PCI TEST 2 UPDATED ACTUAL QUESTIONS AND
CORRECT ANSWERS
Question:
1. Which of the below functions is associated with acquirers?
- Provide clearing services to a merchant
- Provide authorization services to the merchant
- All of the options
- Provide settlement services to the merchant
Answer:
All of the options
Question:
2. If virtualization technologies are used in cardholder data environment?
- Virtualization technologies are not to be used in the cardholder data environment
- The virtualization technologies are not in scope for PCI-DSS
- Entities using virtualization technologies should be complete SAQ C
- The virtualization technologies are included in scope for PCI DSS
Answer:
The virtualization technologies are included in scope for PCI DSS
Question:
3. Access to view audit trails should be granted _____.
- only to individuals with a job-related need
- So that no personnel can view the logs
- To all system operators
- To all personnel
Answer:
only to individuals with a job-related need
Question:
4. Audit logs must be immediately available for analysis for a period of ____ and must be retained for a
period of _____.
- 3 months and 1 year
- 6 months and 1 year
- 2 months and 2 years
- 2 months and 1 year
Answer:
3 months and 1 year
Question:
5. Which of the following is true regarding protection of PAN?
- PAN must be rendered unreadable during transmission over public , wireless networks
- There are no PCI-DSS requirements for rendering PAN unreadable
- PAN must be rendered unreadable during transmission over private, secure network
- PAN must be rendered unreadable when present in volatile memory during a transaction
, Answer:
PAN must be rendered unreadable during transmission over public , wireless networks
Question:
6. One of the principles to be used when granting user access to systems in the CDE is:
- Default allow all
- Equal privilege
- Least privilege
- Most privilege
Answer:
Least privilege
Question:
7. Storing track data "long term" or "persistently" is permitted when_______.
- It is hashed by the merchants storing it.
- It is reported to the PCI SSC annually in a ROC
- It is encrypted by the merchant storing it.
- It is being stored by the issuers
Answer:
It is being stored by the issuers
Question:
8. The decision about a merchant's level is made by the:
- Merchant's QSA
- Payment Brands
- Merchant
- Merchant's acquirer
Answer:
Merchant's acquirer
Question:
9. Which of the following is considered "sensitive authentication data"?
- Cardholder name
- Expiration date
- Card verification value
- PAN
Answer:
Card verification value
Question:
10. PCI-DSS Requirement 3.4 stats that PAN must be rendered unreadable when stored. Which of the
following must be used to meet the requirement?
- Encryption in the first six and the last four numbers of the PAN
- Hiding the column containing PAN data in the database
- Hashing the entire PAN using strong cryptography
- Masking the entire PAN using industry standards
CORRECT ANSWERS
Question:
1. Which of the below functions is associated with acquirers?
- Provide clearing services to a merchant
- Provide authorization services to the merchant
- All of the options
- Provide settlement services to the merchant
Answer:
All of the options
Question:
2. If virtualization technologies are used in cardholder data environment?
- Virtualization technologies are not to be used in the cardholder data environment
- The virtualization technologies are not in scope for PCI-DSS
- Entities using virtualization technologies should be complete SAQ C
- The virtualization technologies are included in scope for PCI DSS
Answer:
The virtualization technologies are included in scope for PCI DSS
Question:
3. Access to view audit trails should be granted _____.
- only to individuals with a job-related need
- So that no personnel can view the logs
- To all system operators
- To all personnel
Answer:
only to individuals with a job-related need
Question:
4. Audit logs must be immediately available for analysis for a period of ____ and must be retained for a
period of _____.
- 3 months and 1 year
- 6 months and 1 year
- 2 months and 2 years
- 2 months and 1 year
Answer:
3 months and 1 year
Question:
5. Which of the following is true regarding protection of PAN?
- PAN must be rendered unreadable during transmission over public , wireless networks
- There are no PCI-DSS requirements for rendering PAN unreadable
- PAN must be rendered unreadable during transmission over private, secure network
- PAN must be rendered unreadable when present in volatile memory during a transaction
, Answer:
PAN must be rendered unreadable during transmission over public , wireless networks
Question:
6. One of the principles to be used when granting user access to systems in the CDE is:
- Default allow all
- Equal privilege
- Least privilege
- Most privilege
Answer:
Least privilege
Question:
7. Storing track data "long term" or "persistently" is permitted when_______.
- It is hashed by the merchants storing it.
- It is reported to the PCI SSC annually in a ROC
- It is encrypted by the merchant storing it.
- It is being stored by the issuers
Answer:
It is being stored by the issuers
Question:
8. The decision about a merchant's level is made by the:
- Merchant's QSA
- Payment Brands
- Merchant
- Merchant's acquirer
Answer:
Merchant's acquirer
Question:
9. Which of the following is considered "sensitive authentication data"?
- Cardholder name
- Expiration date
- Card verification value
- PAN
Answer:
Card verification value
Question:
10. PCI-DSS Requirement 3.4 stats that PAN must be rendered unreadable when stored. Which of the
following must be used to meet the requirement?
- Encryption in the first six and the last four numbers of the PAN
- Hiding the column containing PAN data in the database
- Hashing the entire PAN using strong cryptography
- Masking the entire PAN using industry standards