PCI-DSS ISA Exam | 81 Correct Questions And Answers Latest
44. Appendix A2 applies to: entities using SSL/Early TLS 45. Appendix A3 applies to: Designated Entities Supplemental Validation (DESV) An entity is required to undergo an assessment according to this Appendix ONLY if instructed to do so by an acquirer or a payment brand. 46. Designated entities (DESV) must document and confirm the accuracy of PCI DSS scope at least and upon significant changes to the in-scope environment.: quarterly 47. Designated Entities (DESV) must ensure that pen tests are performed on "segmentation controls" every , and after significant changes.: 6 months 48. In regards to DESV, user accounts and access privileges are reviewed at least every .: 6 months 49. ASV scans must cover .: ALL Internet-Facing IP addresses in existence at the entity. 50. Compensating controls need to be evaluated at least .: annually 51. Compensating controls requirement 1:: Constrains 52. Compensating controls requirement 2:: Objective 53. Compensating controls requirement 3:: Risk 54. Compensating controls requirement 4:: Definition 55. Compensating controls requirement 5:: Validation 56. Compensating controls requirement 6:: Maintenance 57. QSAs are required to retain work papers for a minimum of , and it is also recommended that ISAs retain work papers for a minimum of .: 3 years; 3 years 58. The decision about a merchant's level is made by the:: merchant's acquirer 59. Service provider levels are defined by .- : the payment brands according to transaction volume and/or type of service provider. 60. Issuer: Bank or other organization issuing a payment card on behalf of a Payment Brand. 61. Merchant: Organization accepting the payment card for payment during a purchase 62. Acquirer: Bank or entity the merchant uses to process their payment card transactions Acquirer is also called: Merchant Bank ISO (sometimes) Payment Brand - Amex, Discover, JCB Never Visa or MasterCard 63. only one primary function: Verify system configurations that is implemented per server. 64. Do not store AFTER authorization even if .: sensitive authentication data; encrypted (sensitive auth data: track data, verification code, PIN) 65. Req 3.3: Protection of PAN that displayed on screens, paper receipts, etc. by : masking the PAN and only show first 6 digits and last 4 digits. 66. Req 3.4: Protection of PAN when stored in files, databases, etc. by . (hint: do what to the information?): render the information unreadable. 67. Disk Encryption: Must verify that logical access to encrypted file systems is implemented via a mechanism that is separate from the native operating system's authentication mechanism. 68. Key-encrypting keys are as data-encrypting keys and .: at least as strong; stored separately. 69. Key Management documentation must specifies the following:: Procedures to: 1. Generate strong keys 2. Securely distribute keys 3. Securely store keys 4. Defined cryptoperiod
Document information
- Uploaded on
- June 18, 2023
- Number of pages
- 8
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers