CSC CSC - Cybersecurity Compliance PCI DSS Payment Card Security Questions and Answers 2 — Questions and Answers
Question 1: PCI DSS Requirement 1 focuses on which security control category?
- Installing and maintaining network security controls (Correct answer)
- Encrypting cardholder data at rest
- Managing access control for databases
- Implementing anti-malware software
Correct answer: Installing and maintaining network security controls
Requirement 1 requires organizations to install and maintain firewalls and other network security controls to protect the CDE.
Question 2: Under PCI DSS, what is the maximum number of digits that may be displayed when masking a primary account number (PAN)?
- The first six and last four digits (Correct answer)
- The last eight digits only
- The first four digits only
- No digits may be displayed
Correct answer: The first six and last four digits
PCI DSS allows displaying the first six and last four digits of a PAN; all other digits must be masked.
Question 3: Which cryptographic approach does PCI DSS recommend for protecting PANs stored in databases?
- Strong one-way hash functions or strong encryption (Correct answer)
- Base64 encoding
- ROT13 obfuscation
- Password-protected ZIP archives
Correct answer: Strong one-way hash functions or strong encryption
PCI DSS requires strong cryptography such as AES-256 or NIST-approved one-way hashes to render stored PAN data unreadable.
Question 4: What does PCI DSS Requirement 6 specifically require organizations to do?
- Develop and maintain secure systems and software (Correct answer)
- Monitor all access to cardholder data
- Restrict physical access to cardholder data
- Protect all systems against malware
Correct answer: Develop and maintain secure systems and software
Requirement 6 mandates a secure software development lifecycle, including vulnerability management and patch deployment for all systems in scope.
Question 5: How often must PCI DSS-compliant organizations perform internal vulnerability scans of their CDE?
- At least quarterly (Correct answer)
- Annually only
- Monthly
- Only after a significant change
Correct answer: At least quarterly
PCI DSS requires internal vulnerability scans to be performed at least quarterly and after any significant changes to the environment.
Question 6: What is the purpose of a Self-Assessment Questionnaire (SAQ) in PCI DSS?
- A validation tool for eligible merchants and service providers to self-evaluate compliance (Correct answer)
- A document submitted to acquire merchant account approval
- A technical checklist used only by QSAs during on-site audits
- A report filed with the FTC after a data breach
Correct answer: A validation tool for eligible merchants and service providers to self-evaluate compliance
SAQs allow smaller merchants and service providers to document their PCI DSS compliance without requiring a full QSA on-site assessment.
PCI DSS Requirement 1 focuses on which security control category?