Answers |Latest Version |Already Graded A+
What is PCI DSS ? ✔Correct Answer-Payment Card Industry Data Security Standard
For consistent data security measures globally
12 requirements in six groups
PCI DSS is a minimum set of controls
It is a contractual agreement, not a standard
PCI-DSS only applies if PANs are stored, processed or transmitted
Objective 1 ✔Correct Answer-Build and Maintain a secure network
Objective 2 ✔Correct Answer-Protect Card Holder Data
Objective 3 ✔Correct Answer-Maintain a vulnerability program
Objective 4 ✔Correct Answer-Implement strong Access control measures
Objective 5 ✔Correct Answer-Regularly Monitor and Test networks
Objective 6 ✔Correct Answer-Maintain an Information Security Policy
Cardholder data ✔Correct Answer-Primary Account Number (PAN)
Cardholder name
Expiration date
Service Code
Sensitive Authentication Data ✔Correct Answer-Magnetic stripe data or equivalent on a chip
CAV2/CVC2/CVV2/CID
PINs / PIN Blocks
What is PA-DSS ? ✔Correct Answer-Payment Application Data Security Standard
PA-DSS applies to software sold "off the shelf" by 3rd parties
PA-DSS does not apply to applications developed by merchants and service providers for use in-
house. (this is covered by PCI-DSS)
Scope ✔Correct Answer-Is a primary requirement
cardholder data flows help set scope
business practices and processes need careful consideration and may need re-engineering.
Network Segmentation is ✔Correct Answer-Recommended to reduce scope and risk
When can Wireless be used? ✔Correct Answer-Use only for non-sensitive data
Carefully consider the Risk
MUST be tested
Service Providers ✔Correct Answer-Need their own PCI-DSS compliance or will have their services
reviewed as part of their customers audits.
, The Report on Compliance (ROC) documents the role of each service provider.
Sampling ✔Correct Answer-Sampling of Business Facilities / System components is allowed,
however all applicable PCI DSS requirements must be considered.
Compensating Controls ✔Correct Answer-a Compensating Controls Worksheet must be completed
for each compensating control. And documented in the ROC.
Compliance Completion Steps ✔Correct Answer-1.Complete the ROC
2. Provide evidence of passing scans from ASV
3. Complete the "Attestation of compliance"
4. Submit all to the Aquirer, or Payment Brand
PCI SSC ✔Correct Answer-Payment card Industry Security Standards Council
ASV ✔Correct Answer-Approved Scanning Vendors
QSA ✔Correct Answer-Qualified Security Assessor
PCI PA-DSS ✔Correct Answer-Payment card Industry Payment Application Data Security Standard
PCI PED ✔Correct Answer-Payment Card Industry Pin Entry Devices
Merchant levels ✔Correct Answer-Defined by payment brands.
Levels 1 to 4
1 is the largets merchants or merchants who have been compromised. 6 Million transactions/year +
Non-compliance consequences ✔Correct Answer-Fines according to Level and elapsed time
determined by payment brands
Breach Consequences ✔Correct Answer-Fine per cardholder data compromised / Loss of
reputation / customer trust / suspension of service by credit card account provider
Firewall and Router rule sets be reviewed at least every ✔Correct Answer-6 Months
It is required to install all critical new security patches within ✔Correct Answer-1 Month
Public facing web applications are to be reviewed ✔Correct Answer-at least annually
Users are required to change passwords at least every ✔Correct Answer-90 Days
Remove or Disable inactive accounts over ✔Correct Answer-90 Days
New passwords cannot be the same as __________ previous passwords ✔Correct Answer-4
Passwords
Users accounts are to be locked out after more than ________ invalid logon attempts ✔Correct
Answer-6