PCIP Risk Assessment 5 — Questions and Answers
Question 1: In the NIST SP 800-30 risk assessment framework, which step directly follows threat and vulnerability identification?
- Risk monitoring
- Likelihood determination (Correct answer)
- Control implementation
- Asset inventory
Correct answer: Likelihood determination
After identifying threats and vulnerabilities, NIST SP 800-30 calls for determining the likelihood that a threat will exploit a vulnerability.
Question 2: Which of the following BEST describes the purpose of network segmentation in the context of PCI DSS risk reduction?
- It eliminates all vulnerabilities within the cardholder data environment
- It reduces the scope and attack surface of the cardholder data environment (Correct answer)
- It transfers risk to the network infrastructure vendor
- It satisfies all Requirement 12 obligations automatically
Correct answer: It reduces the scope and attack surface of the cardholder data environment
Network segmentation limits the CDE scope by isolating cardholder data systems, thereby reducing the number of systems subject to PCI DSS requirements and the overall attack surface.
Question 3: A risk assessment finds that a payment terminal vendor's remote access credentials are shared among multiple technicians. The PRIMARY risk this creates is:
- Reduced system uptime due to login conflicts
- Inability to attribute actions to individuals, undermining accountability (Correct answer)
- Excessive bandwidth consumption on the network
- Non-compliance with card brand marketing requirements
Correct answer: Inability to attribute actions to individuals, undermining accountability
Shared credentials prevent individual accountability, making it impossible to trace malicious or erroneous actions to a specific person, which violates PCI DSS access control principles.
Question 4: Which of the following scenarios represents risk AVOIDANCE as a treatment strategy?
- Encrypting all stored PANs to reduce breach impact
- Discontinuing a high-risk paper-based order process that captures full PANs (Correct answer)
- Purchasing insurance to cover breach notification costs
- Accepting a low-rated risk after management review
Correct answer: Discontinuing a high-risk paper-based order process that captures full PANs
Risk avoidance eliminates the risk entirely by stopping the activity that creates it, such as discontinuing a risky business process.
Question 5: When prioritizing risk remediation in a PCI DSS environment, which factor should be weighted MOST heavily?
- The cost of remediation relative to annual IT budget
- The combination of likelihood and impact on cardholder data confidentiality (Correct answer)
- The preferences of the business unit that owns the system
- The age of the vulnerability as listed in the CVE database
Correct answer: The combination of likelihood and impact on cardholder data confidentiality
Prioritization should focus on risks with high likelihood of exploitation and high potential impact on cardholder data, aligning remediation efforts with actual CDE exposure.
Question 6: A PCIP is asked to validate a risk assessment that was conducted entirely by the IT department without business stakeholder input. The PRIMARY concern is:
- IT departments are not authorized to perform risk assessments under PCI DSS
- Business context and operational risks may be missed without cross-functional input (Correct answer)
- The assessment cannot be accepted unless performed by an external party
- IT-led assessments always underestimate technical vulnerabilities
Correct answer: Business context and operational risks may be missed without cross-functional input
Effective risk assessments require input from business stakeholders to capture operational context, business process risks, and impact to business-critical functions.
Question 7: Which of the following is a characteristic of a MATURE organizational risk management program in a PCI DSS context?
- Risk assessments are only triggered by QSA audit requests
- Risks are continuously monitored with defined key risk indicators and escalation thresholds (Correct answer)
- The risk register is maintained solely by the compliance team
- Risk treatment decisions require card brand approval before implementation
Correct answer: Risks are continuously monitored with defined key risk indicators and escalation thresholds
A mature program features continuous monitoring with defined KRIs and escalation paths, rather than point-in-time assessments driven only by external requirements.
In the NIST SP 800-30 risk assessment framework, which step directly follows threat and vulnerability identification?