PCI ISA Solved Exam Questions and
Answers (Complete Practice Papers)
SAQ-A - Correct Answers ✅e-commerce or telephone order
merchants; processing fully outsourced to validated 3rd party.
No processing, transmitting, storing done by merchant
SAQ-B - Correct Answers ✅merchants with imprint
machines and/or merchant with only standalone dial-out
terminals
SAQ-B-IP - Correct Answers ✅Same as SAQ-B but the
terminals not dial-out, the terminals have an IP connection
SAQ-C - Correct Answers ✅Merchants with payment apps
connected to the Internet but have no CHD storage. Not
available if doing ecommerce
SAQ-C-VT - Correct Answers ✅Merchants who only use
virtual terminals from a validated 3rd party. Do transactions
one at a time. Not available if doing ecommerce
SAQ-A-EP - Correct Answers ✅Same as SAQ-A but web site
could affect the security of outsourced 3rd party solution.
SAQ-D - Correct Answers ✅Used by merchants not eligible
for any other SAQ. Service providers must always use SAQ-D
, PCI ISA Solved Exam Questions and
Answers (Complete Practice Papers)
Where are firewalls required - Correct Answers ✅Between
Internet and CHD, between DMZ and internal network,
between wireless networks and CHD
How often must firewall rules be reviewed - Correct
Answers ✅6 months and after significant environment
change
Non-Console admin access must be ______ - Correct
Answers ✅encrypted
CHD data can only be stored for how long? - Correct
Answers ✅based on merchant documented policy based on
biz, regulatory, legal requirements
CHD that has exceeded its defined retention period must be
deleted based on a ________ process - Correct Answers
✅quarterly
When is it OK to store sensitive authentication date (SAD)? -
Correct Answers ✅temporarily prior to authorization.
Issuers can store SAD based on business need
Sensitive Authentication Data - Correct Answers ✅Full
Track, Track 1, Track 2, CVV, PIN. Any equivalent from chip
Answers (Complete Practice Papers)
SAQ-A - Correct Answers ✅e-commerce or telephone order
merchants; processing fully outsourced to validated 3rd party.
No processing, transmitting, storing done by merchant
SAQ-B - Correct Answers ✅merchants with imprint
machines and/or merchant with only standalone dial-out
terminals
SAQ-B-IP - Correct Answers ✅Same as SAQ-B but the
terminals not dial-out, the terminals have an IP connection
SAQ-C - Correct Answers ✅Merchants with payment apps
connected to the Internet but have no CHD storage. Not
available if doing ecommerce
SAQ-C-VT - Correct Answers ✅Merchants who only use
virtual terminals from a validated 3rd party. Do transactions
one at a time. Not available if doing ecommerce
SAQ-A-EP - Correct Answers ✅Same as SAQ-A but web site
could affect the security of outsourced 3rd party solution.
SAQ-D - Correct Answers ✅Used by merchants not eligible
for any other SAQ. Service providers must always use SAQ-D
, PCI ISA Solved Exam Questions and
Answers (Complete Practice Papers)
Where are firewalls required - Correct Answers ✅Between
Internet and CHD, between DMZ and internal network,
between wireless networks and CHD
How often must firewall rules be reviewed - Correct
Answers ✅6 months and after significant environment
change
Non-Console admin access must be ______ - Correct
Answers ✅encrypted
CHD data can only be stored for how long? - Correct
Answers ✅based on merchant documented policy based on
biz, regulatory, legal requirements
CHD that has exceeded its defined retention period must be
deleted based on a ________ process - Correct Answers
✅quarterly
When is it OK to store sensitive authentication date (SAD)? -
Correct Answers ✅temporarily prior to authorization.
Issuers can store SAD based on business need
Sensitive Authentication Data - Correct Answers ✅Full
Track, Track 1, Track 2, CVV, PIN. Any equivalent from chip