Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 40 páginas
Examen

PCI ISA Certification Practice Exam 2025 | 60 Questions with Answers & Explanations | PCI DSS v4.0 Study Guide

Document preview thumbnail
Vista previa 4 fuera de 40 páginas

Prepare for the PCI ISA (Internal Security Assessor) Certification Exam with this comprehensive practice test featuring 60 original questions based on PCI DSS v4.0 requirements. This study resource covers all key domains including Cardholder Data Environment (CDE) scope reduction, network segmentation, multi-factor authentication, vulnerability management, penetration testing, incident response, and third-party service provider management. Each question includes detailed examiner notes and rationales to reinforce understanding of PCI DSS requirements and assessment methodologies. Designed for security professionals seeking PCI ISA certification, internal security assessors, compliance officers, and organizations preparing for PCI compliance assessments. Perfect for self-assessment, exam preparation, and validating knowledge of PCI DSS v4.0 controls.

Vista previa del contenido

PCI ISA Certification Practice Exam 2025 | 60 Questions
with Answers & Explanations | PCI DSS v4.0 Study
Guide

Section 1: Multiple Choice (Questions 1-60)




Question: 1 of 60
According to PCI DSS v4.0, which of the following best defines the concept of "network
segmentation"?

• A) The practice of connecting all systems to a single network for easier
management
• B) The process of isolating the Cardholder Data Environment (CDE) from other
networks to reduce assessment scope
• C) The use of virtual private networks (VPNs) for remote access
• D) The requirement to have multiple firewalls in a cascading configuration

Answer: B) The process of isolating the Cardholder Data Environment (CDE) from
other networks to reduce assessment scope

Examiner Note: Network segmentation is a critical security control that separates the
CDE from other networks, reducing the scope of a PCI DSS assessment and limiting the
potential impact of a security breach.




Question: 2 of 60
Which of the following is considered Sensitive Authentication Data (SAD) and is
prohibited from being stored after authorization under PCI DSS v4.0?

• A) Primary Account Number (PAN)

, • B) Cardholder name
• C) Service code
• D) Expiration date

Answer: C) Service code

Examiner Note: The service code is part of the magnetic stripe data and is considered
Sensitive Authentication Data. PAN, cardholder name, and expiration date are
cardholder data but not SAD. SAD includes full magnetic stripe data,
CAV2/CVC2/CVV2/CID, and PINs/PIN blocks.




Question: 3 of 60
An organization has implemented a demilitarized zone (DMZ) architecture to separate
its web servers from its internal network. What is the primary PCI DSS benefit of this
configuration?

• A) It eliminates the need for vulnerability scanning
• B) It allows the organization to store SAD for longer periods
• C) It reduces the scope of the CDE by isolating systems that do not store
cardholder data
• D) It eliminates the need for multi-factor authentication

Answer: C) It reduces the scope of the CDE by isolating systems that do not store
cardholder data

Examiner Note: A DMZ helps reduce PCI DSS scope by isolating systems that handle
cardholder data from those that do not. Proper segmentation can significantly reduce
the number of systems that fall within the CDE.




Question: 4 of 60
Under PCI DSS v4.0 Requirement 8.4.2, multi-factor authentication (MFA) is required for:

• A) All users accessing the corporate network from the office

, • B) All non-console administrative access into the CDE
• C) Only third-party vendors accessing the CDE
• D) All users accessing public-facing web applications

Answer: B) All non-console administrative access into the CDE

Examiner Note: Requirement 8.4.2 mandates that multi-factor authentication be
implemented for all non-console administrative access into the CDE. This applies to both
internal and external access by administrators.




Question: 5 of 60
According to PCI DSS v4.0, what is the maximum time allowed to remediate a critical
vulnerability identified during an external vulnerability scan?

• A) 7 days
• B) 14 days
• C) 30 days
• D) 90 days

Answer: B) 14 days

Examiner Note: Critical vulnerabilities identified during external vulnerability scans
must be remediated within 14 days. High-risk vulnerabilities are typically prioritized, and
the entity's vulnerability management process should address remediation timelines.




Question: 6 of 60
A merchant processes payments through a fully outsourced e-commerce platform
where all payment pages are hosted by a PCI DSS validated third party. Which Self-
Assessment Questionnaire (SAQ) is most appropriate?

• A) SAQ A
• B) SAQ B
• C) SAQ C

, • D) SAQ D

Answer: A) SAQ A

Examiner Note: SAQ A is designed for e-commerce merchants who fully outsource
payment processing to a PCI DSS validated third party and have no electronic storage,
processing, or transmission of cardholder data on their own systems.




Question: 7 of 60
Requirement 3.5.1 addresses the use of cryptographic keys. What is the primary
requirement?

• A) Keys must be changed annually
• B) Keys must be stored in the same database as cardholder data
• C) Keys must be stored securely with documented key management processes
• D) Keys must be shared with all system administrators

Answer: C) Keys must be stored securely with documented key management
processes

Examiner Note: Cryptographic keys must be stored securely and managed according to
documented key management processes. This includes key generation, distribution,
rotation, and destruction procedures.




Question: 8 of 60
According to Requirement 10.4.1, how frequently must time synchronization
mechanisms be reviewed and synchronized?

• A) Annually
• B) Monthly
• C) At least daily
• D) At least weekly

Answer: C) At least daily

Información del documento

Subido en
24 de marzo de 2026
Número de páginas
40
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$20.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
PresleyKhalid
5.0
(2)
Vendido
4
Seguidores
2
Artículos
134
Última venta
3 meses hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes