2026 FULL QUESTIONS AND SOLUTIONS
GRADED A+
• Track Data Storage.
Answer: True: Track Data cannot be stored post-authorization
• Do not store _____ AFTER authorization even if ___________..
Answer: sensitive authentication data; encrypted (sensitive auth data: track
data, verification code, PIN)
• Settlement.
Answer: Typically occurs within two days
• Verify that personnel attend security awareness training upon hire and at
least ___________________..
Answer: annually
• SHA-2.
Answer: National Security Agency's cryptographic hash functions
• Clear Text PAN Storage.
Answer: False: PAN must be rendered unreadable after authorization
• QSAs are required to retain work papers for a minimum of ____________,
and it is also recommended that ISAs retain work papers for a minimum of
___________..
Answer: 3 years; 3 years
• Manual clear-text key-management procedures specify processes for the use
of the following:.
Answer: Split knowledge AND Dual control of keys
• Audit Trails Storage.
Answer: Logs stored for immediate availability for 1 year and 3 months
, • Information Security Policy Review.
Answer: Annual review requirement
• What are the methods to authenticate users?.
Answer: - "Something you know", such as a password or passphrase -
"Something you have", such as a token device or smart card, or -
"Something you are", such as a biometric.
• Key Retirement.
Answer: When keys are weakened or compromised
• Least Privilege.
Answer: Granting minimal user access in CDE
• ROC Reporting Template.
Answer: Mandatory use for PCI DSS assessment ROCs
• Compensating controls requirement 2:.
Answer: Objective
• Storage Location Security Review.
Answer: Confirmation of secure backup media storage annually
• Perimeter firewalls installed ______________________________..
Answer: between all wireless networks and the CHD environment.
• Change-detection Mechanism Alert.
Answer: Alerts for unauthorized file modifications
• PA-DSS Validation Guarantee.
Answer: False: PA-DSS validation does not guarantee PCI-DSS compliance
• Risk Assessment Frequency.
Answer: Annual assessment and upon significant changes
• Network Segmentation Impact.
Answer: Scope extension without proper segmentation
• Video Camera Data Storage.
Answer: Retention of data for access controls for at least 3 months