PCIP Exam Questions
Requirement 1 - Answer- Install and maintain a firewall configuration to protect cardholder data Requirement 2 - Answer- Do not use vendor supplied defaults for system passwords and other security parameters Requirement 3 - Answer- Protect stored cardholder data by enacting a formal data retention policy and implement secure deletion methods Requirement 4 - Answer- Encrypt transmission of cardholder data across open, public networks Requirement 5 - Answer- Protect all systems against malware and regularly update anti-virus software or programs Requirement 6 - Answer- Develop and maintain secure systems and applications Requirement 7 - Answer- Restrict access to cardholder data by business need to know Requirement 8 - Answer- Identify and authenticate access to system components Requirement 9 - Answer- Restrict physical access to cardholder data Requirement 10 - Answer- Track and monitor all access to network resources and cardholder data Requirement 11 - Answer- Regularly test security systems and processes Requirement 12 - Answer- Maintain a policy that addresses information security for all personnel Appendix A1 - Answer- Shared hosting providers must protect the cardholder data environment Appendix A2 - Answer- Additional PCI DSS Requirements for Entities using SSL/early TLS Appendix A3 - Answer- Designated Entities Supplemental Validation (DESV) Compensating Controls - Answer- 1- Meet the intent and rigor of the original PCI requirement 2- Sufficiently offset the risk that the original PCI DSS requirement was designed to defend against 3- Be "above and beyond" other PCI DSS requirements (i.e., not simply in compliance with other requirements) 4- Be commensurate with additional risk imposed by not adhering to original requirement Compensating Controls - - Answer- To consider Compensating Controls, one of the following must exist that precludes implementing the stated control: 1- Legitimate Technical Constraint 2- Documented Business Constraint Compensating Controls : - Answer- Existing PCI DSS requirements CANNOT be considered as compensating controls if they are already required for the
Document information
- Uploaded on
- October 24, 2023
- Number of pages
- 9
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers