PCIP Incident Response 5 — Questions and Answers
Question 1: A service provider that stores cardholder data on behalf of 50 merchants suffers a breach. Which entities are primarily responsible for notifying affected card brands?
- Each of the 50 individual merchants separately
- The breached service provider and each merchant's acquirer (Correct answer)
- Only the federal government authorities
- The card-issuing banks of affected cardholders
Correct answer: The breached service provider and each merchant's acquirer
Both the breached service provider and the acquirers of affected merchants share notification obligations to the card brands under PCI DSS breach response requirements.
Question 2: Which of the following actions is considered a violation of proper incident response evidence handling procedures?
- Photographing the screen before shutting down a suspect system
- Running antivirus scans directly on the original compromised drive (Correct answer)
- Creating a write-protected forensic image before analysis
- Documenting all actions taken on compromised systems
Correct answer: Running antivirus scans directly on the original compromised drive
Running antivirus or any tool directly on the original compromised drive can alter or destroy evidence; always work from a forensic copy.
Question 3: What type of attack involves an adversary intercepting communications between a cardholder's browser and a payment website to steal card data?
- Denial of service attack
- Man-in-the-middle (MitM) attack (Correct answer)
- Brute-force attack
- SQL injection attack
Correct answer: Man-in-the-middle (MitM) attack
A man-in-the-middle attack intercepts the communication channel between the cardholder and the payment site, allowing the attacker to capture transmitted data.
Question 4: Under PCI DSS incident response requirements, which personnel role is responsible for approving and activating the incident response plan?
- The frontline IT helpdesk staff
- The designated Incident Response Team lead or CISO (Correct answer)
- External legal counsel
- The acquiring bank's representative
Correct answer: The designated Incident Response Team lead or CISO
The Incident Response Team lead or CISO typically holds authority to declare an incident and formally activate the incident response plan.
Question 5: Which of the following describes a 'false negative' in the context of PCI DSS security monitoring?
- An alert triggered by legitimate activity that was flagged as malicious
- A real attack that occurred but was not detected or alerted on (Correct answer)
- An incorrectly configured firewall rule that blocks valid traffic
- A log entry that was improperly formatted by the logging system
Correct answer: A real attack that occurred but was not detected or alerted on
A false negative occurs when a genuine threat or attack goes undetected, meaning monitoring systems failed to generate an alert for a real incident.
Question 6: During post-breach remediation, an organization must demonstrate to their acquirer that all vulnerabilities exploited in the attack have been fixed. Which document most commonly satisfies this requirement?
- An updated business continuity plan
- A remediation validation report from a QSA or ASV (Correct answer)
- A signed affidavit from the CEO
- An internal audit report from the IT department
Correct answer: A remediation validation report from a QSA or ASV
A remediation validation report prepared by a qualified QSA or ASV provides independent verification that exploited vulnerabilities have been resolved.
Question 7: A retailer's incident response team receives an alert indicating large volumes of cardholder data are being transmitted to an external IP at 2 AM. Which action reflects the correct initial triage step?
- Immediately call law enforcement before investigating
- Verify the alert's legitimacy and assess the scope before taking action (Correct answer)
- Shut down all network connections to the internet
- Send a breach notification to all customers right away
Correct answer: Verify the alert's legitimacy and assess the scope before taking action
Initial triage requires verifying whether the alert represents a genuine incident and assessing scope before escalating to containment or notification actions.
A service provider that stores cardholder data on behalf of 50 merchants suffers a breach.
Which entities are primarily responsible for notifying affected card brands?