PCIP Exam Questions & Answers
Can existing PCI DSS requirements be considered as compensating controls if they are already required for the item under review? - ANSWER NO What are reasons to consider using compensating controls? - ANSWER Legitimate technical constraints or documented business constraints Do PCI DSS requirements apply if virtualization is used in the CDE? - ANSWER YES P2PE encrypts data at source and decrypts at destination - ANSWER True A compensating control must __________________________ - ANSWER meet the rigor and intent of the original requirement A merchant with web based virtual terminals and no electronic cardholder data storage must complete a _______ - ANSWER SAQ C-VT Merchant with payment application systems connected to the internet with no electronic cardholder data storage must complete a ____________ - ANSWER SAQ C Create an ___________ that is __________ to be implemented in the event of a breach - ANSWER incident response plan - tested annually Tool to assist merchants and service providers self-evaluate compliance with PCI DSS - ANSWER SAQ Card not present merchants with all cardholder data source functions outsourced must complete the ________ - ANSWER SAQ A Minimum password length required by PCI DSS - ANSWER 7 Retain audit trail history for _____________years with minimum _______ months immediately available - ANSWER 1 3 External penetration testing must be performed ___________ - ANSWER at least annually and after any significant upgrade or modification
Document information
- Uploaded on
- March 15, 2023
- Number of pages
- 1
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers