Payment Card Industry Professional (PCIP) Certification Exam — Questions and Answers
Question 1: What is the first step in a PCI DSS assessment?
- Scoping (Correct answer)
- Validation
- Reporting
- Remediation
Correct answer: Scoping
The first step in a PCI DSS (Payment Card Industry Data Security Standard) assessment is scoping. Scoping involves identifying all system components, processes, and personnel that store, process, or transmit cardholder data, or that could impact the security of the cardholder data environment (CDE). Properly defining the scope is crucial as it determines which systems and controls need to be assessed for compliance.
Question 2: Which document serves as the primary deliverable from a QSA after completing a Level 1 merchant assessment?
- Penetration Test Report
- Self-Assessment Questionnaire (SAQ)
- Attestation of Scan Compliance (ASC)
- Report on Compliance (ROC) (Correct answer)
Correct answer: Report on Compliance (ROC)
The Report on Compliance (ROC) is the formal deliverable QSAs produce for Level 1 merchant and service provider assessments.
Question 3: What is the significance of CVE (Common Vulnerabilities and Exposures) identifiers in PCI DSS vulnerability management?
- CVEs provide a standardized reference for publicly known vulnerabilities, aiding in consistent tracking (Correct answer)
- CVEs are only relevant to network-layer vulnerabilities
- CVEs replace the need for internal vulnerability scanning
- CVEs are used to assign CVSS scores to vulnerabilities
Correct answer: CVEs provide a standardized reference for publicly known vulnerabilities, aiding in consistent tracking
CVE identifiers provide a standardized naming convention for publicly known vulnerabilities, enabling consistent communication and tracking across organizations and tools.
Question 4: When is a merchant permitted to use SAQ B instead of SAQ B-IP for card-present transactions?
- When using a hosted payment page for all transactions
- When processing fewer than 20,000 transactions annually
- When using IP-connected terminals with point-to-point encryption
- When using standalone dial-out terminals not connected to any IP network (Correct answer)
Correct answer: When using standalone dial-out terminals not connected to any IP network
SAQ B applies to merchants using standalone, dial-out terminals (PSTN) that are not connected to any other systems or IP networks.
Question 5: Under PCI DSS, why is it insufficient to rely solely on database-level encryption (Transparent Data Encryption, TDE) to protect stored PANs?
- TDE only works with Oracle databases
- TDE protects data at rest on disk but may expose plaintext PANs to privileged database administrators (Correct answer)
- TDE is not approved by any payment brand
- TDE increases query latency beyond acceptable limits
Correct answer: TDE protects data at rest on disk but may expose plaintext PANs to privileged database administrators
TDE encrypts data files on disk, but authorized DBAs and applications accessing the database through normal channels still see plaintext data, so it does not meet PCI DSS requirements for access control on PANs.
Question 6: Which foundational principle is MOST important for success in the Payment Card Industry Professional profession?
- Maximizing financial returns on every engagement
- Maintaining the minimum requirements for certification
- Specializing in only one narrow area of practice
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 7: Which of the following describes a 'false negative' in the context of PCI DSS security monitoring?
- An alert triggered by legitimate activity that was flagged as malicious
- A log entry that was improperly formatted by the logging system
- An incorrectly configured firewall rule that blocks valid traffic
- A real attack that occurred but was not detected or alerted on (Correct answer)
Correct answer: A real attack that occurred but was not detected or alerted on
A false negative occurs when a genuine threat or attack goes undetected, meaning monitoring systems failed to generate an alert for a real incident.
Question 8: Which documentation is essential when working with network security in PCIP?
- General descriptions without specifics
- Marketing materials
- Detailed technical specifications and as-built diagrams (Correct answer)
- Only verbal notes
Correct answer: Detailed technical specifications and as-built diagrams
Detailed technical specifications and as-built diagrams provide the accurate reference information needed for maintenance and troubleshooting.
Question 9: Which of the following describes a penetration test methodology that is consistent with PCI DSS Requirement 11.4?
