ACTUAL LATEST VERSIONS 65 QUESTIONS AND
CORRECT VERIFIED ANSWERS WITH
RATIONALES (100% CORRECT) A+ GRADED
ASSURED
A retail location that does not use wireless devices in store must test for the presence of
unauthorized wireless devices every ________________. - CORRECT ANSWER: quarter
Acquirer - CORRECT ANSWER: Bank or entity the merchant uses to process their payment
card transactions
Acquirer is also called:
Merchant Bank
ISO (sometimes)
Payment Brand - Amex, Discover, JCB
Never Visa or MasterCard
All security events and logs of (a) all system components that store, process, or transmit CHD;
(b) critical system components; (c) components that perform security functions (for example,
firewalls, intrusion-detection systems/intrusion-prevention systems (IDS/IPS), authentication
servers, e-commerce redirection servers, etc.) to be reviewed at least ______________. -
CORRECT ANSWER: daily
An example of a "one-way" cryptographic function used to render data unreadable is: -
CORRECT ANSWER: SHA-2
Anti-virus solutions may be temporarily disabled only if - CORRECT ANSWER: there is
legitimate technical need, as authorized by management on a case-by-case basis
, Appendix A1 applies to - CORRECT ANSWER: hosting providers
Appendix A2 applies to - CORRECT ANSWER: entities using SSL/Early TLS
Appendix A3 applies to - CORRECT ANSWER: Designated Entities Supplemental Validation
(DESV)
An entity is required to undergo an assessment according to this Appendix ONLY if instructed to
do so by
an acquirer or a payment brand.
ASV scans must cover__________________________________. - CORRECT ANSWER: ALL
Internet-Facing IP addresses in existence at the entity.
Audit logs must be immediately available for analysis for a period of ________ and must be
retained for a period of _________. - CORRECT ANSWER: 3 months; 1 year
Compensating controls need to be evaluated at least_________________. - CORRECT
ANSWER: annually
Compensating controls requirement 1: - CORRECT ANSWER: Constrains
Compensating controls requirement 2: - CORRECT ANSWER: Objective
Compensating controls requirement 3: - CORRECT ANSWER: Risk
Compensating controls requirement 4: - CORRECT ANSWER: Definition
Compensating controls requirement 5: - CORRECT ANSWER: Validation