PCI Fundamentals Questions and Correct Answers |
Latest Update
The payment card brands are responsible for:
Ans: penalty or fee assignment for non-compliance
Authorization of a transaction usually takes place:
Ans: within one day
If a suspected card account number passes the Mod 10 test it means:
Assignment Expert
Ans: it is definitely a valid PAN
Guru01 - Stuvia
Which of the following is true regarding network segmentation?
Ans: Network segmentation is not a PCI DSS requirement
Which of the following is true related to the tracks of data on the
2026
magnetic stripe of a payment card?
Ans: Track 1 contains all the fields of both track 1 and track 2
©
How Often should the firewall and router rule sets be reviewed?
Ans: Every six months
Which Of the following statements is true concerning transaction
volumes for merchants?
Ans: Transaction volume is determined by each acquirer
Storing full track data after authorization is permitted under the
following circumstances:
Ans: NEVER
In order to reduce PCI DSS scope, adequate network segmentation should:
, 2 for specific request mail
Ans: isolate systems that store, process, or transmit cardholder data
from those that do not
Systems that commonly store track data:
Ans: POSsystems
Which Of the following is true, regarding an entity sharing cardholder
data with a service provider?
Ans: The entity must have an established process for engaging service
providers, including proper due diligence prior to engagement.
Assignment Expert
When must critical new security patches be installed?
Guru01 - Stuvia
Ans: Within one month of release
Which Of the following statements is true?
Ans: PA-DSS compliant payment applications are in scope for a
2026
merchant's PCI DSS assessment
In accordance with PCI DSS Requirement 1, firewalls are required:
©
Ans: between the cardholder environment and Other internal networks
Which party is responsible for merchant compliance validation and
merchant communications?
Ans: Acquirer
The Mod 10 formula doubles the value of alternate digits of the primary
account number beginning with which digit?
Ans: Second from the left
Strong access control lists include the following:
Ans: Do not allow "risky" protocols such as FTP or Telnet.