PCI ISA Solved Papers - Questions with
Complete Solutions
Non-console administrator access to any web-based
management interfaces must be encrypted with technology
such as......... - Correct Answers ✅HTTPS
Requirements 2.2.2 and 2.2.3 cover the use of secure
services, protocols and daemons. Which of the following is
considered to be secure? - Correct Answers ✅SSH
Which of the following is considered "Sensitive Authentication
Data"? - Correct Answers ✅Card Verification Value
(CAV2/CVC2/CVV2/CID), Full Track Data, PIN/PIN Block
True or False: It is acceptable for merchants to store Sensitive
Authentication after authorization as long as it is strongly
encrypted? - Correct Answers ✅False
When a PAN is displayed to an employee who does NOT need
to see the full PAN, the minimum digits to be masked are: -
Correct Answers ✅All digits between the first six and last
four
Which of the following is true regarding protection of PAN? -
Correct Answers ✅PAN must be rendered unreadable
during transmission over public, wireless networks
,PCI ISA Solved Papers - Questions with
Complete Solutions
Which of the following may be used to render PAN unreadable
in order to meet requirement 3.4? - Correct Answers
✅Hashing the entire PAN using strong cryptography
True or False Where keys are stored on production systems,
split knowledge and dual control is required? - Correct
Answers ✅True
When assessing requirement 6.5, testing to verify secure
coding techniques are in place to address common coding
vulnerabilities includes: - Correct Answers ✅Reviewing
software development policies and procedures
One of the principles to be used when granting user access to
systems in CDE is: - Correct Answers ✅Least privilege
An example of a "one-way" cryptographic function used to
render data unreadable is: - Correct Answers ✅SHA-2
A set of cryptographic hash functions designed by the
National Security Agency (NS). - Correct Answers ✅SHA-2
(Secure Hash Algorithm
True or False: Procedures must be developed to easily
distinguish the difference between onsite personnel and
visitors. - Correct Answers ✅True
, PCI ISA Solved Papers - Questions with
Complete Solutions
When should access be revoked of recently terminated
employees? - Correct Answers ✅immediately
True or False: A visitor with a badge may enter sensitive area
unescorted. - Correct Answers ✅False, visitors must be
escorted at all times.
Protection of keys used for encryption of cardholder data
against disclosure must include at least: (4 items) - Correct
Answers ✅*Access to keys is restricted to the fewest
number of custodians necessary
*Key-encrypting keys are at least as strong as the data-
encrypting keys they protect
*Key encrypting keys are stored separately from data-
encrypting keys
*Keys are stored securely in the fewest possible locations
Description of cryptographic architecture includes: - Correct
Answers ✅*Details of all algorithms, protocols, and keys
used for the protection of cardholder data, including key
strength and expiry date
*Description of the key usage for each key
*Inventory of any HSMs and other SCDs used for key
management
Complete Solutions
Non-console administrator access to any web-based
management interfaces must be encrypted with technology
such as......... - Correct Answers ✅HTTPS
Requirements 2.2.2 and 2.2.3 cover the use of secure
services, protocols and daemons. Which of the following is
considered to be secure? - Correct Answers ✅SSH
Which of the following is considered "Sensitive Authentication
Data"? - Correct Answers ✅Card Verification Value
(CAV2/CVC2/CVV2/CID), Full Track Data, PIN/PIN Block
True or False: It is acceptable for merchants to store Sensitive
Authentication after authorization as long as it is strongly
encrypted? - Correct Answers ✅False
When a PAN is displayed to an employee who does NOT need
to see the full PAN, the minimum digits to be masked are: -
Correct Answers ✅All digits between the first six and last
four
Which of the following is true regarding protection of PAN? -
Correct Answers ✅PAN must be rendered unreadable
during transmission over public, wireless networks
,PCI ISA Solved Papers - Questions with
Complete Solutions
Which of the following may be used to render PAN unreadable
in order to meet requirement 3.4? - Correct Answers
✅Hashing the entire PAN using strong cryptography
True or False Where keys are stored on production systems,
split knowledge and dual control is required? - Correct
Answers ✅True
When assessing requirement 6.5, testing to verify secure
coding techniques are in place to address common coding
vulnerabilities includes: - Correct Answers ✅Reviewing
software development policies and procedures
One of the principles to be used when granting user access to
systems in CDE is: - Correct Answers ✅Least privilege
An example of a "one-way" cryptographic function used to
render data unreadable is: - Correct Answers ✅SHA-2
A set of cryptographic hash functions designed by the
National Security Agency (NS). - Correct Answers ✅SHA-2
(Secure Hash Algorithm
True or False: Procedures must be developed to easily
distinguish the difference between onsite personnel and
visitors. - Correct Answers ✅True
, PCI ISA Solved Papers - Questions with
Complete Solutions
When should access be revoked of recently terminated
employees? - Correct Answers ✅immediately
True or False: A visitor with a badge may enter sensitive area
unescorted. - Correct Answers ✅False, visitors must be
escorted at all times.
Protection of keys used for encryption of cardholder data
against disclosure must include at least: (4 items) - Correct
Answers ✅*Access to keys is restricted to the fewest
number of custodians necessary
*Key-encrypting keys are at least as strong as the data-
encrypting keys they protect
*Key encrypting keys are stored separately from data-
encrypting keys
*Keys are stored securely in the fewest possible locations
Description of cryptographic architecture includes: - Correct
Answers ✅*Details of all algorithms, protocols, and keys
used for the protection of cardholder data, including key
strength and expiry date
*Description of the key usage for each key
*Inventory of any HSMs and other SCDs used for key
management