PCIP Compliance Reporting 2 — Questions and Answers
Question 1: Which entity is responsible for validating a Level 1 merchant's PCI DSS compliance?
- Internal security team only
- Qualified Security Assessor (QSA) (Correct answer)
- Payment processor automatically
- Card brand directly
Correct answer: Qualified Security Assessor (QSA)
Level 1 merchants must undergo an annual on-site assessment conducted by a QSA to validate PCI DSS compliance.
Question 2: What is the primary purpose of the Report on Compliance (ROC)?
- Marketing document for security certifications
- Detailed assessment report documenting PCI DSS compliance findings (Correct answer)
- Summary of vulnerabilities for remediation
- Annual financial audit report
Correct answer: Detailed assessment report documenting PCI DSS compliance findings
The ROC is a detailed document completed by a QSA that records the results of a PCI DSS assessment and confirms compliance status.
Question 3: How frequently must a Level 2 merchant using a SAQ submit compliance validation to their acquiring bank?
- Monthly
- Quarterly
- Annually (Correct answer)
- Every two years
Correct answer: Annually
Level 2 merchants must submit their SAQ and Attestation of Compliance (AOC) to their acquirer on an annual basis.
Question 4: What does an Attestation of Compliance (AOC) confirm?
- That vulnerabilities have been fully remediated
- That the entity has accurately represented its PCI DSS compliance status (Correct answer)
- That the QSA has been paid for their services
- That the network scan passed all requirements
Correct answer: That the entity has accurately represented its PCI DSS compliance status
The AOC is a declaration signed by both the merchant/service provider and the QSA confirming that the compliance information in the ROC or SAQ is accurate.
Question 5: A service provider that stores cardholder data processes 300,000 transactions annually. What merchant level does this classify them as?
- Level 1 (Correct answer)
- Level 2
- Level 3
- Level 4
Correct answer: Level 1
Service providers storing, processing, or transmitting cardholder data for more than 300,000 transactions annually are classified as Level 1.
Question 6: Which of the following is NOT a required component of a complete PCI DSS compliance submission?
- Completed SAQ or ROC
- Attestation of Compliance (AOC)
- Passing ASV scan results (where applicable)
- Penetration testing executive summary (Correct answer)
Correct answer: Penetration testing executive summary
While penetration testing is a PCI DSS requirement, the penetration test executive summary is not a standard required component of the compliance submission package.
Question 7: What action must a merchant take if they cannot meet a specific PCI DSS requirement by the compliance deadline?
- Simply document the gap and continue operating
- Implement a compensating control and document it in the ROC (Correct answer)
- Request a permanent waiver from the card brands
- Cease processing card payments immediately
Correct answer: Implement a compensating control and document it in the ROC
When a merchant cannot meet a specific requirement due to legitimate technical or business constraints, they may implement a compensating control that provides equivalent protection.
Which entity is responsible for validating a Level 1 merchant's PCI DSS compliance?