- Scanning limited to the external network perimeter only
- Automated-only scanning with no manual exploitation attempts
- Annual review of firewall rules only
- Industry-accepted approach covering network and application layers with exploitation attempts (Correct answer)
Correct answer: Industry-accepted approach covering network and application layers with exploitation attempts
PCI DSS requires penetration tests to follow an industry-accepted methodology covering both network and application layers with actual exploitation attempts.
Question 10: What is the key benefit of evidence-based decision making in PCIP management?
- It speeds up all processes
- It improves accuracy and reduces bias in decisions (Correct answer)
- It eliminates all risk
- It reduces reliance on data
Correct answer: It improves accuracy and reduces bias in decisions
Evidence-based decision making uses data and research to improve the accuracy of decisions and reduce the influence of personal bias.
Question 11: Which PCI DSS requirement specifically addresses the use of time-synchronization technology?
- Requirement 6
- Requirement 8
- Requirement 12
- Requirement 10 (Correct answer)
Correct answer: Requirement 10
Requirement 10.6 requires all systems to synchronize clocks using NTP or similar technology to ensure accurate timestamps in audit logs.
Question 12: What does PCI DSS require if an organization discovers that a cryptographic key has been or is suspected to have been compromised?
- Immediately retire the compromised key and re-encrypt all data protected by it (Correct answer)
- Archive the key in an HSM for forensic analysis without replacement
- Continue using the key while investigating to avoid service disruption
- Notify the card brands and retire the key only after the next scheduled rotation
Correct answer: Immediately retire the compromised key and re-encrypt all data protected by it
PCI DSS requires immediate retirement and replacement of a suspected compromised key and re-encryption of all data that was protected by that key.
Question 13: A QSA reviewing a merchant's PCI DSS compliance finds no documented process for responding to IDS alerts. Which requirement is violated?
- Requirement 10 — Track and Monitor All Access (Correct answer)
- Requirement 6 — Develop Secure Systems
- Requirement 3 — Protect Stored Cardholder Data
- Requirement 12 — Maintain an Information Security Policy
Correct answer: Requirement 10 — Track and Monitor All Access
Requirement 10 encompasses monitoring and requires documented processes for reviewing and responding to security alerts from detection tools.
Question 14: What distinguishes a Payment Card Industry Professional certified professional from a non-certified practitioner?
- Certification validates competency through standardized assessment against established benchmarks (Correct answer)
- Certified professionals always have more years of experience
- There is no meaningful difference in competency
- Certified professionals exclusively work in larger organizations
Correct answer: Certification validates competency through standardized assessment against established benchmarks
Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.
Question 15: An organization is preparing its Attestation of Compliance (AOC). Who is authorized to sign the merchant section of the AOC?
- The acquiring bank's compliance officer
- An officer of the merchant organization (Correct answer)
- The PCI SSC regional representative
- The lead QSA from the assessing firm
Correct answer: An officer of the merchant organization
The merchant section of the AOC must be signed by an executive officer of the merchant organization, attesting to the accuracy of the compliance information provided.
Question 16: A merchant discovers they are out of compliance after completing their annual SAQ. What is the correct first step?
- Notify law enforcement immediately
- Stop accepting card payments until fully compliant
- Inform their acquiring bank and develop a remediation plan (Correct answer)
- Conduct an internal investigation and self-certify compliance
Correct answer: Inform their acquiring bank and develop a remediation plan
Upon discovering non-compliance, merchants must notify their acquirer and work with them to develop an acceptable remediation plan with defined timelines.
Question 17: Which of the following is NOT a valid method for satisfying the PCI DSS web application security review requirement for public-facing applications?
- Automated web application vulnerability scanning
- Network-layer penetration test only (Correct answer)
- Manual code review by a qualified specialist
- Installation of a web application firewall
Correct answer: Network-layer penetration test only
A network-layer penetration test alone does not satisfy the web application security review requirement, which demands application-layer assessment via WAF, code review, or web app scanning.
Question 18: Which of the following actions is considered a violation of proper incident response evidence handling procedures?
