PCIP Risk Assessment 4 — Questions and Answers
Question 1: Which PCI DSS document type formally records identified risks, their ratings, owners, and treatment plans?
- System Security Plan
- Risk Register (Correct answer)
- Network Segmentation Diagram
- Compensating Control Worksheet
Correct answer: Risk Register
A risk register is the formal document used to track identified risks, their assessed ratings, assigned owners, and planned or completed treatment actions.
Question 2: An organization's risk assessment reveals that unencrypted PANs traverse a legacy internal network segment. The FIRST step should be:
- Immediately shut down the legacy segment
- Identify and document all data flows to determine full scope of exposure (Correct answer)
- Apply network segmentation to isolate the legacy segment
- Report the finding to the card brands within 24 hours
Correct answer: Identify and document all data flows to determine full scope of exposure
Before remediating, fully mapping and documenting all affected data flows ensures the complete scope of the exposure is understood and remediation is comprehensive.
Question 3: Which of the following BEST distinguishes inherent risk from residual risk?
- Inherent risk is calculated after controls; residual risk is calculated before
- Inherent risk exists before controls are applied; residual risk remains after controls (Correct answer)
- Inherent risk applies only to external threats; residual risk applies to internal threats
- Inherent risk is qualitative; residual risk is always quantitative
Correct answer: Inherent risk exists before controls are applied; residual risk remains after controls
Inherent risk is the natural level of risk without any controls, while residual risk is what remains after controls have been implemented.
Question 4: A PCIP reviews a risk assessment that omits insider threat scenarios. This is a gap because:
- PCI DSS only requires external threat scenarios
- Insider threats represent a significant and commonly exploited attack vector for cardholder data theft (Correct answer)
- Insider threats are covered by HR policies, not risk assessments
- Qualitative assessments never include insider threat modeling
Correct answer: Insider threats represent a significant and commonly exploited attack vector for cardholder data theft
Insider threats are a well-documented risk to cardholder data environments and must be included in comprehensive PCI DSS risk assessments.
Question 5: When using a risk matrix, a risk rated as 'Low Likelihood / High Impact' is MOST accurately described as:
- Negligible and safe to ignore
- A tail risk requiring monitoring and contingency planning (Correct answer)
- An immediate priority for mitigation above all other risks
- Outside the scope of PCI DSS risk assessment
Correct answer: A tail risk requiring monitoring and contingency planning
Low-likelihood, high-impact risks are often called tail risks; they warrant contingency planning and monitoring even if immediate mitigation isn't prioritized.
Question 6: Which methodology requires organizations to evaluate risks in terms of operational resilience, people, processes, and technology in a self-directed manner?
- FAIR
- OCTAVE Allegro (Correct answer)
- NIST SP 800-30
- ISO/IEC 27005
Correct answer: OCTAVE Allegro
OCTAVE Allegro is a streamlined, self-directed risk assessment methodology focused on operational resilience across people, processes, and technology.
Question 7: A merchant completes their annual PCI DSS risk assessment but does not reassess after migrating their payment application to a new cloud provider. This violates which principle?
- Risk assessments must be conducted only by external QSAs
- Significant changes to the CDE require a new or updated risk assessment (Correct answer)
- Cloud environments are automatically PCI DSS compliant and exempt
- Annual assessments eliminate the need for change-triggered assessments
Correct answer: Significant changes to the CDE require a new or updated risk assessment
PCI DSS requires risk assessments to be triggered by significant environmental changes such as cloud migrations, not just performed annually.
Which PCI DSS document type formally records identified risks, their ratings, owners, and treatment plans?