CSC - Cybersecurity Compliance PCI DSS Payment Card Security Questions and Answers Flashcards
6 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CSC - Cybersecurity Compliance PCI DSS Payment Card Security Questions and Answers flashcards as text
PCI DSS Requirement 1 focuses on which security control category?
Answer: Installing and maintaining network security controls
Requirement 1 requires organizations to install and maintain firewalls and other network security controls to protect the CDE.
Under PCI DSS, what is the maximum number of digits that may be displayed when masking a primary account number (PAN)?
Answer: The first six and last four digits
PCI DSS allows displaying the first six and last four digits of a PAN; all other digits must be masked.
Which cryptographic approach does PCI DSS recommend for protecting PANs stored in databases?
Answer: Strong one-way hash functions or strong encryption
PCI DSS requires strong cryptography such as AES-256 or NIST-approved one-way hashes to render stored PAN data unreadable.
What does PCI DSS Requirement 6 specifically require organizations to do?
Answer: Develop and maintain secure systems and software
Requirement 6 mandates a secure software development lifecycle, including vulnerability management and patch deployment for all systems in scope.
How often must PCI DSS-compliant organizations perform internal vulnerability scans of their CDE?
Answer: At least quarterly
PCI DSS requires internal vulnerability scans to be performed at least quarterly and after any significant changes to the environment.
What is the purpose of a Self-Assessment Questionnaire (SAQ) in PCI DSS?
Answer: A validation tool for eligible merchants and service providers to self-evaluate compliance
SAQs allow smaller merchants and service providers to document their PCI DSS compliance without requiring a full QSA on-site assessment.