PCIP PCI DSS Requirements & Compliance Framework 4 β Questions and Answers
Question 1: A QSA is reviewing a merchant's penetration test. PCI DSS v4.0 requires external penetration testing be performed at what minimum frequency?
- Every 6 months
- Annually and after significant infrastructure changes (Correct answer)
- Quarterly
- Every 2 years
Correct answer: Annually and after significant infrastructure changes
PCI DSS Requirement 11 mandates external penetration testing at least annually and after any significant changes to the network or application infrastructure.
Question 2: Under PCI DSS, which of the following is an example of a compensating control?
- Applying patches within 30 days for critical vulnerabilities
- Using an IDS to monitor the CDE when isolating a legacy system that cannot support encryption (Correct answer)
- Requiring MFA for all administrative access
- Conducting quarterly vulnerability scans with an ASV
Correct answer: Using an IDS to monitor the CDE when isolating a legacy system that cannot support encryption
Compensating controls are alternative measures used when an entity cannot meet a PCI DSS requirement as stated, such as using enhanced monitoring for a legacy system that cannot be upgraded.
Question 3: Which merchant level requires an annual on-site assessment by a Qualified Security Assessor (QSA)?
- Level 4 β fewer than 20,000 e-commerce transactions
- Level 3 β 20,000 to 1 million e-commerce transactions
- Level 2 β 1 to 6 million transactions
- Level 1 β more than 6 million transactions (Correct answer)
Correct answer: Level 1 β more than 6 million transactions
Level 1 merchants (over 6 million transactions annually) are required to undergo a full annual on-site QSA assessment and produce a Report on Compliance (ROC).
Question 4: PCI DSS Requirement 4 governs cardholder data in transit. Which protocol is explicitly prohibited for protecting cardholder data?
- TLS 1.2
- TLS 1.3
- SSL and early TLS versions (Correct answer)
- IPSec
Correct answer: SSL and early TLS versions
PCI DSS explicitly prohibits the use of SSL and early TLS (prior to TLS 1.2) for protecting cardholder data in transit due to known cryptographic weaknesses.
Question 5: When must an organization perform a PAN discovery scan of systems according to PCI DSS v4.0 Requirement 12?
- Only during initial scoping
- As part of a targeted risk analysis defined frequency (Correct answer)
- Every 30 days
- Once per calendar year regardless of changes
Correct answer: As part of a targeted risk analysis defined frequency
PCI DSS v4.0 allows organizations to define the frequency of PAN discovery scans through a targeted risk analysis documented under Requirement 12.
Question 6: Which PCI DSS requirement mandates that anti-malware solutions be kept current and capable of generating audit logs?
- Requirement 3
- Requirement 5 (Correct answer)
- Requirement 7
- Requirement 10
Correct answer: Requirement 5
Requirement 5 requires that anti-malware mechanisms be deployed, maintained with current definitions, and configured to generate logs that are retained per organizational policy.
Question 7: What does PCI DSS require regarding default passwords on system components before they are deployed in the CDE?
- They must be changed to unique passwords (Correct answer)
- They must be documented in a secure password vault
- They may remain if the system is behind a firewall
- They must be reviewed by the QSA before deployment
Correct answer: They must be changed to unique passwords
Requirement 2 mandates that all vendor-supplied default passwords be changed before any system component is installed in the production environment.
A QSA is reviewing a merchant's penetration test.
PCI DSS v4.0 requires external penetration testing be performed at what minimum frequency?