Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Document preview thumbnail
Aperçu 2 sur 7 pages
Examen

PCI ISA Exam with all Correct & 100% Verified Answers |Latest Version |Already Graded A+

Document preview thumbnail
Aperçu 2 sur 7 pages

PCI ISA Exam with all Correct & 100% Verified Answers |Latest Version |Already Graded A+

Aperçu du contenu

PCI ISA Exam with all Correct & 100% Verified Answers
|Latest Version |Already Graded A+

Non-console administrator access to any web-based management interfaces must be encrypted with
technology such as......... ✔Correct Answer-HTTPS

Requirements 2.2.2 and 2.2.3 cover the use of secure services, protocols and daemons. Which of the
following is considered to be secure? ✔Correct Answer-SSH

Which of the following is considered "Sensitive Authentication Data"? ✔Correct Answer-Card
Verification Value (CAV2/CVC2/CVV2/CID), Full Track Data, PIN/PIN Block

True or False: It is acceptable for merchants to store Sensitive Authentication after authorization as
long as it is strongly encrypted? ✔Correct Answer-False

When a PAN is displayed to an employee who does NOT need to see the full PAN, the minimum digits
to be masked are: ✔Correct Answer-All digits between the first six and last four

Which of the following is true regarding protection of PAN? ✔Correct Answer-PAN must be
rendered unreadable during transmission over public, wireless networks

Which of the following may be used to render PAN unreadable in order to meet requirement 3.4?
✔Correct Answer-Hashing the entire PAN using strong cryptography

True or False Where keys are stored on production systems, split knowledge and dual control is
required? ✔Correct Answer-True

When assessing requirement 6.5, testing to verify secure coding techniques are in place to address
common coding vulnerabilities includes: ✔Correct Answer-Reviewing software development
policies and procedures

One of the principles to be used when granting user access to systems in CDE is: ✔Correct Answer-
Least privilege

An example of a "one-way" cryptographic function used to render data unreadable is: ✔Correct
Answer-SHA-2

A set of cryptographic hash functions designed by the National Security Agency (NS). ✔Correct
Answer-SHA-2 (Secure Hash Algorithm

True or False: Procedures must be developed to easily distinguish the difference between onsite
personnel and visitors. ✔Correct Answer-True

When should access be revoked of recently terminated employees? ✔Correct Answer-immediately

True or False: A visitor with a badge may enter sensitive area unescorted. ✔Correct Answer-False,
visitors must be escorted at all times.

, Protection of keys used for encryption of cardholder data against disclosure must include at least: (4
items) ✔Correct Answer-*Access to keys is restricted to the fewest number of custodians
necessary
*Key-encrypting keys are at least as strong as the data-encrypting keys they protect
*Key encrypting keys are stored separately from data-encrypting keys
*Keys are stored securely in the fewest possible locations

Description of cryptographic architecture includes: ✔Correct Answer-*Details of all algorithms,
protocols, and keys used for the protection of cardholder data, including key strength and expiry date
*Description of the key usage for each key
*Inventory of any HSMs and other SCDs used for key management

What 2 methods must NOT be used to be disk-level encryption compliant ✔Correct Answer-
*Cannot use the same user account authenticator as the operating system
*Cannot use a decryption key that is associated with or derived from the systems local user account
database or general network login credentials.

6 months ✔Correct Answer-DESV User accounts and access privileges are reviewed at least
every______

Track 1 (Length up to 79 characters) ✔Correct Answer-Contains all fields of both Track 1 and Track
2

Track 2 (Length up to 40 characters) ✔Correct Answer-Provides shorter processing time for older
dial-up transmissions.

DESV ✔Correct Answer-Designated Entities Supplemental Validation

DESV Requirements: ✔Correct Answer-*Implementing a PCI DSS Compliance program
*Document and validate PCI DSS Scope
*Validate PCI DSS is incorporated into business-as-usual (BAU) activities
*Control and manage logical access to cardholder data environment
*Identify and respond to suspicious events

Who could DESV requirements apply to? ✔Correct Answer-Those that have suffered significant or
repeated breaches of cardholder data.

PCI DSS requirements apply to_____ ✔Correct Answer-people, processes, and technologies

When planning for an assessment what 4 activities should be included during planning? ✔Correct
Answer-*List of people to be interviewed, system components used, documentation (training,
payment logs), facilities (physical security)
*Ensure assessor is familiar with technologies in assessment
*If sampling, verify sample section and size is representative of the entire population
*Identify the roles and the individuals within each role to be interviewed as part of the assessment

What pre-assessment activities should an assessor consider when preparing for an assessment?
✔Correct Answer-*Ensure assessor(s) has competent knowledge of the technologies being assessed
*Identify types of system components and locations of facilities to be reviewed
*Consider size and complexity of the environment to be assessed.

Infos sur le Document

Publié le
20 février 2026
Nombre de pages
7
Écrit en
2025/2026
Type
Examen
Contenu
Questions et réponses
11,45 €

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF

Seller avatar
Les scores de réputation sont basés sur le nombre de documents qu'un vendeur a vendus contre paiement ainsi que sur les avis qu'il a reçu pour ces documents. Il y a trois niveaux: Bronze, Argent et Or. Plus la réputation est bonne, plus vous pouvez faire confiance sur la qualité du travail des vendeurs.
Studyclub
3,6
(14)
Vendu
63
Abonnés
1
Éléments
12559
Dernière vente
4 jours de cela



Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Vous travaillez sur vos références ?

Créez des citations précises en APA, MLA et Harvard avec notre générateur de sources gratuit.

Vous travaillez sur vos références ?

Foire aux questions