with Answers & Explanations | PCI DSS v4.0 Study
Guide
Section 1: Multiple Choice (Questions 1-60)
Question: 1 of 60
According to PCI DSS v4.0, which of the following best defines the concept of "network
segmentation"?
• A) The practice of connecting all systems to a single network for easier
management
• B) The process of isolating the Cardholder Data Environment (CDE) from other
networks to reduce assessment scope
• C) The use of virtual private networks (VPNs) for remote access
• D) The requirement to have multiple firewalls in a cascading configuration
Answer: B) The process of isolating the Cardholder Data Environment (CDE) from
other networks to reduce assessment scope
Examiner Note: Network segmentation is a critical security control that separates the
CDE from other networks, reducing the scope of a PCI DSS assessment and limiting the
potential impact of a security breach.
Question: 2 of 60
Which of the following is considered Sensitive Authentication Data (SAD) and is
prohibited from being stored after authorization under PCI DSS v4.0?
• A) Primary Account Number (PAN)
, • B) Cardholder name
• C) Service code
• D) Expiration date
Answer: C) Service code
Examiner Note: The service code is part of the magnetic stripe data and is considered
Sensitive Authentication Data. PAN, cardholder name, and expiration date are
cardholder data but not SAD. SAD includes full magnetic stripe data,
CAV2/CVC2/CVV2/CID, and PINs/PIN blocks.
Question: 3 of 60
An organization has implemented a demilitarized zone (DMZ) architecture to separate
its web servers from its internal network. What is the primary PCI DSS benefit of this
configuration?
• A) It eliminates the need for vulnerability scanning
• B) It allows the organization to store SAD for longer periods
• C) It reduces the scope of the CDE by isolating systems that do not store
cardholder data
• D) It eliminates the need for multi-factor authentication
Answer: C) It reduces the scope of the CDE by isolating systems that do not store
cardholder data
Examiner Note: A DMZ helps reduce PCI DSS scope by isolating systems that handle
cardholder data from those that do not. Proper segmentation can significantly reduce
the number of systems that fall within the CDE.
Question: 4 of 60
Under PCI DSS v4.0 Requirement 8.4.2, multi-factor authentication (MFA) is required for:
• A) All users accessing the corporate network from the office
, • B) All non-console administrative access into the CDE
• C) Only third-party vendors accessing the CDE
• D) All users accessing public-facing web applications
Answer: B) All non-console administrative access into the CDE
Examiner Note: Requirement 8.4.2 mandates that multi-factor authentication be
implemented for all non-console administrative access into the CDE. This applies to both
internal and external access by administrators.
Question: 5 of 60
According to PCI DSS v4.0, what is the maximum time allowed to remediate a critical
vulnerability identified during an external vulnerability scan?
• A) 7 days
• B) 14 days
• C) 30 days
• D) 90 days
Answer: B) 14 days
Examiner Note: Critical vulnerabilities identified during external vulnerability scans
must be remediated within 14 days. High-risk vulnerabilities are typically prioritized, and
the entity's vulnerability management process should address remediation timelines.
Question: 6 of 60
A merchant processes payments through a fully outsourced e-commerce platform
where all payment pages are hosted by a PCI DSS validated third party. Which Self-
Assessment Questionnaire (SAQ) is most appropriate?
• A) SAQ A
• B) SAQ B
• C) SAQ C
, • D) SAQ D
Answer: A) SAQ A
Examiner Note: SAQ A is designed for e-commerce merchants who fully outsource
payment processing to a PCI DSS validated third party and have no electronic storage,
processing, or transmission of cardholder data on their own systems.
Question: 7 of 60
Requirement 3.5.1 addresses the use of cryptographic keys. What is the primary
requirement?
• A) Keys must be changed annually
• B) Keys must be stored in the same database as cardholder data
• C) Keys must be stored securely with documented key management processes
• D) Keys must be shared with all system administrators
Answer: C) Keys must be stored securely with documented key management
processes
Examiner Note: Cryptographic keys must be stored securely and managed according to
documented key management processes. This includes key generation, distribution,
rotation, and destruction procedures.
Question: 8 of 60
According to Requirement 10.4.1, how frequently must time synchronization
mechanisms be reviewed and synchronized?
• A) Annually
• B) Monthly
• C) At least daily
• D) At least weekly
Answer: C) At least daily