QUESTIONS WITH VERIFIED ANSWERS
GRADED A+
◉ Which party is responsible for merchant compliance validation
and merchant communications? Answer: Acquirer
◉ The Mod 10 formula doubles the value of alternate digits of the
primary account number beginning with which digit? Answer:
Second from the left
◉ Strong access control lists include the following: Answer: Do not
allow "risky" protocols such as FTP or Telnet.
◉ Which of the following is true? Answer: A PA-DSS application
installed by a QIR must still be reviewed during the PCI DSS
assessment.
◉ PCI SSC Community Meetings: Answer: provide opportunity for
PCI stakeholders to provide suggestions for changes and
improvements.
, ◉ Which of the following is true regarding Track data: Answer:
Track 1 contains all Track 2 data and additional fields for use by the
card issuer
◉ Which of the following statements is true? Answer: All systems on
a "flat network" are in scope for the PCI DSS assessment.
◉ Assessors must always use DSS requirements have been met.
Answer: independent judgment
◉ If a merchant is using a validated P2PE solution: Answer: the
merchant is responsible for ensuring their own PCI DSS compliance
◉ If an assessor wishes to use sampling during a PCI DSS
assessment of a merchant environment, the assessor must ensure:
Answer: the sample selection is representative Of all types Of system
components in the environment.
◉ Which Of the following merchant environments could be eligible
for SAQ B? Answer: Merchant with standalone dial-out terminals,
and no electronic cardholder data storage
◉ A service provider with no electronic cardholder data storage may
be eligible to complete: Answer: SAQ D