Already Passed
Can existing PCI DSS requirements be considered as compensating controls if they are already
required for the item under review? ✔✔NO
What are reasons to consider using compensating controls? ✔✔Legitimate technical constraints
or documented business constraints
Do PCI DSS requirements apply if virtualization is used in the CDE? ✔✔YES
P2PE encrypts data at source and decrypts at destination ✔✔True
A compensating control must __________________________ ✔✔meet the rigor and intent of
the original requirement
A merchant with web based virtual terminals and no electronic cardholder data storage must
complete a _______ ✔✔SAQ C-VT