CSC CSC - Cybersecurity Compliance PCI DSS Payment Card Security Questions and Answers 1 — Questions and Answers
Question 1: Which organization maintains and publishes the Payment Card Industry Data Security Standard (PCI DSS)?
- PCI Security Standards Council (Correct answer)
- Federal Trade Commission
- NIST
- ISO
Correct answer: PCI Security Standards Council
The PCI Security Standards Council (PCI SSC), founded by major card brands, owns and publishes PCI DSS.
Question 2: How many high-level requirements does PCI DSS version 4.0 contain?
- 12 (Correct answer)
- 8
- 16
- 6
Correct answer: 12
PCI DSS v4.0 retains the same 12 high-level requirements as prior versions while adding new sub-requirements.
Question 3: Which PCI DSS requirement specifically addresses the protection of stored cardholder data?
- Requirement 3 (Correct answer)
- Requirement 1
- Requirement 6
- Requirement 10
Correct answer: Requirement 3
PCI DSS Requirement 3 mandates protecting stored account data through encryption, masking, and retention controls.
Question 4: What does the term 'cardholder data environment' (CDE) refer to in PCI DSS?
- Systems that store, process, or transmit cardholder data (Correct answer)
- Only point-of-sale terminals
- The card issuer's internal network
- Encrypted backup storage only
Correct answer: Systems that store, process, or transmit cardholder data
The CDE encompasses all people, processes, and technology that store, process, or transmit cardholder or sensitive authentication data.
Question 5: Which PCI DSS compliance validation level applies to merchants processing over 6 million Visa transactions annually?
- Level 1 (Correct answer)
- Level 2
- Level 3
- Level 4
Correct answer: Level 1
Level 1 merchants process more than 6 million transactions per year and must undergo an annual on-site audit by a QSA.
Question 6: What is a Qualified Security Assessor (QSA) in the context of PCI DSS?
- A company certified by PCI SSC to conduct PCI DSS compliance assessments (Correct answer)
- An internal auditor trained in ISO 27001
- A federal regulator who enforces PCI standards
- A card brand representative who approves merchant accounts
Correct answer: A company certified by PCI SSC to conduct PCI DSS compliance assessments
A QSA is an organization qualified by the PCI SSC to perform on-site PCI DSS assessments for Level 1 merchants and service providers.
Which organization maintains and publishes the Payment Card Industry Data Security Standard (PCI DSS)?