Which of the below functions is associated with acquirers?
- Provide clearing services to a merchant
- Provide authorization services to the merchant
- All of the options
- Provide settlement services to the merchant - answerAll of the options
If virtualization technologies are used in cardholder data environment?
- Virtualization technologies are not to be used in the cardholder data environment
- The virtualization technologies are not in scope for PCI-DSS
- Entities using virtualization technologies should be complete SAQ C
- The virtualization technologies are included in scope for PCI DSS - answerThe
virtualization technologies are included in scope for PCI DSS
Access to view audit trails should be granted _____.
- only to individuals with a job-related need
- So that no personnel can view the logs
- To all system operators
- To all personnel - answeronly to individuals with a job-related need
Audit logs must be immediately available for analysis for a period of ____ and must be
retained for a period of _____.
- 3 months and 1 year
- 6 months and 1 year
- 2 months and 2 years
- 2 months and 1 year - answer3 months and 1 year
Which of the following is true regarding protection of PAN?
- PAN must be rendered unreadable during transmission over public , wireless networks
- There are no PCI-DSS requirements for rendering PAN unreadable
- PAN must be rendered unreadable during transmission over private, secure network
- PAN must be rendered unreadable when present in volatile memory during a
transaction - answerPAN must be rendered unreadable during transmission over
public , wireless networks
One of the principles to be used when granting user access to systems in the CDE is:
- Default allow all
- Equal privilege
- Least privilege
- Most privilege - answerLeast privilege
, Storing track data "long term" or "persistently" is permitted when_______.
- It is hashed by the merchants storing it.
- It is reported to the PCI SSC annually in a ROC
- It is encrypted by the merchant storing it.
- It is being stored by the issuers - answerIt is being stored by the issuers
The decision about a merchant's level is made by the:
- Merchant's QSA
- Payment Brands
- Merchant
- Merchant's acquirer - answerMerchant's acquirer
Which of the following is considered "sensitive authentication data"?
- Cardholder name
- Expiration date
- Card verification value
- PAN - answerCard verification value
PCI-DSS Requirement 3.4 stats that PAN must be rendered unreadable when stored.
Which of the following must be used to meet the requirement?
- Encryption in the first six and the last four numbers of the PAN
- Hiding the column containing PAN data in the database
- Hashing the entire PAN using strong cryptography
- Masking the entire PAN using industry standards - answerHashing the entire PAN
using strong cryptography
Which of the following are parts if payment brand role? (Select all that apply)
- Develop and enforce compliance programs
- Endorse QSA, PA-QSA and ASV company qualification criteria
- Accept validation documentation from QSAs, PA-QSAs & ASV's
- Offer training for QSAs, PA. QSAs and ASVs - answerDevelop and enforce
compliance programs
Endorse QSA, PA-QSA and ASV company qualification criteria
Accept validation documentation from QSAs, PA-QSAs & ASV's
In which step does the payment brand network provide complete reconciliation to the
merchant's bank?
- Approval
- Clearing
- Settlement
- Authorization - answerClearing
Account data consists of _______ and ________.
- Cardholder data and Sensitive authentication data
- Card holder names and PANs
- PANs and PINs
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller jw638729. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $12.99. You're not tied to anything after your purchase.