PCIP Access Control 4 — Questions and Answers
Question 1: A company uses a shared service account for automated batch processing in the CDE. What PCI DSS requirement applies to this account?
- Service accounts are exempt from PCI DSS password policies
- Service accounts must have unique IDs and their passwords managed per PCI DSS password policy (Correct answer)
- Service accounts can share credentials if access is logged
- Service accounts only need to be reviewed annually
Correct answer: Service accounts must have unique IDs and their passwords managed per PCI DSS password policy
PCI DSS Requirement 8.2 applies to all accounts including service accounts — each must have a unique ID and comply with password management requirements.
Question 2: What is the maximum session idle timeout PCI DSS requires for interactive sessions accessing the cardholder data environment?
- 5 minutes
- 10 minutes
- 15 minutes (Correct answer)
- 30 minutes
Correct answer: 15 minutes
PCI DSS Requirement 8.2.8 requires that sessions be re-authenticated after no more than 15 minutes of inactivity.
Question 3: Which of the following is an example of 'something you have' in multi-factor authentication for CDE access?
- A password
- A fingerprint scan
- A hardware token generating one-time codes (Correct answer)
- A security question answer
Correct answer: A hardware token generating one-time codes
A hardware token is a possession factor ('something you have'), distinct from knowledge factors (passwords) and inherence factors (biometrics).
Question 4: Under PCI DSS, which of the following best describes how group or shared accounts should be handled in the CDE?
- Allowed if each use is logged in a separate manual log
- Prohibited — each user must have a unique account (Correct answer)
- Permitted for non-administrative functions only
- Allowed for temporary contractors with manager approval
Correct answer: Prohibited — each user must have a unique account
PCI DSS Requirement 8.2.1 prohibits group, shared, or generic user IDs and passwords in the cardholder data environment.
Question 5: A database administrator needs emergency access to production cardholder data outside normal business hours. What PCI DSS control is most appropriate?
- Issue a permanent elevated account for faster response
- Use a break-glass account with full logging, requiring post-access review (Correct answer)
- Allow the DBA to use a colleague's credentials with verbal approval
- Temporarily disable access controls until the issue is resolved
Correct answer: Use a break-glass account with full logging, requiring post-access review
Break-glass (emergency) accounts must be tightly controlled with complete logging and a mandatory review process after use to maintain PCI DSS compliance.
Question 6: What does PCI DSS require when cryptographic keys used for access control are compromised or suspected of compromise?
- Keys should be rotated at the next scheduled key rotation cycle
- Keys must be retired and replaced immediately (Correct answer)
- The system should be taken offline pending a forensic review
- Keys should be backed up and then rotated within 30 days
Correct answer: Keys must be retired and replaced immediately
PCI DSS Requirement 3.7.4 requires that compromised or suspected compromised cryptographic keys be retired and replaced immediately.
Question 7: Which PCI DSS requirement addresses the need to restrict logical access to audit logs in the CDE?
- Requirement 6 — Develop and maintain secure systems
- Requirement 10 — Log and monitor all access to system components and cardholder data (Correct answer)
- Requirement 8 — Identify users and authenticate access to system components
- Requirement 12 — Support information security with organizational policies
Correct answer: Requirement 10 — Log and monitor all access to system components and cardholder data
PCI DSS Requirement 10 covers logging and monitoring, including protecting audit logs from modification and restricting access to only those with a job-related need.
A company uses a shared service account for automated batch processing in the CDE.
What PCI DSS requirement applies to this account?