PCIP PCI DSS Requirements & Compliance Framework 5 β Questions and Answers
Question 1: An organization is preparing its Attestation of Compliance (AOC). Who is authorized to sign the merchant section of the AOC?
- The lead QSA from the assessing firm
- An officer of the merchant organization (Correct answer)
- The acquiring bank's compliance officer
- The PCI SSC regional representative
Correct answer: An officer of the merchant organization
The merchant section of the AOC must be signed by an executive officer of the merchant organization, attesting to the accuracy of the compliance information provided.
Question 2: Under PCI DSS, what is the requirement for displaying the full 16-digit PAN on receipts or reports?
- Full PAN may be displayed if the system is within the CDE
- Only the last four digits or first six digits may be displayed; full PAN must be masked (Correct answer)
- Full PAN display is acceptable with management approval
- PAN must be fully masked to all characters regardless of role
Correct answer: Only the last four digits or first six digits may be displayed; full PAN must be masked
PCI DSS Requirement 3 mandates that PANs be masked when displayed, showing no more than the first six and last four digits, unless there is a defined business need for more.
Question 3: Which PCI DSS requirement addresses the formal management of security policies and the assignment of security responsibilities?
- Requirement 9
- Requirement 10
- Requirement 11
- Requirement 12 (Correct answer)
Correct answer: Requirement 12
Requirement 12 covers the organization's information security policy, including assigning responsibility for cardholder data protection and managing personnel awareness and incident response.
Question 4: A company uses point-to-point encryption (P2PE) with a PCI-validated P2PE solution. What is the primary scoping benefit?
- Eliminates the need for any PCI DSS assessment
- Significantly reduces the merchant's CDE scope because cardholder data is encrypted immediately at the point of interaction (Correct answer)
- Allows storage of full track data post-authorization
- Removes the requirement for quarterly vulnerability scans
Correct answer: Significantly reduces the merchant's CDE scope because cardholder data is encrypted immediately at the point of interaction
A validated P2PE solution encrypts cardholder data at the point of swipe/dip/tap, so the merchant's systems never receive cleartext card data, dramatically reducing PCI DSS scope.
Question 5: Under PCI DSS Requirement 8, what is the minimum idle session timeout that must be applied to user sessions accessing the CDE?
- 5 minutes
- 15 minutes (Correct answer)
- 30 minutes
- 60 minutes
Correct answer: 15 minutes
PCI DSS Requirement 8 mandates that sessions accessing the CDE be re-authenticated after no more than 15 minutes of inactivity.
Question 6: What distinguishes a Qualified Security Assessor (QSA) from an Internal Security Assessor (ISA) under PCI DSS?
- QSAs work only for Level 4 merchants; ISAs work for Level 1 merchants
- QSAs are certified by PCI SSC to assess other organizations; ISAs are certified employees who assess their own organization (Correct answer)
- ISAs can sign Reports on Compliance; QSAs can only conduct gap assessments
- QSAs focus on network security; ISAs focus on application security
Correct answer: QSAs are certified by PCI SSC to assess other organizations; ISAs are certified employees who assess their own organization
A QSA is an independent third-party organization certified by PCI SSC to assess other entities' PCI DSS compliance, while an ISA is a certified employee authorized to assess and champion compliance within their own organization.
Question 7: Which PCI DSS requirement governs the physical security of systems that store, process, or transmit cardholder data?
- Requirement 7
- Requirement 8
- Requirement 9 (Correct answer)
- Requirement 11
Correct answer: Requirement 9
Requirement 9 addresses physical access controls, including restricting physical access to the CDE, protecting point-of-interaction devices, and maintaining visitor logs.
An organization is preparing its Attestation of Compliance (AOC).
Who is authorized to sign the merchant section of the AOC?