PCIP Compliance Reporting 5 — Questions and Answers
Question 1: What is the role of the PCI SSC in enforcing PCI DSS compliance?
- The PCI SSC directly fines non-compliant merchants
- The PCI SSC maintains the standards; card brands and acquirers enforce compliance (Correct answer)
- The PCI SSC conducts on-site assessments of all Level 1 merchants
- The PCI SSC issues merchant IDs and can revoke them
Correct answer: The PCI SSC maintains the standards; card brands and acquirers enforce compliance
The PCI SSC develops and maintains the standards but does not enforce compliance; enforcement is the responsibility of the payment card brands and acquiring banks.
Question 2: A merchant's annual ASV scan reveals a failing vulnerability 30 days before their compliance submission deadline. What must they do?
- Submit the failing scan with an explanation letter
- Remediate the vulnerability and obtain a passing scan before submission (Correct answer)
- Request a 90-day extension from the PCI SSC
- Submit last year's passing scan results instead
Correct answer: Remediate the vulnerability and obtain a passing scan before submission
Merchants must remediate identified vulnerabilities and achieve a passing ASV scan before submitting compliance documentation, as failing scan results are not acceptable.
Question 3: Which of the following scenarios requires a merchant to immediately notify their acquiring bank outside of the normal annual reporting cycle?
- Adding a new point-of-sale terminal
- Suspecting a cardholder data breach (Correct answer)
- Hiring a new IT security manager
- Renewing their SSL certificate
Correct answer: Suspecting a cardholder data breach
Suspected or confirmed cardholder data breaches must be reported to the acquiring bank immediately, regardless of the normal annual compliance reporting schedule.
Question 4: What happens to a merchant's transaction fees or processing privileges if they remain non-compliant with PCI DSS for an extended period?
- Nothing; PCI DSS is voluntary
- Card brands may impose fines on the acquirer, who may pass them to the merchant (Correct answer)
- The merchant is automatically enrolled in a remediation program at no cost
- The PCI SSC suspends the merchant's ability to accept cards
Correct answer: Card brands may impose fines on the acquirer, who may pass them to the merchant
Card brands can assess fines against acquiring banks for non-compliant merchants, and acquirers typically pass these fines to the merchant, which may also include increased transaction fees.
Question 5: What does 'scoping' mean in the context of a PCI DSS assessment?
- Determining the physical location of the assessment
- Identifying all system components that must comply with PCI DSS (Correct answer)
- Selecting which SAQ type to use
- Scheduling the QSA's on-site visit
Correct answer: Identifying all system components that must comply with PCI DSS
Scoping is the process of identifying all system components, people, and processes included in or connected to the cardholder data environment that are subject to PCI DSS requirements.
Question 6: A Level 3 merchant that processes between 20,000 and 1 million e-commerce transactions annually must complete which validation requirement?
- Annual on-site QSA assessment and ROC
- Annual SAQ and quarterly network scans (Correct answer)
- Biannual QSA assessment
- No formal validation required
Correct answer: Annual SAQ and quarterly network scans
Level 3 merchants must complete an annual SAQ and submit passing results from quarterly network vulnerability scans conducted by an approved ASV.
Question 7: When must a compensating control be re-evaluated and documented during the PCI DSS compliance cycle?
- Only when the original control fails
- Annually, as part of each compliance assessment (Correct answer)
- Every three years during a major PCI DSS version update
- Only when the acquiring bank requests it
Correct answer: Annually, as part of each compliance assessment
Compensating controls must be reviewed and documented annually during each PCI DSS assessment to confirm they continue to adequately mitigate the risk of the requirement they replace.
What is the role of the PCI SSC in enforcing PCI DSS compliance?