- Documenting all actions taken on compromised systems
- Photographing the screen before shutting down a suspect system
- Running antivirus scans directly on the original compromised drive (Correct answer)
- Creating a write-protected forensic image before analysis
Correct answer: Running antivirus scans directly on the original compromised drive
Running antivirus or any tool directly on the original compromised drive can alter or destroy evidence; always work from a forensic copy.
Question 19: When engaging a PFI (PCI Forensic Investigator), who is responsible for initiating the engagement after a confirmed cardholder data breach?
- The card brands directly
- The card-issuing bank
- The breached merchant or service provider (Correct answer)
- The federal government
Correct answer: The breached merchant or service provider
The breached entity (merchant or service provider) is responsible for immediately engaging a PFI upon confirmation of a cardholder data compromise.
Question 20: What is the correct classification of expiration date under PCI DSS data storage rules?
- Sensitive Authentication Data that must never be stored post-authorization
- Cardholder data that may be stored if protected according to PCI DSS requirements (Correct answer)
- Sensitive Authentication Data that may be stored with proper encryption
- Non-sensitive data that has no storage restrictions under PCI DSS
Correct answer: Cardholder data that may be stored if protected according to PCI DSS requirements
The expiration date is classified as cardholder data (not SAD) and may be stored post-authorization as long as it is protected in accordance with applicable PCI DSS requirements.
Question 21: Which of the following is an example of 'something you have' in multi-factor authentication for CDE access?
- A password
- A security question answer
- A hardware token generating one-time codes (Correct answer)
- A fingerprint scan
Correct answer: A hardware token generating one-time codes
A hardware token is a possession factor ('something you have'), distinct from knowledge factors (passwords) and inherence factors (biometrics).
Question 22: What does PCI DSS require regarding password history to prevent password reuse?
- Users cannot reuse any of their last 3 passwords
- There is no reuse restriction if passwords are changed every 30 days
- Users cannot reuse any of their last 4 passwords (Correct answer)
- Users cannot reuse any of their last 6 passwords
Correct answer: Users cannot reuse any of their last 4 passwords
PCI DSS Requirement 8.3.7 prohibits users from submitting a new password that is the same as any of their last four passwords.
Question 23: Which of the following best describes 'envelope encryption' as used in cloud-based cardholder data storage?
- Encrypting a DEK with a KEK and storing the wrapped DEK alongside the ciphertext (Correct answer)
- Using multiple layers of hashing before encryption
- Sending encrypted data inside a TLS tunnel
- Encrypting data with a public key and sending it via email
Correct answer: Encrypting a DEK with a KEK and storing the wrapped DEK alongside the ciphertext
Envelope encryption wraps the data-encrypting key (DEK) with a key-encrypting key (KEK), storing the wrapped DEK with the ciphertext so only KEK holders can decrypt.
Question 24: A payment application locks user accounts after failed login attempts. What is the PCI DSS-required lockout threshold?
- 15 failed attempts
- 3 failed attempts
- 10 failed attempts
- 6 failed attempts (Correct answer)
Correct answer: 6 failed attempts
PCI DSS Requirement 8.3.4 requires that accounts be locked out after not more than six invalid access attempts.
Question 25: In Payment Card Industry Professional practice, what is the FIRST step when a safety hazard is identified in the workplace?
- Continue working and report at end of shift
- Wait for a supervisor to notice the issue
- Immediately secure the area and report the hazard (Correct answer)
- Document it for the next safety audit
Correct answer: Immediately secure the area and report the hazard
When a safety hazard is identified, the immediate priority is to secure the area to prevent injury and report the hazard through proper channels. Delaying action increases the risk of incidents.
Question 26: Which of the following is a key deliverable from a PFI (PCI Forensic Investigator) engagement?
- A new incident response plan for the breached entity
- A penetration test report of the environment
- A forensic investigation report documenting findings and scope of compromise (Correct answer)
- A remediation roadmap for PCI DSS compliance
Correct answer: A forensic investigation report documenting findings and scope of compromise
The PFI's primary deliverable is a forensic investigation report that documents the attack timeline, scope of compromise, and evidence gathered.
