PCIP Assessment Procedures & Reporting Obligations 4 — Questions and Answers
Question 1: A newly identified vulnerability is rated Critical (CVSS 9.8) on a system in the CDE. Under PCI DSS Requirement 6, what is the maximum time allowed to remediate it?
- 30 days (Correct answer)
- 60 days
- 90 days
- 180 days
Correct answer: 30 days
PCI DSS requires critical vulnerabilities in the CDE to be addressed within one month (approximately 30 days) of identification.
Question 2: Which of the following findings would cause an ASV scan to result in a failing report?
- An open port running a documented and approved internal service
- An SSL 3.0 service exposed on an internet-facing IP (Correct answer)
- A web server with HTTP on port 80 that redirects to HTTPS
- An informational-level finding with no associated CVE
Correct answer: An SSL 3.0 service exposed on an internet-facing IP
SSL 3.0 is an insecure protocol and its presence on internet-facing systems constitutes a failing finding in an ASV scan per PCI DSS requirements.
Question 3: What is the role of the Forensic Investigator (PFI) in a post-breach scenario under PCI DSS?
- To conduct the next annual QSA assessment on behalf of the breached entity
- To investigate the breach and produce a forensic report for payment brands (Correct answer)
- To impose fines directly on the breached merchant
- To update the SAQ on behalf of the merchant
Correct answer: To investigate the breach and produce a forensic report for payment brands
A PCI Forensic Investigator (PFI) is engaged after a breach to investigate, determine root cause, and deliver a forensic report to the requesting payment brand.
Question 4: A QSA must re-assess a merchant within 12 months of the previous report. What triggers a requirement for an interim or unscheduled assessment?
- The merchant hiring a new CISO
- A significant infrastructure change to the CDE between assessments (Correct answer)
- A competitor suffering a data breach
- Quarterly ASV scans returning clean results
Correct answer: A significant infrastructure change to the CDE between assessments
Significant changes to the CDE—such as new systems, network architecture changes, or major application updates—require the relevant PCI DSS controls to be reassessed.
Question 5: Which PCI DSS requirement specifically mandates that service providers maintain a documented list of all entities they share cardholder data with?
- Requirement 3 (Protect Stored Account Data)
- Requirement 8 (Identify Users and Authenticate Access)
- Requirement 12 (Support Information Security with Organizational Policies) (Correct answer)
- Requirement 6 (Develop and Maintain Secure Systems)
Correct answer: Requirement 12 (Support Information Security with Organizational Policies)
Requirement 12 requires that service providers maintain a list of all entities with which they share cardholder data, including what data is shared and the purpose.
Question 6: An assessor is reviewing network segmentation to reduce PCI DSS scope. What must be verified to confirm segmentation is effective?
- That firewalls exist between all subnets in the organization
- That out-of-scope systems cannot reach CDE systems through any pathway (Correct answer)
- That the CDE is documented in a network diagram
- That all segmentation uses physical rather than logical controls
Correct answer: That out-of-scope systems cannot reach CDE systems through any pathway
Effective segmentation means that out-of-scope systems have no connectivity—direct or indirect—to CDE systems, which must be validated through penetration testing and firewall rule review.
Question 7: When is a merchant permitted to use SAQ B instead of SAQ B-IP for card-present transactions?
- When using standalone dial-out terminals not connected to any IP network (Correct answer)
- When using IP-connected terminals with point-to-point encryption
- When processing fewer than 20,000 transactions annually
- When using a hosted payment page for all transactions
Correct answer: When using standalone dial-out terminals not connected to any IP network
SAQ B applies to merchants using standalone, dial-out terminals (PSTN) that are not connected to any other systems or IP networks.
A newly identified vulnerability is rated Critical (CVSS 9.8) on a system in the CDE.
Under PCI DSS Requirement 6, what is the maximum time allowed to remediate it?