QIR TEST UPDATED ACTUAL QUESTIONS AND CORRECT
ANSWERS
Question:
1. What is an example of sensitive authentication data?
Answer:
PIN Block
Question:
2. What is an example of cardholder data?
Answer:
Expiration Date
Question:
3. The __________________ is an independent industry standards body providing oversight of the
development and management of Payment Card Industry Data Security Standards on a global basis.
Answer:
PCI SSC
Question:
4. What does PCI DSS cover?
Answer:
Covers secure payment environments that store, process or transmit account data
Question:
5. What is PCI PA-DSS?
Answer:
covers secure payment applications to support PCI DSS compliance
Question:
6. True or False: PCI PTS PIN Security covers secure management, processing and transmission of
personal identification number (PIN) data during online and office payment transaction processing.
Answer:
True
Question:
7. True or False: PCI PTS - HSM covers device tamper detection, cryptographic processes, and other
mechanisms used to protect the PIN and other sensitive data, such as cryptographic keys.
Answer:
False PCI PTS - POI
Question:
8. Core responsibilities as a QIR include:
,Answer:
- Install payment application in a manner which supports the customer's PCI DSS compliance using
PA-DSS implementation Guide
- Document for the customer any potential risks to PCI DSS compliance
- Explain any changes made to the customer's system(s) and any potential risks to the customer
- Provide a Feedback Form to the customer
- Support PCI Forensic Investigator (PFI) investigations in the event of a breach
Question:
9. Who is responsible for a Merchant's PCI Compliance?
Answer:
Merchant
Question:
10. The PCI SSC Listing Number, Payment Application Vendor, Payment Application Name and
Application Version Number are found in what part of the Implementation Statement?
Answer:
Implementation Statement Summary
Question:
11. What is P2PE?
Answer:
covers encryption, decryption and key management requirements for point-to-point encryption.
Question:
12. What is the last step in the payment processing workflow?
Answer:
Settlement
Question:
13. What is the 2nd step in the payment processing workflow?
Answer:
Clearing
Question:
14. What tapes place in the Authorization portion of the payment processing workfolw?
Answer:
Merchant requests and receives authorization
Question:
15. Which of the following is not true of acquirers?
Answer:
Also called Visa and/or Mastercard
Question:
16. True or False: Compliance validation requirements vary by payment bread.
, Answer:
True
Question:
17. Who is responsible for validating the scope of a PCI DSS assessment?
Answer:
QSA
Question:
18. Which of the following is not a responsibility of the ASV?
Answer:
Maintaining an internal PA-QSA
Question:
19. True or False: The QIR program aims to assume quality and provide effective feedback among QIRs,
their customers and the PCI SSC.
Answer:
True
Question:
20. True or False: The Implementation Guide and Implementation Statement are to be used together on
each Qualified Installation.
Answer:
True
Question:
21. True or False: PAN should be rendered unreadable anywhere it's stored.
Answer:
True
Question:
22. What are the Implementation Statement sections
Answer:
- Statement Summary
- QIR Employee Observations
- Statement Details
Question:
23. True or False: PCI DSS requirements are applicable wherever primary account number (PAN) or
sensitive authentication data (SAD) is stored, processed or transmitted.
Answer:
True
Question:
24. True or False: Account Data includes cardholder data and/or sensitive authentication data.
Answer:
True
ANSWERS
Question:
1. What is an example of sensitive authentication data?
Answer:
PIN Block
Question:
2. What is an example of cardholder data?
Answer:
Expiration Date
Question:
3. The __________________ is an independent industry standards body providing oversight of the
development and management of Payment Card Industry Data Security Standards on a global basis.
Answer:
PCI SSC
Question:
4. What does PCI DSS cover?
Answer:
Covers secure payment environments that store, process or transmit account data
Question:
5. What is PCI PA-DSS?
Answer:
covers secure payment applications to support PCI DSS compliance
Question:
6. True or False: PCI PTS PIN Security covers secure management, processing and transmission of
personal identification number (PIN) data during online and office payment transaction processing.
Answer:
True
Question:
7. True or False: PCI PTS - HSM covers device tamper detection, cryptographic processes, and other
mechanisms used to protect the PIN and other sensitive data, such as cryptographic keys.
Answer:
False PCI PTS - POI
Question:
8. Core responsibilities as a QIR include:
,Answer:
- Install payment application in a manner which supports the customer's PCI DSS compliance using
PA-DSS implementation Guide
- Document for the customer any potential risks to PCI DSS compliance
- Explain any changes made to the customer's system(s) and any potential risks to the customer
- Provide a Feedback Form to the customer
- Support PCI Forensic Investigator (PFI) investigations in the event of a breach
Question:
9. Who is responsible for a Merchant's PCI Compliance?
Answer:
Merchant
Question:
10. The PCI SSC Listing Number, Payment Application Vendor, Payment Application Name and
Application Version Number are found in what part of the Implementation Statement?
Answer:
Implementation Statement Summary
Question:
11. What is P2PE?
Answer:
covers encryption, decryption and key management requirements for point-to-point encryption.
Question:
12. What is the last step in the payment processing workflow?
Answer:
Settlement
Question:
13. What is the 2nd step in the payment processing workflow?
Answer:
Clearing
Question:
14. What tapes place in the Authorization portion of the payment processing workfolw?
Answer:
Merchant requests and receives authorization
Question:
15. Which of the following is not true of acquirers?
Answer:
Also called Visa and/or Mastercard
Question:
16. True or False: Compliance validation requirements vary by payment bread.
, Answer:
True
Question:
17. Who is responsible for validating the scope of a PCI DSS assessment?
Answer:
QSA
Question:
18. Which of the following is not a responsibility of the ASV?
Answer:
Maintaining an internal PA-QSA
Question:
19. True or False: The QIR program aims to assume quality and provide effective feedback among QIRs,
their customers and the PCI SSC.
Answer:
True
Question:
20. True or False: The Implementation Guide and Implementation Statement are to be used together on
each Qualified Installation.
Answer:
True
Question:
21. True or False: PAN should be rendered unreadable anywhere it's stored.
Answer:
True
Question:
22. What are the Implementation Statement sections
Answer:
- Statement Summary
- QIR Employee Observations
- Statement Details
Question:
23. True or False: PCI DSS requirements are applicable wherever primary account number (PAN) or
sensitive authentication data (SAD) is stored, processed or transmitted.
Answer:
True
Question:
24. True or False: Account Data includes cardholder data and/or sensitive authentication data.
Answer:
True