โ† All CSC Flashcard Decks

CSC - Cybersecurity Compliance PCI DSS Payment Card Security Questions and Answers Flashcards

6 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CSC - Cybersecurity Compliance PCI DSS Payment Card Security Questions and Answers flashcards as text
  1. Which PCI DSS requirement addresses the implementation of strong access control measures for cardholder data systems?

    Answer: Requirement 7

    Requirement 7 mandates restricting access to system components and cardholder data to only those individuals whose job requires such access.

  2. Under PCI DSS, what must be assigned to each individual with computer access to the CDE?

    Answer: A unique user ID

    PCI DSS Requirement 8 requires each user to have a unique ID so that actions within the CDE can be attributed to a specific individual.

  3. What does PCI DSS Requirement 9 govern?

    Answer: Restricting physical access to cardholder data

    Requirement 9 covers physical security controls to prevent unauthorized physical access to systems that store, process, or transmit cardholder data.

  4. PCI DSS Requirement 10 requires organizations to do which of the following?

    Answer: Log and monitor all access to network resources and cardholder data

    Requirement 10 mandates that audit logs capture all access to network resources and cardholder data to enable forensic investigation and anomaly detection.

  5. What is the primary purpose of penetration testing under PCI DSS Requirement 11?

    Answer: To verify that security controls are working and identify exploitable vulnerabilities

    PCI DSS Requirement 11.4 requires penetration testing to simulate real-world attacks and confirm that network and application-layer controls are effective.

  6. Which PCI DSS requirement mandates that organizations maintain an information security policy for all personnel?

    Answer: Requirement 12

    Requirement 12 requires a comprehensive information security policy that is reviewed annually and communicated to all relevant personnel.

CSC - Cybersecurity Compliance PCI DSS Payment Card Security Questions and Answers Flashcards โ€” CSC Study Cards with Answers