QIR PRACTICE TEST | QUESTIONS AND
ANSWERS | SOLVED 100% CORRECT
What is an example of sensitive authentication data? Answer - PIN Block
What is an example of cardholder data? Answer - Expiration Date
The __________________ is an independent industry standards body providing
oversight of the development and management of Payment Card Industry Data
Security Standards on a global basis. Answer - PCI SSC
What does PCI DSS cover? Answer - Covers secure payment environments that
store, process or transmit account data
What is PCI PA-DSS? Answer - covers secure payment applications to support PCI
DSS compliance
True or False: PCI PTS PIN Security covers secure management, processing and
transmission of personal identification number (PIN) data during online and office
payment transaction processing. Answer - True
True or False: PCI PTS - HSM covers device tamper detection, cryptographic
processes, and other mechanisms used to protect the PIN and other sensitive data,
such as cryptographic keys. Answer - False
PCI PTS - POI
Core responsibilities as a QIR include: Answer - - Install payment application in a
manner which supports the customer's PCI DSS compliance using PA-DSS
implementation Guide
- Document for the customer any potential risks to PCI DSS compliance
- Explain any changes made to the customer's system(s) and any potential risks to
the customer
- Provide a Feedback Form to the customer
- Support PCI Forensic Investigator (PFI) investigations in the event of a breach
Who is responsible for a Merchant's PCI Compliance? Answer - Merchant
,The PCI SSC Listing Number, Payment Application Vendor, Payment Application
Name and Application Version Number are found in what part of the Implementation
Statement? Answer - Implementation Statement Summary
What is P2PE? Answer - covers encryption, decryption and key management
requirements for point-to-point encryption.
What is the last step in the payment processing workflow? Answer - Settlement
What is the 2nd step in the payment processing workflow? Answer - Clearing
What tapes place in the Authorization portion of the payment processing workfolw?
Answer - Merchant requests and receives authorization
Which of the following is not true of acquirers? Answer - Also called Visa and/or
Mastercard
True or False: Compliance validation requirements vary by payment bread. Answer
- True
Who is responsible for validating the scope of a PCI DSS assessment? Answer -
QSA
Which of the following is not a responsibility of the ASV? Answer - Maintaining an
internal PA-QSA
True or False: The QIR program aims to assume quality and provide effective
feedback among QIRs, their customers and the PCI SSC. Answer - True
True or False: The Implementation Guide and Implementation Statement are to be
used together on each Qualified Installation. Answer - True
True or False: PAN should be rendered unreadable anywhere it's stored. Answer -
True
What are the Implementation Statement sections Answer - - Statement Summary
- QIR Employee Observations
- Statement Details
True or False: PCI DSS requirements are applicable wherever primary account
number (PAN) or sensitive authentication data (SAD) is stored, processed or
transmitted. Answer - True
True or False: Account Data includes cardholder data and/or sensitive authentication
data. Answer - True
True or False: PCI DSS Requirements do not apply to systems that provide security
services or could impact the security of account data. Answer - False
,True or False: Account data includes all of the information printed on the physical
card as well as the data on the magnetic stripe or chip Answer - True
What does ISA stand for? Answer - Internal Security Assessor
True or False: Sensitive authentication data is not stored post-authorization. Answer
- True
Records details about the customer, the QIR company and the QIR Employees and
the payment application. Answer - Implementation Statement Summary
Includes required signatures for the customer acceptance and the QIR Employee
affirmation of the Qualified Installation. Answer - Implementation Statement
Summary
Records details about the activities performed by the QIR Employee during the
Qualified Installation. Answer - Implementation Statement Details
Records observations or details that the customer should be aware of. Answer - QIR
Employee Additional Observations.
Includes items identified in the Details section that require explanation. Answer -
QIR Employee Additional Obeservations.
True or False: Sensitive authentication data can be stored after authorization, if
encrypted. Answer - False
How often does each validated payment application undergo attestation, until Expiry
Date is reached? Answer - Annually.
