Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 8 pages
Exam (elaborations)

PCI DSS Fundamentals Exam & QUESTIONS VERIFIED

Document preview thumbnail
Preview 2 out of 8 pages

PCI DSS Fundamentals Exam & QUESTIONS VERIFIED A Sustainable Compliance Program must: - ANSWER Be implemented into Business-as-usual (BAU) activities as part of the organizations overall security strategy. True or False: The driving objective behind all PCI DSS compliance activities is to attain a compliant report. - ANSWER False ongoing security of cardholder data is the driving objective which will lead to a compliant report Effective metrics program can provide useful data for: - ANSWER Allocation of resources to minimize risk occurrence and measure the business consequences of security events. Security Goals should include: - ANSWER Continuous monitoring, testing, documenting implementation, effectiveness, efficiency, impact, and status of controls and activities. Control-failure response processes should include: - ANSWER minimizing the impact of the incident, restoring controls, performing root-cause analysis and remediation, implementing hardening standards and enhancing monitoring. True or False: 3rd party providers are monitored by issuers - ANSWER False, Organizations should develop and implement processes to monitor the compliance status of its service providers to determine whether a change in status requires a change in the relationship. True or False: Organizations should evolve their controls with the threat landscape, changes in organizations structure, new business initiatives, and changes in business processes and technologies - ANSWER True Evolving security reduces the negative impact on an organizations security posture. How can organizations prevent "fall-off" between assessments - ANSWER Develop a well designed program of security controls and monitoring practices. True or False: Network segmentation is one method that can help reduce the number of system components in scope for PCI DSS - ANSWER True, outsourcing to a 3rd party service provider and using P2PE are other methods of reducing scope. Who is ultimately responsible for making its own PCI DSS scoping decisions, designing effective segmentation and ensuring its own PCI DSS compliance and related validation requirements are met - ANSWER Each entity is responsible for themselves. What does segmentation involve - ANSWER additional controls to separate systems with different security needs. Segmentation can consist of: - ANSWER logical controls, physical controls or a combination of both Name some commonly used segmentation methods - ANSWER Firewalls and router configurations (preventing traffic in & out), network configurations (preventing communication) and physical controls E-commerce Payment Gateway/Payment Processor - ANSWER may facilitate payment authorization by forwarding transactions to the processors/acquirers that perform the actual payment authorization. E-Commerce infrastructure may include: - ANSWER consumers browser, application servers, database servers and any other underlying servers or devices such as network devices. Merchants infrastructure may include: - ANSWER networking and operating system, firewalls, switches, routers and any virtual infrastructure such as hypervisors. E-commerce infrastructure typically follows what 3-tier computing model - ANSWER 1) Presentation layer (web) 2) processing layer (application) 3) data-storage layer Requirements for firewall configuration standards are: - ANSWER a firewall at each internet connection and between any demilitarized zone (DMZ) and the internal network zone. Examine firewall and router configurations to verify that a DMZ is implemented to limit - ANSWER inbound traffic to only a system components that provide authorized publicly accessible services, protocols, and ports Examine firewall an


Document information

Uploaded on
January 4, 2024
Number of pages
8
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers
$14.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
osorebrilliant
3.6
(77)
Sold
456
Followers
368
Items
4655
Last sold
6 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions

Whoops! We can’t load your doc right now. Try again or contact support.