PCIP Exam Questions with Correct Answers (Grade A+)
Question 1: Can existing PCI DSS requirements be considered as compensating controls if they are
already required for the item under review?
Answer: NO
Question 2: What are reasons to consider using compensating controls?
Answer: Legitimate technical constraints or documented business constraints
Question 3: Do PCI DSS requirements apply if virtualization is used in the CDE?
Answer: YES
Question 4: P2PE encrypts data at source and decrypts at destination
Answer: True
Question 5: A compensating control must __________________________
Answer: meet the rigor and intent of the original requirement
Question 6: A merchant with web based virtual terminals and no electronic cardholder data storage
must complete a _______
Answer: SAQ C-VT
Question 7: Merchant with payment application systems connected to the internet with no electronic
cardholder data storage must complete a ____________
Answer: SAQ C
Question 8: Create an ___________ that is __________ to be implemented in the event of a breach
Answer: incident response plan - tested annually
Question 9: Tool to assist merchants and service providers self-evaluate compliance with PCI DSS
Answer: SAQ
Question 10: Card not present merchants with all cardholder data source functions outsourced must
complete the ________
Answer: SAQ A
Page 1
Question 1: Can existing PCI DSS requirements be considered as compensating controls if they are
already required for the item under review?
Answer: NO
Question 2: What are reasons to consider using compensating controls?
Answer: Legitimate technical constraints or documented business constraints
Question 3: Do PCI DSS requirements apply if virtualization is used in the CDE?
Answer: YES
Question 4: P2PE encrypts data at source and decrypts at destination
Answer: True
Question 5: A compensating control must __________________________
Answer: meet the rigor and intent of the original requirement
Question 6: A merchant with web based virtual terminals and no electronic cardholder data storage
must complete a _______
Answer: SAQ C-VT
Question 7: Merchant with payment application systems connected to the internet with no electronic
cardholder data storage must complete a ____________
Answer: SAQ C
Question 8: Create an ___________ that is __________ to be implemented in the event of a breach
Answer: incident response plan - tested annually
Question 9: Tool to assist merchants and service providers self-evaluate compliance with PCI DSS
Answer: SAQ
Question 10: Card not present merchants with all cardholder data source functions outsourced must
complete the ________
Answer: SAQ A
Page 1