PCIP Incident Response 4 — Questions and Answers
Question 1: Which of the following is a key deliverable from a PFI (PCI Forensic Investigator) engagement?
- A remediation roadmap for PCI DSS compliance
- A forensic investigation report documenting findings and scope of compromise (Correct answer)
- A new incident response plan for the breached entity
- A penetration test report of the environment
Correct answer: A forensic investigation report documenting findings and scope of compromise
The PFI's primary deliverable is a forensic investigation report that documents the attack timeline, scope of compromise, and evidence gathered.
Question 2: A hotel discovers that its property management system was exfiltrating PANs to an external server for the past two months. What is the estimated minimum number of cards that must be assessed for potential compromise?
- Only cards used in the 24 hours before discovery
- All cards processed since the first day the malware was active (Correct answer)
- Only cards belonging to loyalty program members
- Cards used at peak occupancy periods only
Correct answer: All cards processed since the first day the malware was active
All payment cards processed during the entire window of compromise must be considered potentially at risk, starting from when the malware first became active.
Question 3: What is 'dwell time' in the context of a payment card breach investigation?
- The time it takes to reimage a compromised server
- The period between initial compromise and detection of the breach (Correct answer)
- The duration of the forensic investigation
- The time cardholders wait for replacement cards
Correct answer: The period between initial compromise and detection of the breach
Dwell time refers to the period an attacker remains undetected within the environment, from initial compromise through detection.
Question 4: Which containment strategy segments a compromised system from the rest of the network while keeping it running for forensic analysis?
- Cold shutdown
- Network isolation with monitoring (Correct answer)
- Full system reimaging
- VLAN reassignment without logging
Correct answer: Network isolation with monitoring
Network isolation with continued monitoring contains the threat while preserving the system's volatile data (memory, active connections) for forensic examination.
Question 5: After a breach, a card brand may place a merchant on a compliance acceleration program. What is the primary goal of this program?
- To penalize the merchant financially for the breach
- To expedite the merchant's return to full PCI DSS compliance (Correct answer)
- To permanently revoke the merchant's card acceptance rights
- To transfer liability to the merchant's acquiring bank
Correct answer: To expedite the merchant's return to full PCI DSS compliance
Compliance acceleration programs are designed to fast-track the breached entity's remediation efforts and restore full PCI DSS compliance as quickly as possible.
Question 6: Which technique do attackers commonly use to exfiltrate cardholder data without triggering data loss prevention tools?
- Sending data in plaintext over HTTP
- Encoding data within DNS queries or HTTPS traffic (Correct answer)
- Using unencrypted USB drives
- Emailing cardholder data to an internal address
Correct answer: Encoding data within DNS queries or HTTPS traffic
Attackers encode stolen data within legitimate-looking DNS queries or HTTPS traffic to blend with normal network activity and evade DLP detection.
Question 7: Which of the following is the MOST important reason to avoid powering off a compromised system immediately during incident response?
- To continue processing transactions during the investigation
- To preserve volatile memory evidence such as encryption keys and running processes (Correct answer)
- To avoid triggering the system's intrusion detection alerts
- To maintain uptime SLA commitments with customers
Correct answer: To preserve volatile memory evidence such as encryption keys and running processes
Volatile memory contains critical forensic evidence — including active malware, encryption keys, and network connections — that is permanently lost upon shutdown.
Which of the following is a key deliverable from a PFI (PCI Forensic Investigator) engagement?