PCI Practice Test Questions & Answers | VERIFIED
PCI Practice Test Questions & Answers | VERIFIED Which of the below functions is associated with acquirers? - Provide clearing services to a merchant - Provide authorization services to the merchant - All of the options - Provide settlement services to the merchant - ANSWER All of the options If virtualization technologies are used in cardholder data environment? - Virtualization technologies are not to be used in the cardholder data environment - The virtualization technologies are not in scope for PCI-DSS - Entities using virtualization technologies should be complete SAQ C - The virtualization technologies are included in scope for PCI DSS - ANSWER The virtualization technologies are included in scope for PCI DSS Access to view audit trails should be granted _____. - only to individuals with a job-related need - So that no personnel can view the logs - To all system operators - To all personnel - ANSWER only to individuals with a job-related need Audit logs must be immediately available for analysis for a period of ____ and must be retained for a period of _____. - 3 months and 1 year - 6 months and 1 year - 2 months and 2 years - 2 months and 1 year - ANSWER 3 months and 1 year Which of the following is true regarding protection of PAN? - PAN must be rendered unreadable during transmission over public , wireless networks - There are no PCI-DSS requirements for rendering PAN unreadable - PAN must be rendered unreadable during transmission over private, secure network - PAN must be rendered unreadable when present in volatile memory during a transaction - ANSWER PAN must be rendered unreadable during transmission over public , wireless networks One of the principles to be used when granting user access to systems in the CDE is: - Default allow all - Equal privilege - Least privilege - Most privilege - ANSWER Least privilege Storing track data "long term" or "persistently" is permitted when_______. - It is hashed by the merchants storing it. - It is reported to the PCI SSC annually in a ROC - It is encrypted by the merchant storing it. - It is being stored by the issuers - ANSWER It is being stored by the issuers The decision about a merchant's level is made by the: - Merchant's QSA - Payment Brands - Merchant - Merchant's acquirer - ANSWER Merchant's acquirer Which of the following is considered "sensitive authentication data"? - Cardholder name - Expiration date - Card verification value - PAN - ANSWER Card verification value PCI-DSS Requirement 3.4 stats that PAN must be rendered unreadable when stored. Which of the following must be used to meet the requirement? - Encryption in the first six and the last four numbers of the PAN - Hiding the column containing PAN data in the database - Hashing the entire PAN using strong cryptography - Masking the entire PAN using industry standards - ANSWER Hashing the entire PAN using strong cryptography Which of the following are parts if payment brand role? (Select all that apply) - Develop and enforce compliance programs - Endorse QSA, PA-QSA and ASV company qualification criteria - Accept validation documentation from QSAs, PA-QSAs & ASV's - Offer training for QSAs, PA. QSAs and ASVs - ANSWER Develop and enforce compliance programs Endorse QSA, PA-QSA and ASV company qualification criteria Accept validation documentation from QSAs, PA-QSAs & ASV's In which step does the payment brand network provide complete reconciliation to the merchant's bank? - Approval - Clearing - Settlement - Authorization - ANSWER
Document information
- Uploaded on
- January 4, 2024
- Number of pages
- 11
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers