QUESTIONS WITH COMPLETE SOLUTIONS
GRADED A+
◉ Which of the following statements is true? Answer: All systems on
a "flat network" are in scope for the PCI DSS assessment.
◉ Assessors must always use DSS requirements have been met.
Answer: independent judgment
◉ Assessors must always use DSS requirements have been met.
Answer: independent judgment
◉ If a merchant is using a validated P2PE solution: Answer: the
merchant is responsible for ensuring their own PCI DSS compliance
◉ If an assessor wishes to use sampling during a PCI DSS
assessment of a merchant environment, the assessor must ensure:
Answer: the sample selection is representative Of all types Of system
components in the environment.
, ◉ Which Of the following merchant environments could be eligible
for SAQ B? Answer: Merchant with standalone dial-out terminals,
and no electronic cardholder data storage
◉ A service provider with no electronic cardholder data storage may
be eligible to complete: Answer: SAQ D
◉ It is permissible to store track data only if: Answer: An issuer has
a business reason
◉ Typically, these accounts have elevated or increased privileges
with more rights than a standard user account: Answer: Privileged
User
◉ A common error in scoping a PCI DSS assessment includes:
Answer: Assuming encrypted data is out-of-scope
◉ The assessment kickoff phase should include: Answer: Planning,
PCI Updates, Approach review, Key Dates, Key Roles and
Responsibilities, Project Governance
◉ This SAQ should be used for Merchants with Payment Application
Systems Connected to the Internet - No Electronic Cardholder Data
Storage: Answer: SAQ C