(QUESTIONS AND ANSWERS) already passed!!
Steps of the PCI DSS Assessment Process
1. Assessor
2. Scope
3. Assess
4. Report
5. Attest
6. Submit
7. Compliance Accepting Entity
AOC
Attestation of Compliance-official PCI SSC form for merchants and service
providers for attest to a SAQ or ROC
Network Segmentation
Isolates segments from other processes, systems and data, Out of scope system
must not be able to be used via in scope system through CDE
Sampling
The sample is appropriate and the representative of the overall population
, CDE
Cardholder Data environment
How often do NSC configurations need to be reviewed for effectiveness?
Every 6 months
Truncation
method of rendering a full PAN unreadable by removing a segment of PAN
data. relates to protection of PAN when electronically stored, processed, or
transmitted
How often is training necessary for a software development personnel?
every 12 months
How often must public facing application must be reviewed?
every 12 months
How often are user accounts and related privileges, including third parities,
reviewed?
every 6 months
How many days of inactivity until users are removed?
90 days