Question 27: In PCIP practice, reliability in assessment refers to:
- The popularity of the instrument
- The speed of administration
- The cost of the assessment tool
- The consistency and reproducibility of results (Correct answer)
Correct answer: The consistency and reproducibility of results
Reliability refers to the consistency and reproducibility of assessment results when the test is repeated under similar conditions.
Question 28: What is the MOST effective way for new PCIP professionals to build competency in their field?
- Studying certification materials exclusively
- Learning entirely through trial and error
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Focusing solely on the most advanced topics
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 29: A service provider that stores cardholder data on behalf of 50 merchants suffers a breach. Which entities are primarily responsible for notifying affected card brands?
- Each of the 50 individual merchants separately
- The card-issuing banks of affected cardholders
- Only the federal government authorities
- The breached service provider and each merchant's acquirer (Correct answer)
Correct answer: The breached service provider and each merchant's acquirer
Both the breached service provider and the acquirers of affected merchants share notification obligations to the card brands under PCI DSS breach response requirements.
Question 30: Which risk management approach is MOST effective for PCIP professionals when evaluating potential workplace hazards?
- Reactive analysis after incidents occur
- Delegating all safety decisions to management
- Relying solely on historical accident data
- Proactive hazard identification and assessment (Correct answer)
Correct answer: Proactive hazard identification and assessment
Proactive hazard identification and assessment allows professionals to identify and mitigate risks before incidents occur, which is far more effective than reactive approaches that only address problems after they happen.
Question 31: Which scenario correctly implements the PCI DSS principle of least privilege for a call center agent?
- Agent can view only the last four digits of PANs needed to verify caller identity (Correct answer)
- Agent has admin rights to resolve any cardholder dispute independently
- Agent has read/write access to all cardholder records in case of escalation
- Agent can access all transaction history for improved customer service
Correct answer: Agent can view only the last four digits of PANs needed to verify caller identity
Least privilege limits access to the minimum necessary — a call center agent only needs partial PAN data to verify identity, not full cardholder data.
Question 32: Which PCI DSS requirement mandates that a formal risk assessment be performed at least annually?
- Requirement 12 (Correct answer)
- Requirement 10
- Requirement 6
- Requirement 8
Correct answer: Requirement 12
PCI DSS Requirement 12.3 requires that a risk assessment be performed at least annually and upon significant changes to the environment.
Question 33: Which network model layers data communication into 7 layers?
- WPA2
- IPV6
- OSI model (Correct answer)
- TCP/IP
Correct answer: OSI model
The OSI (Open Systems Interconnection) model is a conceptual framework that standardizes the functions of a telecommunication or computing system into seven distinct layers. Each layer performs specific tasks, from the physical transmission of data (Layer 1) to application-level services (Layer 7). This layered approach helps in understanding, designing, and troubleshooting network architectures.
Question 34: How often should PCIP compliance training be conducted?
- Every five years
- Only when violations occur
- At regular intervals as required by regulations (Correct answer)
- Only during initial orientation
Correct answer: At regular intervals as required by regulations
Compliance training must be conducted at regular intervals as specified by applicable regulations to keep practitioners current.
Question 35: Which action is required after a failed assessment?
- Report only part of the findings
- Ignore the results
- Remediate and reassess (Correct answer)
- Start over after one year
Correct answer: Remediate and reassess
If an organization fails a PCI DSS assessment, the required action is to remediate the identified non-compliance issues and then undergo a reassessment. Simply ignoring the results or waiting a year is not an option, as non-compliance can lead to fines, penalties, and potential loss of card processing privileges. The goal is to achieve full compliance to protect cardholder data.
Question 36: Which PCI DSS requirement mandates that anti-malware solutions be kept current and capable of generating audit logs?
