PCI PCI DSS Requirements & Implementation — Questions and Answers
Question 1: How many core requirements does PCI DSS contain?
- 12 requirements organized into 6 goals (Correct answer)
- 6 requirements
- 24 requirements
- 3 requirements
Correct answer: 12 requirements organized into 6 goals
PCI DSS contains 12 core requirements organized under 6 goals: build/maintain secure network, protect cardholder data, maintain vulnerability management, implement access controls, monitor/test networks, and maintain security policies.
Question 2: What is the purpose of network segmentation in PCI compliance?
- To isolate the cardholder data environment from the rest of the network, reducing the scope of PCI assessment (Correct answer)
- To increase internet speed for the organization
- To create separate networks for each employee
- Network segmentation is prohibited under PCI DSS
Correct answer: To isolate the cardholder data environment from the rest of the network, reducing the scope of PCI assessment
Network segmentation isolates systems that process cardholder data, reducing the number of systems subject to PCI requirements and the attack surface available to threat actors.
Question 3: What is a Self-Assessment Questionnaire (SAQ) in PCI compliance?
- A validation tool for merchants and service providers to self-evaluate their compliance with PCI DSS (Correct answer)
- A customer satisfaction survey about payment experiences
- An employee knowledge assessment about company policies
- A vendor evaluation questionnaire for procurement
Correct answer: A validation tool for merchants and service providers to self-evaluate their compliance with PCI DSS
SAQs allow smaller merchants to self-assess their PCI compliance status based on their specific payment processing methods, with different SAQ types for different processing environments.
Question 4: What data elements must be protected under PCI DSS?
- Primary Account Number (PAN), cardholder name, expiration date, and service code (Correct answer)
- Only the cardholder's name and address
- Only the card number, nothing else
- Social Security numbers and birth dates only
Correct answer: Primary Account Number (PAN), cardholder name, expiration date, and service code
PCI DSS requires protection of the PAN (which must be rendered unreadable when stored), cardholder name, expiration date, and service code, with sensitive authentication data never stored after authorization.
Question 5: What encryption standards does PCI DSS require for transmitting cardholder data?
- Strong cryptography protocols like TLS 1.2+ for data in transit over public networks (Correct answer)
- No encryption is required for card data transmission
- Only email encryption is required
- Encryption is only needed for storage, not transmission
Correct answer: Strong cryptography protocols like TLS 1.2+ for data in transit over public networks
PCI DSS requires strong cryptographic protocols (TLS 1.2 or higher) when transmitting cardholder data across open, public networks to prevent interception by unauthorized parties.
Question 6: What are the consequences of PCI DSS non-compliance?
- Fines from card brands, increased transaction fees, liability for breach costs, and potential loss of card processing privileges (Correct answer)
- No consequences exist for non-compliance
- Only a warning letter from the card brands
- A one-time small administrative fee
Correct answer: Fines from card brands, increased transaction fees, liability for breach costs, and potential loss of card processing privileges
Non-compliance consequences include monthly fines ($5,000-$100,000), increased per-transaction fees, liability for fraud losses and breach costs, and potential termination of the ability to accept card payments.
How many core requirements does PCI DSS contain?