PCIP Cardholder Data Environment 2 — Questions and Answers
Question 1: Which technique is most effective for permanently removing systems from PCI DSS scope?
- Encrypting all cardholder data stored on those systems
- Applying strong access controls to limit who can view the data
- Eliminating the storage, processing, and transmission of cardholder data on those systems (Correct answer)
- Using tokenization to replace card data with a token that is also stored on the system
Correct answer: Eliminating the storage, processing, and transmission of cardholder data on those systems
A system can only be removed from PCI DSS scope if it does not store, process, or transmit cardholder data and cannot impact the security of systems that do; encryption and access controls alone do not descope a system.
Question 2: A merchant implements a point-to-point encryption (P2PE) solution validated by the PCI SSC. What is the key benefit regarding the CDE?
- The merchant no longer needs to implement any PCI DSS controls
- The merchant's systems outside the P2PE solution are removed from CDE scope because card data is encrypted at the point of interaction (Correct answer)
- The merchant can store full PANs in plaintext once they exit the P2PE device
- All PCI DSS SAQ types become available to the merchant regardless of transaction volume
Correct answer: The merchant's systems outside the P2PE solution are removed from CDE scope because card data is encrypted at the point of interaction
A PCI-validated P2PE solution encrypts cardholder data at the point of interaction so that systems downstream that handle only encrypted data may be removed from scope, significantly reducing compliance burden.
Question 3: When scoping the CDE, which category of systems is considered 'connected-to' and therefore in scope?
- Systems that are on a separate network segment with no direct route to the CDE
- Systems that share a network segment with CDE systems or have unrestricted connectivity to them (Correct answer)
- Only systems that directly process PANs
- Any system that has internet connectivity, regardless of network placement
Correct answer: Systems that share a network segment with CDE systems or have unrestricted connectivity to them
Systems sharing a network segment with CDE systems or having unrestricted network access to CDE systems are considered in scope because they could impact the security of the CDE.
Question 4: Tokenization is used by a merchant to replace PANs with tokens in their database. Which statement accurately describes the scoping impact?
- The token vault that maps tokens to PANs is outside PCI DSS scope because it contains no raw PANs
- The merchant's systems are entirely out of scope once tokenization is deployed
- The token vault is within PCI DSS scope because it stores the mapping to cardholder data (Correct answer)
- Tokenization has no effect on PCI DSS scope
Correct answer: The token vault is within PCI DSS scope because it stores the mapping to cardholder data
The token vault that holds the mapping between tokens and real PANs is in scope for PCI DSS because it stores or provides access to actual cardholder data.
Question 5: How often must a PCI DSS–covered entity identify and document all in-scope system components as part of scoping?
- Only once during the initial assessment
- At least annually and also before any significant change to the environment (Correct answer)
- Every three years as part of the full PCI DSS recertification cycle
- Only when requested by the acquiring bank or card brand
Correct answer: At least annually and also before any significant change to the environment
PCI DSS requires entities to identify and document the scope of their CDE at least once a year and also whenever significant changes occur that could affect scope.
Question 6: A company's CDE is connected to its corporate network via a firewall. If the firewall is misconfigured and allows unrestricted traffic between the two networks, what is the implication for scope?
- The corporate network remains out of scope because the firewall is still physically present
- The corporate network systems become in scope for PCI DSS because they can impact the security of the CDE (Correct answer)
- Only the firewall itself becomes in scope; the corporate network is unaffected
- Scope is unaffected because PCI DSS does not penalize for firewall misconfigurations
Correct answer: The corporate network systems become in scope for PCI DSS because they can impact the security of the CDE
If network controls fail to properly isolate the CDE, systems on the connected network are considered in scope because they can impact the security of cardholder data systems.
Question 7: Under PCI DSS v4.0, which term describes the approach where entities implement controls that meet the intent of a requirement using methods other than those specified?
- Compensating control
- Customized approach (Correct answer)
- Targeted risk analysis
- Best-effort compliance
Correct answer: Customized approach
PCI DSS v4.0 introduced the 'customized approach,' which allows entities to implement alternative controls that achieve the security objective of a requirement using different methods than those defined.
Which technique is most effective for permanently removing systems from PCI DSS scope?