PCIP Assessment Procedures & Reporting Obligations 3 — Questions and Answers
Question 1: A QSA is assessing a cloud service provider that hosts cardholder data. The cloud provider claims certain PCI DSS controls are the customer's responsibility. What document should define this responsibility split?
- The cloud provider's SLA
- A Responsibility Matrix or shared responsibility documentation (Correct answer)
- The customer's SAQ
- The PCI SSC's cloud computing guidelines only
Correct answer: A Responsibility Matrix or shared responsibility documentation
A shared responsibility matrix clearly delineates which PCI DSS controls are owned by the cloud provider versus the customer.
Question 2: Which SAQ type is appropriate for e-commerce merchants that fully outsource payment processing and never receive cardholder data electronically?
- SAQ A (Correct answer)
- SAQ B
- SAQ C
- SAQ D
Correct answer: SAQ A
SAQ A applies to card-not-present merchants who have fully outsourced all cardholder data functions to a PCI DSS-compliant third party.
Question 3: What is the maximum number of days a service provider has to notify acquirers of a suspected or confirmed cardholder data compromise under typical payment brand rules?
- 3 days (Correct answer)
- 7 days
- 15 days
- 30 days
Correct answer: 3 days
Payment brands generally require notification within 3 days (72 hours) of discovering a suspected or confirmed cardholder data compromise.
Question 4: During a penetration test required by PCI DSS, what is the minimum scope that must be tested?
- Only externally facing systems
- Segmentation controls and all CDE system components (Correct answer)
- Only internal network segments
- Only servers that store PANs
Correct answer: Segmentation controls and all CDE system components
PCI DSS penetration testing must cover all CDE components and validate that segmentation controls effectively isolate the CDE from out-of-scope systems.
Question 5: A Level 2 merchant transitions to Level 1 after processing volume increases. What new compliance reporting obligation is triggered?
- Annual SAQ submission replaces the ROC
- An annual on-site assessment by a QSA producing a ROC (Correct answer)
- Quarterly ASV scans are no longer required
- They must self-attest using SAQ D only
Correct answer: An annual on-site assessment by a QSA producing a ROC
Level 1 merchants must undergo an annual on-site assessment conducted by a QSA resulting in a Report on Compliance (ROC).
Question 6: When a QSA finds a compensating control in use, what must be included in the ROC to satisfy PCI DSS documentation requirements?
- Only a brief note that a compensating control exists
- A completed Compensating Control Worksheet explaining the constraint, objective, risk, and control details (Correct answer)
- A letter from the merchant's CEO approving the control
- An approval stamp from the PCI SSC
Correct answer: A completed Compensating Control Worksheet explaining the constraint, objective, risk, and control details
PCI DSS requires a fully completed Compensating Control Worksheet (CCW) that documents the constraint, objective met, identified risk, and definition of the compensating control.
Question 7: An internal security assessor (ISA) completes a PCI DSS assessment for their employer. Who must review and sign the resulting AOC?
- The ISA and an external QSA
- An officer of the assessed company (Correct answer)
- The PCI SSC Quality Assurance team
- The merchant's acquirer
Correct answer: An officer of the assessed company
The AOC for ISA-led assessments must be signed by an officer of the company, attesting to the accuracy of the assessment results.
A QSA is assessing a cloud service provider that hosts cardholder data.
The cloud provider claims certain PCI DSS controls are the customer's responsibility.
What document should define this responsibility split?