PCIP Incident Response 2 — Questions and Answers
Question 1: According to PCI DSS, within how many hours must a payment card brand be notified after confirming a security incident involving cardholder data?
- 12 hours
- 24 hours (Correct answer)
- 48 hours
- 72 hours
Correct answer: 24 hours
PCI DSS requires entities to notify their acquirer and applicable payment brands within 24 hours of confirming a cardholder data incident.
Question 2: Which type of forensic investigation approach involves capturing and analyzing a full bit-for-bit image of a compromised system's storage?
- Live forensics
- Disk imaging (Correct answer)
- Log aggregation
- Memory dump analysis
Correct answer: Disk imaging
Disk imaging creates an exact bit-for-bit copy of storage media, preserving all data including deleted files for forensic analysis.
Question 3: During a PCI DSS incident investigation, which log source is most critical for tracing unauthorized access to the cardholder data environment?
- Marketing analytics logs
- Authentication and access logs (Correct answer)
- Application performance logs
- Employee time-tracking logs
Correct answer: Authentication and access logs
Authentication and access logs reveal who accessed the cardholder data environment and when, making them essential for tracing unauthorized access.
Question 4: What is the primary purpose of a 'lessons learned' session conducted after resolving a payment card security incident?
- To assign blame to responsible employees
- To identify improvements to prevent recurrence (Correct answer)
- To calculate the financial cost of the breach
- To prepare the public press release
Correct answer: To identify improvements to prevent recurrence
Lessons learned sessions focus on identifying control gaps and process improvements to strengthen defenses and prevent similar incidents.
Question 5: A merchant discovers malware on a POS terminal that was exfiltrating track data. Which containment action should be taken FIRST?
- Reformat the POS terminal immediately
- Isolate the affected POS terminal from the network (Correct answer)
- Interview all cashiers who used the terminal
- Replace all payment cards swiped at that terminal
Correct answer: Isolate the affected POS terminal from the network
Network isolation of the affected terminal stops ongoing data exfiltration before any other remediation steps are taken.
Question 6: Which PCI DSS requirement specifically mandates that organizations maintain and implement an incident response plan?
- Requirement 6
- Requirement 10
- Requirement 12 (Correct answer)
- Requirement 8
Correct answer: Requirement 12
PCI DSS Requirement 12.10 mandates that organizations implement an incident response plan and be prepared to respond immediately to a system breach.
Question 7: During incident response, what does 'chain of custody' documentation ensure in the context of collected evidence?
- Evidence is encrypted before storage
- Evidence integrity and admissibility in legal proceedings (Correct answer)
- Evidence is shared with all stakeholders
- Evidence is deleted after the case is closed
Correct answer: Evidence integrity and admissibility in legal proceedings
Chain of custody documentation tracks who handled evidence and when, ensuring its integrity and admissibility in potential legal or regulatory proceedings.
According to PCI DSS, within how many hours must a payment card brand be notified after confirming a security incident involving cardholder data?