QIR Training Part 1 questions with
verified answers
Which is the following responsibility of a QIR? - ANS ✔✔Install payment applications in a
manner which supports the customers PCS DSS compliance.
What does the Councils Standards Include? - ANS ✔✔The Council's standards include the PCI
Data Security Standard, the Payment Application Data Security Standard, the Point-to-Point
Encryption Standard, the PIN Transaction Security Point of Interaction, Hardware Security
Module and PIN standards, the Card Production standards, and all of their supporting
documents.
What happens in the clearing process? - ANS ✔✔In the Clearing process, the acquirer and
issuer need to exchange purchase information to complete the transaction.
The process includes:
1. The acquirer sends purchase information to the payment brand network.
2. The payment brand network sends purchase information to the issuer, which prepares data
for the cardholder's statement.
3. The payment brand network provides complete reconciliation to the acquirer.
This process usually occurs within one day in North America and may vary in other countries.
When does PCI DSS apply? - ANS ✔✔wherever cardholder data is being stored, processed or
transmitted. It therefore applies to all entities involved in payment card processing, including
merchants, processors, acquirers, issuers, and service providers, as well as all other entities that
store, process, or transmit cardholder data or sensitive authentication data.
What are some of the acquirers responsibilities? - ANS ✔✔For working with merchants and
their service providers to ensure that they:
,Review and understand PCI DSS
Understand their compliance and validation requirements
Validate and report compliance to the acquirer
Maintain on-going compliance
Read and incorporate on-going communications
QSA Responsibility - ANS ✔✔In all cases, the QSA must first evaluate and document how the
compensating control meets the intent of the requirement.
ISA Responsibility - ANS ✔✔As compliance is an ongoing process, internal assessors should help
their stakeholders to understand PCI DSS requirements, meet compliance obligations and
increase their security awareness if needed.
PA QSA Roles - ANS ✔✔The PA-QSA's role is to perform assessments according to the PA-DSS
security assessment procedures and per their PA-QSA validation requirements, to render
opinions about an application's compliance status, to adequately document the results of their
review, and to submit all required documentation to PCI SSC. Both QSAs and PA-QSAs are
required to maintain an internal quality assurance program to ensure their work meets
expectations.
Acquirer Roles - ANS ✔✔it is the acquirer who is responsible for the compliance validation of
their merchants. This could involve determining the merchant's reporting method, accepting
compensating controls, as well as any necessary actions resulting from data breaches such as
passing on fines and supporting forensic investigations.
QIR Installation - ANS ✔✔Assessors are encouraged to review any QIR documentation for
information that may help with the PCI DSS assessment. However, it's important to remember
that, while the QIR documentation may provide useful information about what to look for, the
application or environment may have changed since the installation took place, and the
information documented by the QIR may no longer represent the current configuration. A
, Qualified Installation, therefore, does not remove the need for a proper PCI DSS assessment or
reduce the level of testing to be performed.
Service Provider - ANS ✔✔The definition for a service provider is a business entity directly
involved in the processing, storage, or transmission of transaction data or cardholder data on
behalf of another merchant or service provider.
Service providers also include companies that provide services which control or could impact
the security of cardholder data. Examples may include providers of managed firewalls, IDS and
other security services, as well as hosting providers and other entities. So to confirm, when an
entity is processing, storing or transmitting cardholder data on behalf of another entity, or they
have access to another entity's cardholder data, they are a service provider.
Entities using third party service provider? - ANS ✔✔Entities often use third-party service
providers to store, process, or transmit cardholder data on their behalf, or to manage system
components - such as routers, firewalls, databases, physical security, and/or servers - in their
CDE.
Entities should clearly identify the services and system components which are included in the
scope of their service provider's PCI DSS assessment, as well as the PCI DSS requirements
covered by the service provider and any requirements which need to be covered by the entity
itself.
There are two options for third-party service providers to validate compliance: They can
undergo a PCI DSS assessment on their own and provide evidence to their customers to
demonstrate their compliance; or, if they do not undergo their own PCI DSS assessment, they
can have their services reviewed during the course of each of their customers' PCI DSS
assessments.
If the third party undergoes their own PCI DSS assessment, they should provide sufficient
evidence to their customers to verify that the scope of the service provider's PCI DSS
assessment covered the services applicable to the customer and that the relevant PCI DSS
verified answers
Which is the following responsibility of a QIR? - ANS ✔✔Install payment applications in a
manner which supports the customers PCS DSS compliance.