What is the standard for vetting off-the-shelf payment applications used in
authorization and settlement? Answer - PA-DSS
True or False: Many PA-DSS requirements are derived from PCI DSS Requirements
and Security Assessment (PCI DSS). Answer - True
True or False: PA-DSS Requirements apply to application vendors, to develop and
maintain secure payment applications. Answer - True
Changes to the PCI DSS and PA DSS, follow a _______ lifecycle, to ensure a
gradual, phased introduction of new version of the standard, in order to prevent
organizations from becoming non-compliant when changes are published. Answer -
3 year
The Payment Card Industry Data Security Standard (PCI DSS) is managed by the
_______________? Answer - PCI Security Standard Council
Select the PCI SSC stakeholders, who give input for proposed changes to the PCI
DSS: Answer - - Participating Organizations
- Merchants
, - Banks
- Point-of-sale Vendors
- Assessment community (QSA & ASV)
- Software & Hardware developers
- Processors
- PCI SSC Board of Advisors
________: Standards Published, occurs in October of year 1, after the Council's
annual Community Meetings and imitates a new lifecycle for the PCI DSS and the
PA-DSS. Stakeholders may immediately implement the new standards, but are not
required to do so, until they become effective. Answer - Stage 1
What date and year, in the PCI DSS and PA-DSS lifecycle, do the new PCI DSS
standards become effective? Answer - January 1 of Year 1
In what stage of the PCI DSS and PA-DSS lifecycle, is feedback given from the
stakeholders on the new standards? Answer - Stage 4
_______: Market Implementation occurs through Year 1, and entails assessing
changes to the new standard and determining their applicability to a stakeholder's
cardholder data environment. It is a period that provides for an orderly, phased
implementation of any required changes. Answer - Stage 3
On December 31st, every ___________ in the PCI DSS lifecycle, the old PCI DSS
and PA-DSS standards are retired. After this date, all validation efforts for
compliance must follow the new standards. Answer - 2 years
At this stage in the PCI DSS and PA-DSS lifecycle, feedback collected from
Participating Organizations is evaluated and clarification request about language in
standards that may be perceived as confusing, are addressed. Answer - Stage 6
True or False: Stage 2 occurs in October of Year 1, after the Council's annual
community meetings are initiates a new lifecycle for PCI DSS and the PA-DSS.
Answer - False
What is an example of two factor authentication? Answer - Token and password
When reviewing the Implementation Statement Summary with the client, the lead
QIR makes sure they understand the system passwords should be changed every
_________. Answer - 90 days
If the QIR Company suspects one of their customer's has been breached. who
should they notify? Answer - PCI SSC
Organizations qualified by the PCI SSC to implement, configure and/or support PA-
DSS validated Payment Applications on behalf of merchants and service providers
are referred to as ______ compaines. Answer - QIR
Re-qualification is required every _______ on or before the QIR Employee's
qualification expiration date. Answer - 2 years
ANSWERS | SOLVED 100% CORRECT
What is an example of sensitive authentication data? Answer - PIN Block
What is an example of cardholder data? Answer - Expiration Date
The __________________ is an independent industry standards body providing
oversight of the development and management of Payment Card Industry Data
Security Standards on a global basis. Answer - PCI SSC
What does PCI DSS cover? Answer - Covers secure payment environments that
store, process or transmit account data
What is PCI PA-DSS? Answer - covers secure payment applications to support PCI
DSS compliance
True or False: PCI PTS PIN Security covers secure management, processing and
transmission of personal identification number (PIN) data during online and office
payment transaction processing. Answer - True
True or False: PCI PTS - HSM covers device tamper detection, cryptographic
processes, and other mechanisms used to protect the PIN and other sensitive data,
such as cryptographic keys. Answer - False
PCI PTS - POI
Core responsibilities as a QIR include: Answer - - Install payment application in a
manner which supports the customer's PCI DSS compliance using PA-DSS
implementation Guide
- Document for the customer any potential risks to PCI DSS compliance
- Explain any changes made to the customer's system(s) and any potential risks to
the customer
- Provide a Feedback Form to the customer
- Support PCI Forensic Investigator (PFI) investigations in the event of a breach
Who is responsible for a Merchant's PCI Compliance? Answer - Merchant
,The PCI SSC Listing Number, Payment Application Vendor, Payment Application
Name and Application Version Number are found in what part of the Implementation
Statement? Answer - Implementation Statement Summary
What is P2PE? Answer - covers encryption, decryption and key management
requirements for point-to-point encryption.
What is the last step in the payment processing workflow? Answer - Settlement
What is the 2nd step in the payment processing workflow? Answer - Clearing
What tapes place in the Authorization portion of the payment processing workfolw?