- Requirement 3
- Requirement 5 (Correct answer)
- Requirement 10
- Requirement 7
Correct answer: Requirement 5
Requirement 5 requires that anti-malware mechanisms be deployed, maintained with current definitions, and configured to generate logs that are retained per organizational policy.
Question 37: What does an Attestation of Compliance (AOC) confirm?
- That vulnerabilities have been fully remediated
- That the QSA has been paid for their services
- That the entity has accurately represented its PCI DSS compliance status (Correct answer)
- That the network scan passed all requirements
Correct answer: That the entity has accurately represented its PCI DSS compliance status
The AOC is a declaration signed by both the merchant/service provider and the QSA confirming that the compliance information in the ROC or SAQ is accurate.
Question 38: A PCIP reviews a risk assessment that omits insider threat scenarios. This is a gap because:
- Qualitative assessments never include insider threat modeling
- Insider threats are covered by HR policies, not risk assessments
- Insider threats represent a significant and commonly exploited attack vector for cardholder data theft (Correct answer)
- PCI DSS only requires external threat scenarios
Correct answer: Insider threats represent a significant and commonly exploited attack vector for cardholder data theft
Insider threats are a well-documented risk to cardholder data environments and must be included in comprehensive PCI DSS risk assessments.
Question 39: Under PCI DSS incident response requirements, which personnel role is responsible for approving and activating the incident response plan?
- The frontline IT helpdesk staff
- External legal counsel
- The acquiring bank's representative
- The designated Incident Response Team lead or CISO (Correct answer)
Correct answer: The designated Incident Response Team lead or CISO
The Incident Response Team lead or CISO typically holds authority to declare an incident and formally activate the incident response plan.
Question 40: A PCIP professional discovers a conflict of interest in a current assignment. What is the MOST ethical course of action?
- Disclose the conflict immediately and recuse if necessary (Correct answer)
- Ignore it if no one else has noticed
- Handle it privately without informing stakeholders
- Continue the assignment but document the conflict later
Correct answer: Disclose the conflict immediately and recuse if necessary
Ethical standards require immediate disclosure of conflicts of interest. Transparency protects both the professional's integrity and the stakeholders' interests. Recusal may be necessary to maintain objectivity.
Question 41: Which principle states that users should only have access necessary for their role?
- Need to share
- Principle of least privilege (Correct answer)
- Defense in depth
- Separation of duties
Correct answer: Principle of least privilege
The principle of least privilege ensures users only have the minimum access rights needed to perform their job functions, limiting potential damage.
Question 42: A PCIP certified professional is asked to provide services outside their scope of competence. The CORRECT ethical response is to:
- Accept and learn as they go
- Accept but charge a lower rate
- Accept the work to gain new experience
- Decline and refer to a qualified professional (Correct answer)
Correct answer: Decline and refer to a qualified professional
Ethical practice requires professionals to work within their scope of competence. Accepting work beyond one's qualifications can lead to substandard results and potential harm. Referring to qualified professionals ensures proper service delivery.
Question 43: Which element is NOT typically included in a PCI DSS incident response plan?
- Communication procedures for notifying stakeholders
- Procedures for preserving evidence
- Quarterly employee performance reviews (Correct answer)
- Roles and responsibilities of response team members
Correct answer: Quarterly employee performance reviews
Performance reviews are an HR function unrelated to incident response; IRP elements focus on response roles, communication, evidence handling, and recovery procedures.
Question 44: A company wants to allow a third-party service provider to access the CDE for maintenance. Which control is MOST critical under PCI DSS?
- Allowing access only during business hours without additional controls
- Implementing time-limited access with MFA and logging all activity (Correct answer)
- Ensuring the provider uses a Mac OS device
- Providing the provider with permanent VPN credentials
Correct answer: Implementing time-limited access with MFA and logging all activity
Third-party CDE access must be time-limited, require MFA, and have all activities logged to maintain accountability and minimize risk.
Question 45: During a risk assessment, the likelihood of a SQL injection attack is rated 'High' and the impact is rated 'High.' According to a standard risk matrix, what is the resulting risk level?
- Medium
- Low
- Critical (Correct answer)
- High
Correct answer: Critical
A High likelihood combined with High impact produces a Critical (or highest-tier) risk rating on a standard 4×4 or 5×5 risk matrix.
Question 46: A merchant completes an SAQ and finds one requirement partially met. What should they do with the Attestation of Compliance (AOC)?
- Submit the AOC with only passing requirements listed
- Do not sign the AOC until full compliance is achieved (Correct answer)
- Sign the AOC and note the partial finding in an addendum
- Ask their acquirer to waive the failing requirement
Correct answer: Do not sign the AOC until full compliance is achieved
An AOC should only be signed when the entity is fully compliant; partial compliance means the AOC cannot be legitimately signed.
Question 47: Which document typically outlines the compliance requirements for PCIP professionals?
- Annual financial report
- Standards of practice and code of conduct (Correct answer)
- Marketing brochure
- Employee handbook
Correct answer: Standards of practice and code of conduct
Standards of practice and codes of conduct define the professional and ethical requirements practitioners must follow.
Question 48: What is the PRIMARY ethical obligation of a certified Payment Card Industry Professional professional regarding confidential information?
- Share it with colleagues who might benefit
- Use it to advance career opportunities
- Protect it from unauthorized disclosure at all times (Correct answer)
- Discuss it informally during professional networking
Correct answer: Protect it from unauthorized disclosure at all times
Confidentiality is a fundamental ethical obligation. Certified professionals must protect confidential information from unauthorized disclosure, regardless of circumstances. Breach of confidentiality can result in loss of certification and legal liability.
Question 49: Which of the following BEST describes the purpose of network segmentation in the context of PCI DSS risk reduction?
- It eliminates all vulnerabilities within the cardholder data environment
- It reduces the scope and attack surface of the cardholder data environment (Correct answer)
- It satisfies all Requirement 12 obligations automatically
- It transfers risk to the network infrastructure vendor
Correct answer: It reduces the scope and attack surface of the cardholder data environment
Network segmentation limits the CDE scope by isolating cardholder data systems, thereby reducing the number of systems subject to PCI DSS requirements and the overall attack surface.
Question 50: Which authentication factor is classified as "something you are"?
- Password
- Security token
- Smart card
- Biometric data (Correct answer)
Correct answer: Biometric data
Biometric data such as fingerprints, facial recognition, or retinal scans represents the "something you are" authentication factor.
Question 51: What is the compliance reporting obligation for a newly identified service provider that stores cardholder data?
- They must immediately submit an AOC to the card brands
- No reporting is required until their first data breach
- They have 180 days before reporting is required
- They must begin working toward compliance immediately and report by the acquirer's deadline (Correct answer)
Correct answer: They must begin working toward compliance immediately and report by the acquirer's deadline
Newly identified service providers must begin PCI DSS compliance efforts immediately and meet reporting deadlines set by their acquiring bank or card brand.
Question 52: What does PCI DSS require when cryptographic keys used for access control are compromised or suspected of compromise?
- Keys should be rotated at the next scheduled key rotation cycle
- The system should be taken offline pending a forensic review
- Keys must be retired and replaced immediately (Correct answer)
- Keys should be backed up and then rotated within 30 days
Correct answer: Keys must be retired and replaced immediately
PCI DSS Requirement 3.7.4 requires that compromised or suspected compromised cryptographic keys be retired and replaced immediately.
Question 53: During a PCI DSS incident investigation, which log source is most critical for tracing unauthorized access to the cardholder data environment?
- Marketing analytics logs
- Application performance logs
- Authentication and access logs (Correct answer)
- Employee time-tracking logs
Correct answer: Authentication and access logs
Authentication and access logs reveal who accessed the cardholder data environment and when, making them essential for tracing unauthorized access.
Question 54: Under PCI DSS, which of the following must be prohibited for traffic flowing into the CDE from the internet?
- DNS queries to a CDE-hosted authoritative DNS server
- HTTPS traffic on port 443 to a payment web server
- Direct inbound connections from the internet to internal IP addresses in the CDE without passing through a DMZ (Correct answer)
- Encrypted API calls from partner payment processors
Correct answer: Direct inbound connections from the internet to internal IP addresses in the CDE without passing through a DMZ
PCI DSS Requirement 1.3 prohibits direct internet access to CDE systems; all inbound internet traffic must pass through a DMZ or other demarcation layer before reaching internal CDE systems.
Question 55: What is the purpose of network segmentation in PCI DSS compliance reporting?
- It automatically makes a merchant Level 4
- It is required by law for all card processors
- It eliminates the need for quarterly vulnerability scans
- It reduces the scope of the PCI DSS assessment (Correct answer)
Correct answer: It reduces the scope of the PCI DSS assessment
Proper network segmentation isolates the cardholder data environment from other networks, reducing the number of systems in scope and simplifying compliance validation.
Question 56: Which of the following is a valid compensating control for an entity that cannot implement MFA due to a technical constraint in a legacy system?
- Documenting the exception and accepting the risk permanently
- Replacing MFA with monthly password rotation
- Requiring users to verbally confirm their identity before login
- Implementing additional layers such as IP whitelisting, enhanced monitoring, and strict physical access controls with documented justification (Correct answer)
Correct answer: Implementing additional layers such as IP whitelisting, enhanced monitoring, and strict physical access controls with documented justification
Compensating controls must provide equivalent security and be documented in the entity's Risk Assessment and Compensating Control Worksheet — additional technical and physical controls can substitute for MFA.
Question 57: After eradicating malware from a compromised system in the CDE, what must be verified before returning the system to production?
- The system has the latest marketing software installed
- The system is clean, patched, and all vulnerabilities are remediated (Correct answer)
- The system's performance benchmarks are restored to baseline
- All employee accounts on the system have been reset to default passwords
Correct answer: The system is clean, patched, and all vulnerabilities are remediated
Before restoring a system, organizations must verify it is free of malware, fully patched, and all exploited vulnerabilities are remediated to prevent reinfection.
Question 58: Which password requirement is mandated by PCI DSS for accounts accessing the cardholder data environment?
- Minimum 6 characters with no special character requirement
- Minimum 7 characters with numeric and alphabetic characters (Correct answer)
- Minimum 10 characters with at least two special characters
- Minimum 8 characters with uppercase only
Correct answer: Minimum 7 characters with numeric and alphabetic characters
PCI DSS Requirement 8.3.6 specifies passwords must be at least 12 characters (or 8 if the system doesn't support 12), containing both numeric and alphabetic characters.
Question 59: A merchant discovers that its third-party delivery application is storing full PANs in plaintext log files. Under PCI DSS, which immediate action is the HIGHEST priority?
- Stop the storage of full PANs and delete existing plaintext log data (Correct answer)
- Encrypt the log files using AES-128
- Rotate all encryption keys used by the application
- Notify the card brands within 24 hours
Correct answer: Stop the storage of full PANs and delete existing plaintext log data
PCI DSS Requirement 3 prohibits storing sensitive authentication data after authorization; the immediate priority is to cease the prohibited storage and purge existing data.
Question 60: An organization running cardholder data environment systems on a shared hosting provider—who is responsible for ensuring vulnerability scans meet PCI DSS requirements?
- The card brands assume responsibility for shared hosting environments
- The hosting provider bears full responsibility
- The merchant retains compliance responsibility but may rely on the provider's scans if documented (Correct answer)
- Responsibility is split 50/50 between merchant and provider automatically
Correct answer: The merchant retains compliance responsibility but may rely on the provider's scans if documented
Merchants retain PCI DSS compliance responsibility even in shared hosting environments and must ensure scans meet requirements, whether performed by them or documented from the provider.
Payment Card Industry Professional (PCIP) Certification Exam
The PCIP certification validates an individual's knowledge and understanding of the PCI Data Security Standard (PCI DSS) and its application in securing payment card data.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds