PCIP Assessment Procedures & Reporting Obligations 2 — Questions and Answers
Question 1: During a PCI DSS assessment, a QSA discovers that a merchant stores full PANs in plaintext log files. What is the correct reporting action?
- Log it as a compensating control
- Mark the requirement as 'Not in Place' and document findings (Correct answer)
- Allow 90 days to remediate before noting it
- Exclude log files from scope since they are temporary
Correct answer: Mark the requirement as 'Not in Place' and document findings
When a control is not met, the QSA must mark it 'Not in Place' and document the specific finding in the ROC.
Question 2: Which document serves as the primary deliverable from a QSA after completing a Level 1 merchant assessment?
- Self-Assessment Questionnaire (SAQ)
- Report on Compliance (ROC) (Correct answer)
- Attestation of Scan Compliance (ASC)
- Penetration Test Report
Correct answer: Report on Compliance (ROC)
The Report on Compliance (ROC) is the formal deliverable QSAs produce for Level 1 merchant and service provider assessments.
Question 3: A merchant completes an SAQ and finds one requirement partially met. What should they do with the Attestation of Compliance (AOC)?
- Sign the AOC and note the partial finding in an addendum
- Do not sign the AOC until full compliance is achieved (Correct answer)
- Submit the AOC with only passing requirements listed
- Ask their acquirer to waive the failing requirement
Correct answer: Do not sign the AOC until full compliance is achieved
An AOC should only be signed when the entity is fully compliant; partial compliance means the AOC cannot be legitimately signed.
Question 4: How often must an Approved Scanning Vendor (ASV) scan be performed for PCI DSS external vulnerability scanning requirements?
- Annually
- Semi-annually
- Quarterly (Correct answer)
- Monthly
Correct answer: Quarterly
PCI DSS requires external vulnerability scans by an ASV to be performed at least quarterly.
Question 5: A service provider fails an ASV scan but has implemented a compensating control. What is the correct procedure?
- Submit the failing scan report with a compensating control worksheet (Correct answer)
- Rescan until the vulnerability is resolved before submitting
- Request the ASV remove the finding from the report
- Self-certify the control as passing based on internal testing
Correct answer: Submit the failing scan report with a compensating control worksheet
Failing scan results with compensating controls must be submitted with supporting documentation including a completed compensating control worksheet.
Question 6: What is the purpose of the 'scoping' phase in a PCI DSS assessment?
- To identify which systems store, process, or transmit cardholder data (Correct answer)
- To determine how many QSAs are needed for the audit
- To set the budget for remediation activities
- To review historical compliance reports
Correct answer: To identify which systems store, process, or transmit cardholder data
Scoping identifies all system components that store, process, or transmit cardholder data or are connected to such systems, defining the cardholder data environment (CDE).
Question 7: Under PCI DSS, which entity is responsible for reporting a data breach involving cardholder data to the payment brands?
- The QSA who conducted the last assessment
- The merchant or service provider that experienced the breach (Correct answer)
- The card-issuing bank
- The PCI SSC directly
Correct answer: The merchant or service provider that experienced the breach
The entity experiencing the breach (merchant or service provider) is responsible for notifying payment brands and acquiring banks per their contractual and PCI DSS obligations.
During a PCI DSS assessment, a QSA discovers that a merchant stores full PANs in plaintext log files.
What is the correct reporting action?