PCIP Access Control 3 — Questions and Answers
Question 1: Under PCI DSS, how frequently must access rights for users with access to cardholder data be reviewed?
- Monthly
- Quarterly
- At least every six months (Correct answer)
- Annually
Correct answer: At least every six months
PCI DSS Requirement 8.1.6 requires that user access rights be reviewed at least every six months to ensure appropriateness.
Question 2: A vendor requires remote access to configure payment terminals. What PCI DSS control must be in place?
- The vendor may use a shared company VPN account
- Vendor access must be enabled only when needed and monitored while active (Correct answer)
- Vendor access is exempt from PCI DSS requirements
- Vendors must use the same credentials as internal staff
Correct answer: Vendor access must be enabled only when needed and monitored while active
PCI DSS Requirement 8.1.5 requires that vendor remote access be enabled only when needed, monitored during use, and disabled immediately after.
Question 3: Which password requirement is mandated by PCI DSS for accounts accessing the cardholder data environment?
- Minimum 6 characters with no special character requirement
- Minimum 7 characters with numeric and alphabetic characters (Correct answer)
- Minimum 10 characters with at least two special characters
- Minimum 8 characters with uppercase only
Correct answer: Minimum 7 characters with numeric and alphabetic characters
PCI DSS Requirement 8.3.6 specifies passwords must be at least 12 characters (or 8 if the system doesn't support 12), containing both numeric and alphabetic characters.
Question 4: What does PCI DSS require regarding password history to prevent password reuse?
- Users cannot reuse any of their last 3 passwords
- Users cannot reuse any of their last 4 passwords (Correct answer)
- Users cannot reuse any of their last 6 passwords
- There is no reuse restriction if passwords are changed every 30 days
Correct answer: Users cannot reuse any of their last 4 passwords
PCI DSS Requirement 8.3.7 prohibits users from submitting a new password that is the same as any of their last four passwords.
Question 5: A payment application locks user accounts after failed login attempts. What is the PCI DSS-required lockout threshold?
- 3 failed attempts
- 6 failed attempts (Correct answer)
- 10 failed attempts
- 15 failed attempts
Correct answer: 6 failed attempts
PCI DSS Requirement 8.3.4 requires that accounts be locked out after not more than six invalid access attempts.
Question 6: After an account is locked due to failed login attempts, what does PCI DSS require before the account is unlocked?
- Automatic unlock after 5 minutes
- Automatic unlock after 30 minutes, or manual reset by an administrator (Correct answer)
- Only administrator reset is allowed — no automatic unlock
- The user must submit a password reset via email
Correct answer: Automatic unlock after 30 minutes, or manual reset by an administrator
PCI DSS Requirement 8.3.4 allows accounts to be unlocked either after a lockout duration of at least 30 minutes or through administrator intervention.
Question 7: Which scenario correctly implements the PCI DSS principle of least privilege for a call center agent?
- Agent has read/write access to all cardholder records in case of escalation
- Agent can view only the last four digits of PANs needed to verify caller identity (Correct answer)
- Agent has admin rights to resolve any cardholder dispute independently
- Agent can access all transaction history for improved customer service
Correct answer: Agent can view only the last four digits of PANs needed to verify caller identity
Least privilege limits access to the minimum necessary — a call center agent only needs partial PAN data to verify identity, not full cardholder data.
Under PCI DSS, how frequently must access rights for users with access to cardholder data be reviewed?