• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 2 fuera de 12 páginas
Examen

PCIP EXAM ACTUAL EXAM 140 QUESTIONS AND

Document preview thumbnail
Vista previa 2 fuera de 12 páginas

PCIP EXAM ACTUAL EXAM 140 QUESTIONS AND CORRECT acquirer - CORRECT ANSWERS party is responsible for merchant compliance validation and merchant communications Which statement is correct regarding the internal vulnerability scans and/or rescans? - CORRECT ANSWERS They must be performed after an upgrade to a server that impacts the cardholder data environment When confirming PCI DSS requirements have been met, assessors must always use which of the following? - CORRECT ANSWERS independent judgment Typical locations where track data may be found include which of the following? - CORRECT ANSWERS databases and log files from point-of-sales terminals Which of the following statements about "flat networks" is true? - CORRECT ANSWERS All systems on flat network are in scope for the PCI DSS assessments If network segmentation is being used to reduce the scope of the PCI DSS assessment, what must the assessor verify? - CORRECT ANSWERS All controls used for segmentation are configured properly PCI DSS requirement 10.2 defines the types of events to be logged. - CORRECT ANSWERS Audit trails, user identification, type of event, date and time, success and failure indications, source IP address (origination of event), data and systems touched, time synchronization technology in use. The payment card brands are responsible for which of the following? - CORRECT ANSWERS Penalties or fee assignment for non-compliance Which of the following is related to the use of EMV chip technology? - CORRECT ANSWERS PCI DSS applies to environments using EMV chip technology In order for PCI DSS scope to be reduced, what must adequate network segmentation do? - CORRECT ANSWERS Isolate systems that store, process, or transmit cardholder data from those that do not The Mod 10 formula doubles the value of every other digit of the primary account number beginning with which digit? - CORRECT ANSWERS Second from the right What is the Mod 10 or Luhn formula? - CORRECT ANSWERS The algorithm used to validate PAN (primary account numbers) What is required regarding the entity sharing cardholder data with a service provider? - CORRECT ANSWERS The entity must have an established process of engaging service provider, including proper due diligence prior to engagement Who is responsible for setting compliance deadlines and fines? - CORRECT ANSWERS Payment brands In accordance with the requirement 12.3.8, usage policies must be defined to automatically disconnect remote-access sessions. When should the remote-access sessions be disconnected? - CORRECT ANSWERS After a specific period if inactivity the following statements is correct regarding a PA-DSS application? - CORRECT ANSWERS PA-DSS compliant payment applications are in scope for the merchant's PCI DSS assessment What does it mean if a suspected card number passes Mod 10? - CORRECT ANSWERS It is definitely a valid PAN Which of the following is correct related to the tracks of the data on the magnetic stripe of a payment card? - CORRECT ANSWERS Track 1 contains all the field of both Track 1 and Track 2 Which of the following is a responsibility of the PCI SSC? - CORRECT ANSWERS Define validation requirements of ASVs (Approved scanning vendors When should penetration testing be performed? - CORRECT ANSWERS At least annually, and after any significant changes to infrastructure or applications How often are risk assessments required? - CORRECT ANSWERS At least annually This statement about the transaction process is true - CORRECT ANSWERS The card holder receives the type of payment, the card, and the bills from the issuers Which of the following statements accurately describes the service providers? - CORRECT ANSWERS A service provider processes, stores, or transmits card holder's data on the behalf of another entity A service provider with no electric cardholder data storage may be eligible to complete the SAQ? - CORRECT ANSWERS SAQ B SAQ A - CORRECT ANSWERS If your organization only accepts card-not-present transactions (e-commerce or phone/mail order) If the processing of cardholder data is entirely outsourced to third-party service providers approved by PCI DS

Vista previa del contenido

PCIP EXAM 2023-2024 ACTUAL EXAM
140 QUESTIONS AND CORRECT
acquirer - CORRECT ANSWERS party is responsible for merchant compliance
validation and merchant communications

Which statement is correct regarding the internal vulnerability scans and/or rescans? -
CORRECT ANSWERS They must be performed after an upgrade to a server that
impacts the cardholder data environment

When confirming PCI DSS requirements have been met, assessors must always use
which of the following? - CORRECT ANSWERS independent judgment

Typical locations where track data may be found include which of the following? -
CORRECT ANSWERS databases and log files from point-of-sales terminals

Which of the following statements about "flat networks" is true? - CORRECT
ANSWERS All systems on flat network are in scope for the PCI DSS assessments

If network segmentation is being used to reduce the scope of the PCI DSS assessment,
what must the assessor verify? - CORRECT ANSWERS All controls used for
segmentation are configured properly

PCI DSS requirement 10.2 defines the types of events to be logged. - CORRECT
ANSWERS Audit trails, user identification, type of event, date and time, success and
failure indications, source IP address (origination of event), data and systems touched,
time synchronization technology in use.

The payment card brands are responsible for which of the following? - CORRECT
ANSWERS Penalties or fee assignment for non-compliance

Which of the following is related to the use of EMV chip technology? - CORRECT
ANSWERS PCI DSS applies to environments using EMV chip technology

In order for PCI DSS scope to be reduced, what must adequate network segmentation
do? - CORRECT ANSWERS Isolate systems that store, process, or transmit
cardholder data from those that do not

The Mod 10 formula doubles the value of every other digit of the primary account
number beginning with which digit? - CORRECT ANSWERS Second from the right

What is the Mod 10 or Luhn formula? - CORRECT ANSWERS The algorithm used to
validate PAN (primary account numbers)

, What is required regarding the entity sharing cardholder data with a service provider? -
CORRECT ANSWERS The entity must have an established process of engaging
service provider, including proper due diligence prior to engagement

Who is responsible for setting compliance deadlines and fines? - CORRECT
ANSWERS Payment brands

In accordance with the requirement 12.3.8, usage policies must be defined to
automatically disconnect remote-access sessions. When should the remote-access
sessions be disconnected? - CORRECT ANSWERS After a specific period if inactivity

the following statements is correct regarding a PA-DSS application? - CORRECT
ANSWERS PA-DSS compliant payment applications are in scope for the merchant's
PCI DSS assessment

What does it mean if a suspected card number passes Mod 10? - CORRECT
ANSWERS It is definitely a valid PAN

Which of the following is correct related to the tracks of the data on the magnetic stripe
of a payment card? - CORRECT ANSWERS Track 1 contains all the field of both Track
1 and Track 2

Which of the following is a responsibility of the PCI SSC? - CORRECT ANSWERS
Define validation requirements of ASVs (Approved scanning vendors

When should penetration testing be performed? - CORRECT ANSWERS At least
annually, and after any significant changes to infrastructure or applications

How often are risk assessments required? - CORRECT ANSWERS At least annually

This statement about the transaction process is true - CORRECT ANSWERS The card
holder receives the type of payment, the card, and the bills from the issuers

Which of the following statements accurately describes the service providers? -
CORRECT ANSWERS A service provider processes, stores, or transmits card holder's
data on the behalf of another entity

A service provider with no electric cardholder data storage may be eligible to complete
the SAQ? - CORRECT ANSWERS SAQ B

SAQ A - CORRECT ANSWERS If your organization only accepts card-not-present
transactions (e-commerce or phone/mail order)
If the processing of cardholder data is entirely outsourced to third-party service
providers approved by PCI DSS

Información del documento

Subido en
19 de enero de 2025
Número de páginas
12
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$15.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Vendido
0
Seguidores
0
Artículos
12
Última venta
-



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes