PCIP Compliance Reporting 4 — Questions and Answers
Question 1: Which of the following best describes the scope of a PCI DSS compliance assessment?
- All systems in the corporate network
- Only systems that store cardholder data
- All system components that store, process, or transmit cardholder data, plus connected systems (Correct answer)
- Only point-of-sale terminals
Correct answer: All system components that store, process, or transmit cardholder data, plus connected systems
PCI DSS scope includes all system components that store, process, or transmit cardholder data, as well as any systems that could impact the security of the cardholder data environment.
Question 2: What is the purpose of network segmentation in PCI DSS compliance reporting?
- It is required by law for all card processors
- It reduces the scope of the PCI DSS assessment (Correct answer)
- It eliminates the need for quarterly vulnerability scans
- It automatically makes a merchant Level 4
Correct answer: It reduces the scope of the PCI DSS assessment
Proper network segmentation isolates the cardholder data environment from other networks, reducing the number of systems in scope and simplifying compliance validation.
Question 3: A merchant uses a fully outsourced hosted payment page where they never receive or access cardholder data. Which SAQ type applies?
- SAQ A (Correct answer)
- SAQ B
- SAQ C-VT
- SAQ D
Correct answer: SAQ A
SAQ A applies to card-not-present merchants who have fully outsourced all cardholder data functions to PCI DSS compliant third-party service providers.
Question 4: What information must a merchant provide to their acquirer regarding third-party service providers used in their cardholder data environment?
- Nothing; service providers report directly to card brands
- A list of service providers and confirmation they are PCI DSS compliant (Correct answer)
- Copies of all service provider contracts
- The service provider's financial statements
Correct answer: A list of service providers and confirmation they are PCI DSS compliant
Merchants must maintain a list of third-party service providers and ensure those providers are PCI DSS compliant, which is often verified through the service provider's AOC.
Question 5: How long must a merchant retain documentation supporting their PCI DSS compliance validation?
- 6 months
- 1 year
- At least 1 year, per card brand requirements (Correct answer)
- 5 years
Correct answer: At least 1 year, per card brand requirements
Card brand requirements generally mandate that merchants retain PCI DSS compliance documentation for at least one year to support compliance validation inquiries.
Question 6: What is the consequence for a service provider that loses their PCI DSS compliant status mid-year?
- They must wait until annual renewal to revalidate
- They must immediately notify their clients and the acquiring banks (Correct answer)
- They are automatically removed from card brand programs
- No immediate action is required
Correct answer: They must immediately notify their clients and the acquiring banks
Service providers that lose compliance status must promptly notify their clients and acquiring banks so affected parties can take appropriate protective action.
Question 7: Which PCI DSS document type is shared with merchants by their service providers to demonstrate compliance status?
- Full Report on Compliance (ROC)
- Attestation of Compliance (AOC) (Correct answer)
- Self-Assessment Questionnaire (SAQ)
- Compensating Control Worksheet
Correct answer: Attestation of Compliance (AOC)
Service providers share their AOC with merchant clients to demonstrate their PCI DSS compliance status, as the full ROC contains sensitive security details.
Which of the following best describes the scope of a PCI DSS compliance assessment?