PCIP PCI DSS Requirements & Compliance Framework 2 — Questions and Answers
Question 1: Under PCI DSS v4.0, which requirement mandates that organizations perform a targeted risk analysis to determine how frequently certain activities must be performed?
- Requirement 6
- Requirement 12 (Correct answer)
- Requirement 10
- Requirement 3
Correct answer: Requirement 12
PCI DSS v4.0 Requirement 12 introduces targeted risk analysis, allowing organizations to define the frequency of certain activities based on their specific risk environment.
Question 2: A merchant's cardholder data environment (CDE) uses a flat network where all systems can communicate with each other. Which PCI DSS requirement is most directly violated?
- Requirement 1 – Install and maintain network security controls (Correct answer)
- Requirement 5 – Protect all systems against malware
- Requirement 8 – Identify users and authenticate access
- Requirement 11 – Test security of systems and networks
Correct answer: Requirement 1 – Install and maintain network security controls
Requirement 1 mandates network segmentation controls (firewalls/routers) to restrict traffic and isolate the CDE from untrusted networks.
Question 3: Which PCI DSS scoping concept refers to systems that are NOT in the CDE but could impact its security?
- In-scope systems
- Connected-to systems (Correct answer)
- Out-of-scope systems
- Segmented systems
Correct answer: Connected-to systems
Connected-to systems are outside the CDE but have connectivity to it and must still be assessed for their potential impact on CDE security.
Question 4: An organization wants to use a customized approach for a PCI DSS v4.0 control. What is required before doing so?
- Approval from the card brands
- A documented targeted risk analysis and controls testing methodology (Correct answer)
- A letter of attestation from a QSA
- Written consent from all acquiring banks
Correct answer: A documented targeted risk analysis and controls testing methodology
The customized approach in PCI DSS v4.0 requires organizations to document their targeted risk analysis and describe how the customized control meets the stated objective.
Question 5: Which PCI DSS requirement covers the protection of stored account data, including the use of strong cryptography?
- Requirement 2
- Requirement 3 (Correct answer)
- Requirement 4
- Requirement 6
Correct answer: Requirement 3
Requirement 3 addresses protection of stored account data, mandating that sensitive authentication data not be retained and that stored PANs be protected with strong cryptography.
Question 6: What is the maximum number of consecutive failed authentication attempts allowed before a user account must be locked out per PCI DSS?
- 3
- 5
- 10
- 6 (Correct answer)
Correct answer: 6
PCI DSS Requirement 8 specifies that accounts must be locked out after not more than 6 consecutive invalid access attempts.
Question 7: Which entity publishes the PCI DSS standard and oversees the PCIP certification program?
- Visa Inc.
- The Federal Reserve
- PCI Security Standards Council (PCI SSC) (Correct answer)
- NIST
Correct answer: PCI Security Standards Council (PCI SSC)
The PCI Security Standards Council (PCI SSC), founded by major card brands, develops and maintains PCI DSS and administers related professional certifications including PCIP.
Under PCI DSS v4.0, which requirement mandates that organizations perform a targeted risk analysis to determine how frequently certain activities must be performed?