PCIP EXAM QUESTIONS WITH 100% CORRECT ANSWERS LATEST
PCIP Exam PCI Data Security Standard (PCI DSS) - CORRECT ANSWER The PCI DSS applies to all entities that store, process, and/or transmit cardholder data. It covers technical and operational system components included in or connected to cardholder data. If you accept or process payment cards, PCI DSS applies to you. Sensitive Authentication Data - CORRECT ANSWER Merchants, service providers, and other entities involved with payment card processing must never store sensitive authentication data after authorization. This includes the 3- or 4- digit security code printed on the front or back of a card (CVD), the data stored on a card's magnetic stripe or chip (also called "Full Track Data") - and personal identification numbers (PIN) entered by the cardholder. Card Verification Data Codes (CVD) - CORRECT ANSWER 3 or 4 digit code that further authenticates a not-present cardholder Visa-CVV2 MC- CVC2 Discover- CVD JCB-CAV2 AmEx- CID Requirement 1 - CORRECT ANSWER Install and maintain a firewall configuration to protect cardholder data Network devices in scope for Requirement 1 - CORRECT ANSWER Firewalls and Routers- Routers connect traffic between networks, Firewalls control the traffic between networks and within internal network QIR Qualified Integrators & Resellers - CORRECT ANSWER Qualified Integrators & Resellers- authorized by the SSC to implement, configure and/or support PA-DSS payment applications. Visa requires all level 4 merchants use QIRs for POS application and terminal installation and servicing Compensating Controls - CORRECT ANSWER An alternative control, put in place to satisfy the requirement for a security measure that is deemed too difficult or impractical to implement at the present time. Permitted reasons for using Compensating Controls - CORRECT ANSWER Organizations needing an alternative to security requirements that could not be met due to legitimate technological OR documented business constraints, but has sufficiently mitigated the risk associated with the requirement through implementation of other compensating controls Examples of Compensating Controls - CORRECT ANSWER (i) Segregation of Duties (SOD) and (ii) Encryption Compensating Controls must: - CORRECT ANSWER 1) Meet the intent and rigor of the original stated requirement; 2) Provide a similar level of defense as the original stated requirement; 3) Be "above and beyond" other PCI DSS requirements (not simply in compliance with other PCI DSS requirements); and 4) Be commensurate with the additional risk imposed by not adhering to the original stated requirement.
Geschreven voor
- Instelling
- PCIP
- Vak
- PCIP
Documentinformatie
- Geüpload op
- 28 september 2023
- Aantal pagina's
- 21
- Geschreven in
- 2023/2024
- Type
- Tentamen (uitwerkingen)
- Bevat
- Vragen en antwoorden
Onderwerpen
-
pcip exam questions with 100 correct answers 2023