PCIP PCI DSS Requirements & Compliance Framework 3 — Questions and Answers
Question 1: Under PCI DSS, what is the minimum period for which audit logs must be retained?
- 6 months
- 1 year with 3 months immediately available (Correct answer)
- 2 years
- 90 days
Correct answer: 1 year with 3 months immediately available
PCI DSS Requirement 10 requires audit logs to be retained for at least 12 months, with the most recent 3 months immediately available for analysis.
Question 2: A service provider stores, processes, or transmits cardholder data on behalf of another entity. What compliance document must they provide to their clients annually?
- PCI DSS Report on Compliance (ROC)
- Attestation of Compliance (AOC) (Correct answer)
- Self-Assessment Questionnaire (SAQ)
- Network segmentation penetration test results
Correct answer: Attestation of Compliance (AOC)
Service providers must provide an Attestation of Compliance (AOC) to their clients as evidence of their own PCI DSS compliance status.
Question 3: Which PCI DSS requirement specifically addresses the use of multi-factor authentication (MFA) for all non-console administrative access into the CDE?
- Requirement 6
- Requirement 7
- Requirement 8 (Correct answer)
- Requirement 12
Correct answer: Requirement 8
Requirement 8 mandates MFA for all non-console administrative access to systems in the CDE, as well as for all remote network access.
Question 4: What does the term 'SAD' refer to in PCI DSS, and what is the key rule regarding it post-authorization?
- Stored Account Data — must be encrypted at rest
- Sensitive Authentication Data — must not be stored after authorization is complete (Correct answer)
- Secondary Account Data — may be stored if tokenized
- Supplemental Account Details — must be masked in displays
Correct answer: Sensitive Authentication Data — must not be stored after authorization is complete
Sensitive Authentication Data (SAD) includes full track data, CVV2, and PINs, and PCI DSS absolutely prohibits retaining SAD after transaction authorization.
Question 5: An e-commerce merchant outsources its entire payment page to a PCI-compliant payment processor using an iFrame. Which SAQ is most likely applicable?
- SAQ A (Correct answer)
- SAQ B
- SAQ C
- SAQ D
Correct answer: SAQ A
SAQ A applies to card-not-present merchants that have fully outsourced all payment processing to a PCI DSS compliant third-party and never receive cardholder data on their own systems.
Question 6: Which PCI DSS control requires that payment software vendors protect their applications from known vulnerabilities by applying security patches within a defined timeframe?
- Requirement 3 – Protect stored account data
- Requirement 5 – Protect all systems against malware
- Requirement 6 – Develop and maintain secure systems and software (Correct answer)
- Requirement 11 – Test security of systems and networks
Correct answer: Requirement 6 – Develop and maintain secure systems and software
Requirement 6 covers secure development practices and mandates applying critical security patches within one month of release.
Question 7: What is the primary purpose of network segmentation in the context of PCI DSS?
- To eliminate the need for encryption of cardholder data in transit
- To reduce the scope of the PCI DSS assessment by isolating the CDE (Correct answer)
- To replace the need for firewalls on CDE systems
- To enable shared user accounts across departments
Correct answer: To reduce the scope of the PCI DSS assessment by isolating the CDE
Effective network segmentation isolates the CDE from out-of-scope systems, reducing the number of systems subject to PCI DSS requirements and lowering compliance costs.
Under PCI DSS, what is the minimum period for which audit logs must be retained?