PCI Final 2024 Study
Cardholder data - ANSPrimary Account Number (PAN)
Cardholder name
Expiration date
Service Code
Sensitive Authentication Data - ANSMagnetic stripe data or equivalent on a chip
CAV2/CVC2/CVV2/CID
PINs / PIN Blocks
Network Segmentation is - ANSRecommended to reduce scope and risk
Sampling - ANSSampling of Business Facilities / System components is allowed, however all
applicable PCI DSS requirements must be considered.
Compensating Controls - ANSa Compensating Controls Worksheet must be completed for each
compensating control. And documented in the ROC.
Merchant levels - ANSDefined by payment brands.
Levels 1 to 4
1 is the largets merchants or merchants who have been compromised. 6 Million
transactions/year +
Non-compliance consequences - ANSFines according to Level and elapsed time determined by
payment brands
Breach Consequences - ANSFine per cardholder data compromised / Loss of reputation /
customer trust / suspension of service by credit card account provider
Firewall and Router rule sets be reviewed at least every - ANS6 Months
It is required to install all critical new security patches within - ANS1 Month
Public facing web applications are to be reviewed - ANSat least annually
Users are required to change passwords at least every - ANS90 Days
Users accounts are to be locked out after more than ________ invalid logon attempts - ANS6
System/session idle time out features should be set to _______ or less - ANS15 Minutes
Visitor log for physical access should be retained for at least - ANS3 Months
, Video Cameras/access control mechanisms should be stored for at least - ANS3 Months
Back up media storage location should be reviewed at least - ANSAnnually
Periodic media inventories are to be performed at least - ANSAnnually
Audit logs should be retained for at least - ANS1 Year
Processes should be in place to immediately restore at least _______ audit logs for analysis -
ANS3 months
Internal and external vulnerability scans are to be performed - ANSQuarterly
Penetration testing should be performed at least - ANSAnnually
Tools are to be configured to perform critical file comparisons at least - ANSWeekly
Passwords length are required to be - ANS7 characters
Requirement 3 - ANSProtect stored cardholder data
Requirement 4 - ANSEncrypt transmission of cardholder data across open, public networks
Requirement 5 - ANSUse and regularly update anti-virus software or programs
Requirement 6 - ANSDevelop and maintain secure systems and applications
Requirement 7 - ANSRestrict access to cardholder data by business need to know
Requirement 8 - ANSAssign a unique ID to each person with computer access
Requirement 9 - ANSRestrict physical access to cardholder data
Requirement 10 - ANSTrack and monitor all access to network resources and cardholder data
Requirement 11 - ANSRegularly test security systems and processes
Requirement 12 - ANSMaintain a policy that addresses information security for all personne
Remove or Disable inactive accounts over - ANS90 Days
How many characters are on Track 1 - ANSUp to 79
How many characters are on Track 2 - ANSUp to 40
Cardholder data - ANSPrimary Account Number (PAN)
Cardholder name
Expiration date
Service Code
Sensitive Authentication Data - ANSMagnetic stripe data or equivalent on a chip
CAV2/CVC2/CVV2/CID
PINs / PIN Blocks
Network Segmentation is - ANSRecommended to reduce scope and risk
Sampling - ANSSampling of Business Facilities / System components is allowed, however all
applicable PCI DSS requirements must be considered.
Compensating Controls - ANSa Compensating Controls Worksheet must be completed for each
compensating control. And documented in the ROC.
Merchant levels - ANSDefined by payment brands.
Levels 1 to 4
1 is the largets merchants or merchants who have been compromised. 6 Million
transactions/year +
Non-compliance consequences - ANSFines according to Level and elapsed time determined by
payment brands
Breach Consequences - ANSFine per cardholder data compromised / Loss of reputation /
customer trust / suspension of service by credit card account provider
Firewall and Router rule sets be reviewed at least every - ANS6 Months
It is required to install all critical new security patches within - ANS1 Month
Public facing web applications are to be reviewed - ANSat least annually
Users are required to change passwords at least every - ANS90 Days
Users accounts are to be locked out after more than ________ invalid logon attempts - ANS6
System/session idle time out features should be set to _______ or less - ANS15 Minutes
Visitor log for physical access should be retained for at least - ANS3 Months
, Video Cameras/access control mechanisms should be stored for at least - ANS3 Months
Back up media storage location should be reviewed at least - ANSAnnually
Periodic media inventories are to be performed at least - ANSAnnually
Audit logs should be retained for at least - ANS1 Year
Processes should be in place to immediately restore at least _______ audit logs for analysis -
ANS3 months
Internal and external vulnerability scans are to be performed - ANSQuarterly
Penetration testing should be performed at least - ANSAnnually
Tools are to be configured to perform critical file comparisons at least - ANSWeekly
Passwords length are required to be - ANS7 characters
Requirement 3 - ANSProtect stored cardholder data
Requirement 4 - ANSEncrypt transmission of cardholder data across open, public networks
Requirement 5 - ANSUse and regularly update anti-virus software or programs
Requirement 6 - ANSDevelop and maintain secure systems and applications
Requirement 7 - ANSRestrict access to cardholder data by business need to know
Requirement 8 - ANSAssign a unique ID to each person with computer access
Requirement 9 - ANSRestrict physical access to cardholder data
Requirement 10 - ANSTrack and monitor all access to network resources and cardholder data
Requirement 11 - ANSRegularly test security systems and processes
Requirement 12 - ANSMaintain a policy that addresses information security for all personne
Remove or Disable inactive accounts over - ANS90 Days
How many characters are on Track 1 - ANSUp to 79
How many characters are on Track 2 - ANSUp to 40