Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Document preview thumbnail
Aperçu 2 sur 9 pages
Examen

PCI - ISA Exam with all Correct & 100% Verified Answers |Latest Version |Already Graded A+ (Just Released)

Document preview thumbnail
Aperçu 2 sur 9 pages

PCI - ISA Exam with all Correct & 100% Verified Answers |Latest Version |Already Graded A+ (Just Released)

Aperçu du contenu

PCI - ISA Exam with all Correct & 100% Verified Answers
|Latest Version |Already Graded A+ (Just Released)

What makes up SAD? ✔Correct Answer-- Track Data
- CAV2/CVC2/CVV2/CID)
- PINs & PIN Blocks

Track 1 ✔Correct Answer-Contains all fields of both Track 1 and Track 2, up to 79 characters long

11.2 Internal Scans - Frequency and performed by who? ✔Correct Answer-Quarterly and after
significant changes in the network - Performed by qualified, internal or external, resource

11.3 Penetration Tests (SERVICE PROVIDERS) - Frequency and performed by who? ✔Correct
Answer-Every 6 months by a qualified, internal or external, resource

11.2 External Scans - Frequency and performed by who? ✔Correct Answer-Quarterly and after
significant changes in the network - Performed by PCI SSC Approved Scanning Vendor (ASV)

11.3 Penetration Tests - Frequency and performed by who? ✔Correct Answer-At least annually and
after significant changes in the network - Performed by qualified, internal or external, resource

11.2 Review scan reports and verify scan process includes rescans until: ✔Correct Answer--
External scans: no vulnerabilities exists that scored 4.0 or higher by the CVSS
- Internal scans: all high-risk vulnerabilities as defined in PCI DSS requirement 6.1 are resolved

Who decides if a ROC or SAQ is required? ✔Correct Answer-Payment Brands / Acquirers

10.2 Implement audit trails for all system components to reconstruct the following events:
✔Correct Answer-- All individual accesses to CHD
- Actions taken by any individual with root or admin privileges
- Access to all audit trails
- Invalid logical access attempts
- Use of, and changes to, identification and authentication mechanisms
- Initialization, stopping, or pausing of the audit logs
- Creation and deleting of system-level objects

How long must QSA's retain work papers? ✔Correct Answer-3 years, recommend the same for ISAs

Firewall and router rule sets must be reviewed every _____________________. ✔Correct Answer-
6 months

Things to consider when assessing: ✔Correct Answer-People, processes, technology

How often should an entity undergo a process to securely delete stored CHD that exceeds defined
retention requirements? ✔Correct Answer-At least quarterly

3.6 Key-management operations Dual Control vs Split Knowledge ✔Correct Answer-Dual Control:
At least two people are required to perform any key-management operations and no one person has
access to the authentication materials (e.g., passwords, keys) of another

, Split Knowledge: Key components are under the control of at least two people who only have
knowledge of their own key components

3.4 Pan is rendered unreadable in which ways? ✔Correct Answer-Hash, truncation, encrypt, index
token and pads

6.2 Critical Security patches should be installed __________________________________.
✔Correct Answer-Within 1 month of release

6.2 Installation of applicable vendor-supplied security patches (non-critical) should be installed:
✔Correct Answer-Within an appropriate time frame (e.g., 3 months)

6.4.5 Change control procedures must include the following ✔Correct Answer-- Documentation of
impact
- Documented change approval by authorized parties
- Functionality testing to verify change does not adversely impact security of the system
- Back-out procedures

6.5 Developers must be trained in up-to-date secure coding techniques at least ________.
✔Correct Answer-Annually

6.6 For public-facing web applications, address new threats and vulnerabilities on an ongoing basis
and ensure these applications are protected against known attacks by either of the following
methods ✔Correct Answer-- At least annually, and after any changes, review via manual or
automated application vulnerability assessment tools/methods
- Automated technical solution that detects and prevents web-based attacks continuously

1.3.2 Examine firewall and router configurations to verify inbound traffic is: ✔Correct Answer-
Limited to IP addresses within the DMZ

7.1.4 Select sample of user IDs and compare with documented approvals to verify: ✔Correct
Answer-1) Documented approval exists for the assigned privileges
2) Approved by authorized parties
3) Specified privileges match the role of the user ID

8.1.4 Inactive user accounts ________________ should be removed or disabled. ✔Correct Answer-
Over 90 days old

8.1.5 Accounts used by third-parties should be: ✔Correct Answer-1) Disabled when not in use
2) Enabled only when needed, and disabled when not in use

8.1.6 Accounts should be locked out after _______________________. ✔Correct Answer-6 failed
login attempts

8.1.7 Locked out accounts remain locked out for __________ or _________________________ .
✔Correct Answer-30 minutes; administrator unlocks the account

8.1.8 Idle time-out set to _______________________. ✔Correct Answer-15 minutes or less

Infos sur le Document

Publié le
20 février 2026
Nombre de pages
9
Écrit en
2025/2026
Type
Examen
Contenu
Questions et réponses
13,21 €

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF

Seller avatar
Les scores de réputation sont basés sur le nombre de documents qu'un vendeur a vendus contre paiement ainsi que sur les avis qu'il a reçu pour ces documents. Il y a trois niveaux: Bronze, Argent et Or. Plus la réputation est bonne, plus vous pouvez faire confiance sur la qualité du travail des vendeurs.
Studyclub
3,6
(14)
Vendu
63
Abonnés
1
Éléments
12559
Dernière vente
4 jours de cela



Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Vous travaillez sur vos références ?

Créez des citations précises en APA, MLA et Harvard avec notre générateur de sources gratuit.

Vous travaillez sur vos références ?

Foire aux questions