Spring Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

What does the PCI PTS standard cover?

A.

Point-of-interaction devices used to protect account data

B.

Secure coding practices for commercial payment applications.

C.

Development of strong cryptographic algorithms

D.

End-to-end encryption solutions for transmission of account data

Where can live PANs be used for testing?

A.

Production (live) environments only

B.

Pre-production (test) environments only if located outside the CDE.

C.

Pre-production environments that are located within the CDE

D.

Testing with live PANs must only be performed in the QSA Company environment

Which of the following can be sampled for testing during a PCI DSS assessment?

A.

PCI DSS requirements and testing procedures.

B.

Compensating controls

C.

Business facilities and system components

D.

Security policies and procedures

Which statement is true regarding the presence of both hashed and truncated versions of the same PAN in an environment?

A.

Controls are needed to prevent the original PAN being exposed by the hashed and truncated versions

B.

The hashed version of the PAN must also be truncated per PCI OSS requirements for strong cryptography.

C.

The hashed and truncated versions must be correlated so the source PAN can be identified

D.

Hashed and truncated versions of a PAN must not exist in same environment

A "Partial Assessment is a new assessment result What is a ‘Partial Assessment’?

A.

A ROC that has been completed after using an SAQ to determine which requirements should be tested. As per FAQ 1331. (As long as the entity meets the SAQs eligibility criteria)

B.

An interim result before the final ROC has been completed

C.

A term used by payment brands and acquirers to describe entities that have multiple payment channels with each channel having its own assessment

D.

An assessment with at least one requirement marked as Not Tested”

Which statement about the Attestation of Compliance (AOC) is correct?

A.

There are different AOC templates for service providers and merchants

B.

The AOC must be signed by both the merchant/service provider and by PCI SSC

C.

The same AOC template is used for ROCs and SAQs

D.

The AOC must be signed by either the merchant service provider or the QSA'ISA

An entity wants to know if the Software Security Framework can be leveraged during their assessment Which of the following software types would this apply to?

A.

Any payment software in the CDE

B.

Only software which runs on PCI PTS devices

C.

Validated Payment Applications that are listed by PCI SSC and have undergone a PA-DSS assessment

D.

Software developed by the entity in accordance with the Secure SLC Standard

An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?

A.

Certificates are assigned only to administrative groups and not to regular users

B.

A different certificate is assigned to each individual user account, and certificates are not shared

C.

Certificates are logged so they can be retrieved when the employee leaves the company

D.

Change control processes are in place to ensue certificates are changed every 90 days