What does the Councils Standards Include? - ANS ✔✔The Council's standards include the PCI
Data Security Standard, the Payment Application Data Security Standard, the Point-to-Point
Encryption Standard, the PIN Transaction Security Point of Interaction, Hardware Security
Module and PIN standards, the Card Production standards, and all of their supporting
documents.
What happens in the clearing process? - ANS ✔✔In the Clearing process, the acquirer and
issuer need to exchange purchase information to complete the transaction.
The process includes:
1. The acquirer sends purchase information to the payment brand network.
2. The payment brand network sends purchase information to the issuer, which prepares data
for the cardholder's statement.
3. The payment brand network provides complete reconciliation to the acquirer.
This process usually occurs within one day in North America and may vary in other countries.
When does PCI DSS apply? - ANS ✔✔wherever cardholder data is being stored, processed or
transmitted. It therefore applies to all entities involved in payment card processing, including
merchants, processors, acquirers, issuers, and service providers, as well as all other entities that
store, process, or transmit cardholder data or sensitive authentication data.
What are some of the acquirers responsibilities? - ANS ✔✔For working with merchants and
their service providers to ensure that they:
,Review and understand PCI DSS
Understand their compliance and validation requirements
Validate and report compliance to the acquirer
Maintain on-going compliance
Read and incorporate on-going communications
QSA Responsibility - ANS ✔✔In all cases, the QSA must first evaluate and document how the
compensating control meets the intent of the requirement.
ISA Responsibility - ANS ✔✔As compliance is an ongoing process, internal assessors should help
their stakeholders to understand PCI DSS requirements, meet compliance obligations and
increase their security awareness if needed.
PA QSA Roles - ANS ✔✔The PA-QSA's role is to perform assessments according to the PA-DSS
security assessment procedures and per their PA-QSA validation requirements, to render
opinions about an application's compliance status, to adequately document the results of their
review, and to submit all required documentation to PCI SSC. Both QSAs and PA-QSAs are
required to maintain an internal quality assurance program to ensure their work meets
expectations.
Acquirer Roles - ANS ✔✔it is the acquirer who is responsible for the compliance validation of
their merchants. This could involve determining the merchant's reporting method, accepting
compensating controls, as well as any necessary actions resulting from data breaches such as
passing on fines and supporting forensic investigations.
QIR Installation - ANS ✔✔Assessors are encouraged to review any QIR documentation for
information that may help with the PCI DSS assessment. However, it's important to remember
that, while the QIR documentation may provide useful information about what to look for, the
application or environment may have changed since the installation took place, and the
information documented by the QIR may no longer represent the current configuration. A
, Qualified Installation, therefore, does not remove the need for a proper PCI DSS assessment or
reduce the level of testing to be performed.
Service Provider - ANS ✔✔The definition for a service provider is a business entity directly
involved in the processing, storage, or transmission of transaction data or cardholder data on
behalf of another merchant or service provider.
Service providers also include companies that provide services which control or could impact
the security of cardholder data. Examples may include providers of managed firewalls, IDS and
other security services, as well as hosting providers and other entities. So to confirm, when an
entity is processing, storing or transmitting cardholder data on behalf of another entity, or they
have access to another entity's cardholder data, they are a service provider.
Entities using third party service provider? - ANS ✔✔Entities often use third-party service
providers to store, process, or transmit cardholder data on their behalf, or to manage system
components - such as routers, firewalls, databases, physical security, and/or servers - in their
CDE.
Entities should clearly identify the services and system components which are included in the
scope of their service provider's PCI DSS assessment, as well as the PCI DSS requirements
covered by the service provider and any requirements which need to be covered by the entity
itself.
There are two options for third-party service providers to validate compliance: They can
undergo a PCI DSS assessment on their own and provide evidence to their customers to
demonstrate their compliance; or, if they do not undergo their own PCI DSS assessment, they
can have their services reviewed during the course of each of their customers' PCI DSS
assessments.
If the third party undergoes their own PCI DSS assessment, they should provide sufficient
evidence to their customers to verify that the scope of the service provider's PCI DSS
assessment covered the services applicable to the customer and that the relevant PCI DSS