Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free PCI SSC QSA_New_V4 Practice Exam with Questions & Answers

Questions 1

An entity accepts e-commerce payment card transactions and stores account data in a database. The database server and the web server are both accessible from the Internet. The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements?

Options:
A.

The web server and the database server should be installed on the same physical server.

B.

The database server should be relocated so that it is not accessible from untrusted networks.

C.

The web server should be moved into the internal network.

D.

The database server should be moved to a separate segment from the web server to allow for more concurrent connections.

PCI SSC QSA_New_V4 Premium Access
Questions 2

Which statement is true regarding the PCI DSS Report on Compliance (ROC)?

Options:
A.

The ROC Reporting Template and instructions provided by PCI SSC should be used for all ROCs.

B.

The assessor may use either their own template or the ROC Reporting Template provided by PCI SSC.

C.

The assessor must create their own ROC template for each assessment report.

D.

The ROC Reporting Template provided by PCI SSC is only required for service provider assessments.

Questions 3

Could an entity use both the Customized Approach and the Defined Approach to meet the same requirement?

Options:
A.

No, because a single approach must be selected.

B.

No, because only compensating controls can be used with the Defined Approach.

C.

Yes, if the entity uses no compensating controls.

D.

Yes, if the entity is eligible to use both approaches.

Questions 4

Which of the following is a requirement for multi-tenant service providers?

Options:
A.

Ensure that customers cannot access another entity’s cardholder data environment.

B.

Provide customers with access to the hosting provider's system configuration files.

C.

Provide customers with a shared user ID for access to critical system binaries.

D.

Ensure that a customer’s log files are available to all hosted entities.

Questions 5

Which systems must have anti-malware solutions?

Options:
A.

All CDE systems, connected systems. NSCs, and security-providing systems.

B.

All portable electronic storage.

C.

All systems that store PAN.

D.

Any in-scope system except for those identified as 'not at risk' from malware.

Questions 6

Which statement is true regarding the PCI DSS Report on Compliance (ROC)?

Options:
A.

The ROC Reporting Template and instructions provided by PCI SSC should be used for all ROCs.

B.

The assessor may use either their own template or the ROC Reporting Template provided by PCI SSC.

C.

The assessor must create their own ROC template tor each assessment report.

D.

The ROC Reporting Template provided by PCI SSC is only required for service provider assessments.

Questions 7

What does the PCI PTS standard cover?

Options:
A.

Point-of-Interaction devices used to protect account data.

B.

Secure coding practices for commercial payment applications.

C.

Development of strong cryptographic algorithms.

D.

End-lo-end encryption solutions for transmission of account data.

Questions 8

In accordance with PCI DSS Requirement 10, how long must audit logs be retained?

Options:
A.

At least 1 year, with the most recent 3 months immediately available.

B.

At least 2 years, with the most recent 3 months immediately available.

C.

At least 2 years, with the most recent month immediately available.

D.

At least 3 months, with the most recent month immediately available.

Questions 9

Which of the following is true regarding compensating controls?

Options:
A.

A compensating control is not necessary if all other PCI DSS requirements are in place.

B.

A compensating control must address the risk associated with not adhering to the PCI DSS requirement.

C.

An existing PCI DSS requirement can be used as a compensating control if it is already implemented.

D.

A compensating control worksheet is not required if the acquirer approves the compensating control.

Questions 10

What must be included in an organization's procedures for managing visitors?

Options:
A.

Visitors are escorted at all times within areas where cardholder data is processed or maintained.

B.

Visitor badges are identical to badges used by onsite personnel.

C.

Visitor log includes visitor name, address, and contact phone number.

D.

Visitors retain their identification (for example, a visitor badge) for 30 days after completion of the visit.