PCIP Risk Assessment 2 — Questions and Answers
Question 1: During a PCI DSS risk assessment, which threat modeling approach focuses on identifying assets, threats, vulnerabilities, and countermeasures?
- STRIDE
- PASTA
- OCTAVE (Correct answer)
- TRIKE
Correct answer: OCTAVE
OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is an asset-driven threat modeling approach widely used in PCI DSS risk assessments.
Question 2: A risk assessment identifies that a third-party vendor stores cardholder data. Under PCI DSS, what is the PRIMARY responsibility of the assessed entity?
- Conduct the vendor's PCI audit directly
- Ensure the vendor is PCI DSS compliant and monitor their compliance (Correct answer)
- Transfer all liability to the vendor via contract
- Remove cardholder data from the vendor immediately
Correct answer: Ensure the vendor is PCI DSS compliant and monitor their compliance
The assessed entity must ensure third-party service providers are PCI DSS compliant and maintain ongoing monitoring of their compliance status.
Question 3: Which PCI DSS requirement mandates that a formal risk assessment be performed at least annually?
- Requirement 6
- Requirement 8
- Requirement 12 (Correct answer)
- Requirement 10
Correct answer: Requirement 12
PCI DSS Requirement 12.3 requires that a risk assessment be performed at least annually and upon significant changes to the environment.
Question 4: When assessing residual risk after controls are applied, which formula best represents the calculation?
- Residual Risk = Inherent Risk + Control Effectiveness
- Residual Risk = Inherent Risk × Control Effectiveness
- Residual Risk = Inherent Risk − Control Effectiveness (Correct answer)
- Residual Risk = Threat × Vulnerability − Asset Value
Correct answer: Residual Risk = Inherent Risk − Control Effectiveness
Residual risk is the remaining risk after subtracting the risk reduction achieved by implemented controls from the inherent risk.
Question 5: A PCIP professional is reviewing a risk assessment that categorizes risks as High, Medium, or Low. This approach is BEST described as:
- Quantitative risk analysis
- Qualitative risk analysis (Correct answer)
- Monte Carlo simulation
- Annualized loss expectancy analysis
Correct answer: Qualitative risk analysis
Qualitative risk analysis uses descriptive categories (High/Medium/Low) rather than numerical monetary values to rank risks.
Question 6: Which of the following is a key input required BEFORE conducting a PCI DSS scoped risk assessment?
- Completed penetration test report
- Accurate network diagram and data flow diagram (Correct answer)
- Signed merchant agreement with the acquiring bank
- List of all employee access credentials
Correct answer: Accurate network diagram and data flow diagram
Accurate network and data flow diagrams are essential prerequisites to properly define scope and identify cardholder data flows before risk assessment.
Question 7: During risk assessment, a business unit argues that compensating controls fully eliminate a known vulnerability. As a PCIP, your BEST response is:
- Accept the claim if the business unit signs off in writing
- Verify the compensating controls meet all PCI DSS criteria and still document the residual risk (Correct answer)
- Remove the vulnerability from the risk register since controls exist
- Escalate immediately to the card brands for guidance
Correct answer: Verify the compensating controls meet all PCI DSS criteria and still document the residual risk
Compensating controls must meet specific PCI DSS criteria, and residual risk should still be documented even when compensating controls are accepted.
During a PCI DSS risk assessment, which threat modeling approach focuses on identifying assets, threats, vulnerabilities, and countermeasures?