Answer - Merchant requests and receives authorization
Which of the following is not true of acquirers? Answer - Also called Visa and/or
Mastercard
True or False: Compliance validation requirements vary by payment bread. Answer
- True
Who is responsible for validating the scope of a PCI DSS assessment? Answer -
QSA
Which of the following is not a responsibility of the ASV? Answer - Maintaining an
internal PA-QSA
True or False: The QIR program aims to assume quality and provide effective
feedback among QIRs, their customers and the PCI SSC. Answer - True
True or False: The Implementation Guide and Implementation Statement are to be
used together on each Qualified Installation. Answer - True
True or False: PAN should be rendered unreadable anywhere it's stored. Answer -
True
What are the Implementation Statement sections Answer - - Statement Summary
- QIR Employee Observations
- Statement Details
True or False: PCI DSS requirements are applicable wherever primary account
number (PAN) or sensitive authentication data (SAD) is stored, processed or
transmitted. Answer - True
True or False: Account Data includes cardholder data and/or sensitive authentication
data. Answer - True
True or False: PCI DSS Requirements do not apply to systems that provide security
services or could impact the security of account data. Answer - False
,True or False: Account data includes all of the information printed on the physical
card as well as the data on the magnetic stripe or chip Answer - True
What does ISA stand for? Answer - Internal Security Assessor
True or False: Sensitive authentication data is not stored post-authorization. Answer
- True
Records details about the customer, the QIR company and the QIR Employees and
the payment application. Answer - Implementation Statement Summary
Includes required signatures for the customer acceptance and the QIR Employee
affirmation of the Qualified Installation. Answer - Implementation Statement
Summary
Records details about the activities performed by the QIR Employee during the
Qualified Installation. Answer - Implementation Statement Details
Records observations or details that the customer should be aware of. Answer - QIR
Employee Additional Observations.
Includes items identified in the Details section that require explanation. Answer -
QIR Employee Additional Obeservations.
True or False: Sensitive authentication data can be stored after authorization, if
encrypted. Answer - False
How often does each validated payment application undergo attestation, until Expiry
Date is reached? Answer - Annually.
What is the standard for vetting off-the-shelf payment applications used in
authorization and settlement? Answer - PA-DSS
True or False: Many PA-DSS requirements are derived from PCI DSS Requirements
and Security Assessment (PCI DSS). Answer - True
True or False: PA-DSS Requirements apply to application vendors, to develop and
maintain secure payment applications. Answer - True
Changes to the PCI DSS and PA DSS, follow a _______ lifecycle, to ensure a
gradual, phased introduction of new version of the standard, in order to prevent
organizations from becoming non-compliant when changes are published. Answer -
3 year
The Payment Card Industry Data Security Standard (PCI DSS) is managed by the
_______________? Answer - PCI Security Standard Council
Select the PCI SSC stakeholders, who give input for proposed changes to the PCI
DSS: Answer - - Participating Organizations
- Merchants
, - Banks
- Point-of-sale Vendors
- Assessment community (QSA & ASV)
- Software & Hardware developers
- Processors
- PCI SSC Board of Advisors
________: Standards Published, occurs in October of year 1, after the Council's
annual Community Meetings and imitates a new lifecycle for the PCI DSS and the
PA-DSS. Stakeholders may immediately implement the new standards, but are not
required to do so, until they become effective. Answer - Stage 1
What date and year, in the PCI DSS and PA-DSS lifecycle, do the new PCI DSS
standards become effective? Answer - January 1 of Year 1
In what stage of the PCI DSS and PA-DSS lifecycle, is feedback given from the
stakeholders on the new standards? Answer - Stage 4
_______: Market Implementation occurs through Year 1, and entails assessing
changes to the new standard and determining their applicability to a stakeholder's
cardholder data environment. It is a period that provides for an orderly, phased
implementation of any required changes. Answer - Stage 3
On December 31st, every ___________ in the PCI DSS lifecycle, the old PCI DSS
and PA-DSS standards are retired. After this date, all validation efforts for
compliance must follow the new standards. Answer - 2 years
At this stage in the PCI DSS and PA-DSS lifecycle, feedback collected from
Participating Organizations is evaluated and clarification request about language in
standards that may be perceived as confusing, are addressed. Answer - Stage 6
True or False: Stage 2 occurs in October of Year 1, after the Council's annual
community meetings are initiates a new lifecycle for PCI DSS and the PA-DSS.
Answer - False
What is an example of two factor authentication? Answer - Token and password
When reviewing the Implementation Statement Summary with the client, the lead
QIR makes sure they understand the system passwords should be changed every
_________. Answer - 90 days
If the QIR Company suspects one of their customer's has been breached. who
should they notify? Answer - PCI SSC
Organizations qualified by the PCI SSC to implement, configure and/or support PA-
DSS validated Payment Applications on behalf of merchants and service providers
are referred to as ______ compaines. Answer - QIR
Re-qualification is required every _______ on or before the QIR Employee's
qualification expiration date. Answer - 2 years