PCIP Network Security 5 — Questions and Answers
Question 1: What is the purpose of a 'network diagram' requirement in PCI DSS?
- To provide marketing materials about network infrastructure
- To document all connections between the CDE and other networks, enabling accurate scope determination (Correct answer)
- To satisfy physical security requirements
- To replace the need for a data flow diagram
Correct answer: To document all connections between the CDE and other networks, enabling accurate scope determination
PCI DSS requires current network diagrams showing all connections into and out of the CDE so assessors and entities can accurately identify what is in scope.
Question 2: Which technique involves sending specially crafted packets to exploit vulnerabilities in network protocols and is tested during penetration testing?
- Phishing
- Fuzzing (Correct answer)
- Social engineering
- Vishing
Correct answer: Fuzzing
Fuzzing sends malformed or unexpected inputs to network services to uncover vulnerabilities that could be exploited by attackers.
Question 3: Under PCI DSS Requirement 11, how frequently must internal vulnerability scans be performed?
- Weekly
- Monthly
- Quarterly (Correct answer)
- Annually
Correct answer: Quarterly
PCI DSS Requirement 11.3.1 requires internal vulnerability scans to be performed at least quarterly by qualified personnel.
Question 4: What does 'defense in depth' mean in the context of PCI DSS network security?
- Using the deepest available firewall rule sets
- Implementing multiple overlapping security controls so failure of one does not compromise the entire environment (Correct answer)
- Encrypting data at multiple levels simultaneously
- Conducting security reviews at every layer of management
Correct answer: Implementing multiple overlapping security controls so failure of one does not compromise the entire environment
Defense in depth applies layered security controls so that if one control fails, additional controls remain to protect cardholder data.
Question 5: Which network security control prevents systems in the CDE from initiating connections to the internet unless explicitly required?
- Ingress firewall rules
- Egress firewall rules restricting outbound connections (Correct answer)
- IDS signature updates
- DNS sinkholing
Correct answer: Egress firewall rules restricting outbound connections
Outbound (egress) firewall rules ensure CDE systems can only connect to approved external destinations, limiting the blast radius of a compromise.
Question 6: A company wants to allow a third-party service provider to access the CDE for maintenance. Which control is MOST critical under PCI DSS?
- Ensuring the provider uses a Mac OS device
- Implementing time-limited access with MFA and logging all activity (Correct answer)
- Providing the provider with permanent VPN credentials
- Allowing access only during business hours without additional controls
Correct answer: Implementing time-limited access with MFA and logging all activity
Third-party CDE access must be time-limited, require MFA, and have all activities logged to maintain accountability and minimize risk.
Question 7: What is 'ARP spoofing' and why is it a concern for cardholder data environments?
- A method to forge DNS responses redirecting users to malicious sites
- A technique to associate an attacker's MAC address with a legitimate IP, enabling traffic interception on local networks (Correct answer)
- An attack that floods network switches to disable segmentation
- A method to bypass firewall rules using crafted ICMP packets
Correct answer: A technique to associate an attacker's MAC address with a legitimate IP, enabling traffic interception on local networks
ARP spoofing lets an attacker redirect local network traffic through their machine, enabling man-in-the-middle attacks against cardholder data in transit on the same LAN segment.
What is the purpose of a 'network diagram' requirement in PCI DSS?