Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

PCIP Exam Questions and Answers Graded A+

Rating
-
Sold
-
Pages
37
Grade
A+
Uploaded on
06-09-2023
Written in
2023/2024

PCI Data Security Standard (PCI DSS) The PCI DSS applies to all entities that store, process, and/or transmit cardholder data. It covers technical and operational system components included in or connected to cardholder data. If you accept or process payment cards, PCI DSS applies to you. Sensitive Authentication Data Merchants, service providers, and other entities involved with payment card processing must never store sensitive authentication data after authorization. This includes the 3- or 4- digit security code printed on the front or back of a card (CVD), the data stored on a card's magnetic stripe or chip (also called "Full Track Data") - and personal identification numbers (PIN) entered by the cardholder.

Show more Read less
Institution
Course

Content preview

PCIP Exam Questions and Answers
Graded A+
PCI Data Security Standard (PCI DSS)

The PCI DSS applies to all entities that store, process, and/or transmit cardholder data. It

covers technical

and operational system components included in or connected to cardholder data. If you accept

or process payment cards, PCI DSS applies to you.




Sensitive Authentication Data

Merchants, service providers, and other

entities involved with payment card processing must never store sensitive authentication

data after

authorization. This includes the 3- or 4- digit security code printed on the front or back of a card

(CVD), the data stored on a card's magnetic stripe or chip (also called "Full Track Data") - and

personal identification numbers (PIN) entered by the cardholder.

,Card Verification Data Codes (CVD)

3 or 4 digit code that further authenticates a not-present cardholder

Visa-CVV2

MC- CVC2

Discover- CVD

JCB-CAV2

AmEx- CID

Requirement 1

Install and maintain a firewall configuration to protect cardholder data




Network devices in scope for Requirement 1

Firewalls and Routers- Routers connect traffic between networks, Firewalls control the

traffic between networks and within internal network




QIR Qualified Integrators & Resellers

,Qualified Integrators & Resellers- authorized by the SSC to implement, configure and/or

support PA-DSS payment applications. Visa requires all level 4 merchants use QIRs for POS

application and terminal installation and servicing

Compensating Controls

An alternative control, put in place to satisfy the requirement for a security measure that is

deemed too difficult or impractical to implement at the present time.

Permitted reasons for using Compensating Controls

Organizations needing an alternative to security requirements that could not be met due

to legitimate technological OR documented business constraints, but has sufficiently

mitigated the risk associated with the requirement through implementation of other

compensating controls

Examples of Compensating Controls

(i) Segregation of Duties (SOD) and (ii) Encryption

Compensating Controls must:

1) Meet the intent and rigor of the original stated requirement;



2) Provide a similar level of defense as the original stated requirement;



3) Be "above and beyond" other PCI DSS requirements (not simply in compliance with other

PCI DSS requirements); and

, 4) Be commensurate with the additional risk imposed by not adhering to the original stated

requirement.

Compensating Controls Worksheet

1) Constraint; 2) Objective; 3) Identified Risk; 4) Define Compensating Control; 5)Validate

Controls; 6) Maintenance (COIDVM)

Card Data that cannot be stored by Merchants, Service providers after authorization

Sensitive Authentication Data. i) 3- or 4- digit security code printed on the front or back of a

card, ii) data stored on a card's magnetic stripe or chip (also called "Full Track Data"), and iii)

personal identification

numbers (PIN) entered by the cardholder

Card Data that MAY be stored

i) cardholder name, ii) service code (identifies industry iii) Personal Account Number (PAN)

iv) expiration date may be stored.

Network Segmentation

The process of isolating the cardholder data environment from the remainder of an entity's

network

Not a requirement but strongly recommended.

Report on Compliance (ROC)

Prepared at the time of the assessment of PCI compliance and comprehensively provides details

about the assessment approach and compliance standing against each PCI DSS requirement

Written for

Course

Document information

Uploaded on
September 6, 2023
Number of pages
37
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$18.89
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Layer City University New York
Follow You need to be logged in order to follow users or courses
Sold
9
Member since
3 year
Number of followers
7
Documents
1666
Last sold
1 year ago
exams and notes

Credible notes and exams questions and answers at convenient rates

5.0

2 reviews

5
2
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions