach and ensure the risk is
mitigated to the same level as the Defined Approach.
2. When is it permissible for a merchant to store Sensitive Authentication Data (SAD) after
authorization?
A. If the data is encrypted with AES-256.
,B. It is never permissible for a merchant to store SAD after authorization.
C. If the merchant is a Level 1 merchant with a valid business need.
D. If the merchant has been granted a specific waiver by the PCI SSC.
Answer: B
Conceptual Explanation: PCI DSS Requirement 3.2 explicitly prohibits the storage of SAD
after authorization, even if encrypted. Only issuers and some service providers may have a
legitimate business need to store it.
3. In PCI DSS v4.0, what is the minimum frequency for performing a Targeted Risk Analysis
(TRA) for any requirement that allows an entity to determine the frequency of a control?
A. Every six months.
B. Once every three years.
C. Only when a significant change occurs.
D. At least once every 12 months.
Answer: D
Conceptual Explanation: Requirement 12.3.1 specifies that for requirements where the
frequency is determined by the entity, a targeted risk analysis must be performed at least
once every 12 months.
, 4. Requirement 8.4.2 mandates Multi-Factor Authentication (MFA) for which of the
following?
A. Only for remote access from outside the corporate network.
B. All non-console administrative access to the CDE.
C. All user access to any system component.
D. All access to the CDE.
Answer: D
Conceptual Explanation: PCI DSS v4.0 expanded MFA requirements. Requirement 8.4.2
now requires MFA for all access into the Cardholder Data Environment (CDE).
5. Which of the following describes the ‘Time-of-Use’ requirement for administrative
passwords according to PCI DSS v4.0?
A. If passwords are the only factor for authentication, they must be changed at least once
every 90 days.
B. Application and system accounts must be limited to specific time windows.
C. Passwords must be unique for every login attempt.
D. Passwords must be changed every 90 days.
Answer: A