PCIP Risk Management & Data Protection Strategies 4 β Questions and Answers
Question 1: An e-commerce organization implements point-to-point encryption (P2PE) using a PCI-validated P2PE solution. What is the PRIMARY scope reduction benefit?
- The organization no longer needs to file a SAQ
- Merchant systems that only handle encrypted data and cannot decrypt it may be removed from CDE scope (Correct answer)
- All PCI DSS requirements are waived for the merchant
- The acquiring bank assumes liability for any data breaches
Correct answer: Merchant systems that only handle encrypted data and cannot decrypt it may be removed from CDE scope
A validated P2PE solution encrypts card data at the point of interaction, so merchant systems that handle only ciphertext and cannot decrypt it can be excluded from the cardholder data environment.
Question 2: What does the term 'residual risk' mean in a payment security risk management program?
- The risk that remains after all planned controls have been applied (Correct answer)
- The initial risk rating before any controls are considered
- The risk transferred to a third-party vendor
- The risk associated with legacy systems that cannot be patched
Correct answer: The risk that remains after all planned controls have been applied
Residual risk is the level of risk that persists after existing or planned controls have been applied, which management must then accept, transfer, or further mitigate.
Question 3: A payment organization must restrict access to cardholder data to only those individuals whose job function requires it. Which security principle does this BEST represent?
- Defense in depth
- Least privilege
- Separation of duties
- Need to know (Correct answer)
Correct answer: Need to know
The need-to-know principle limits data access to individuals whose specific role requires that information, directly aligning with PCI DSS Requirement 7.
Question 4: Under PCI DSS v4.0, how frequently must a targeted risk analysis be performed for controls where the entity defines its own frequency?
- At least once every three years
- At least once every two years
- At least annually (Correct answer)
- Each time a significant change occurs
Correct answer: At least annually
PCI DSS v4.0 requires that targeted risk analyses be reviewed and updated at least once every 12 months to remain relevant.
Question 5: Which attack specifically targets the cardholder data environment by intercepting network traffic to capture PANs transmitted in cleartext between systems?
- Brute force attack
- Packet sniffing (network eavesdropping) (Correct answer)
- Cross-site scripting (XSS)
- Denial of service (DoS)
Correct answer: Packet sniffing (network eavesdropping)
Packet sniffing captures unencrypted network packets, making cleartext PAN transmissions visible to an attacker with network access.
Question 6: An organization is designing its incident response plan for a cardholder data breach. Which step must occur BEFORE forensic investigation begins?
- Notifying the media
- Containing the breach to prevent further data loss (Correct answer)
- Resuming normal payment operations
- Filing a police report
Correct answer: Containing the breach to prevent further data loss
Containment is the critical first technical step to stop ongoing data loss before evidence is collected or other notifications are made.
Question 7: PCI DSS Requirement 8 addresses authentication. Which of the following is an example of multi-factor authentication (MFA) as defined by PCI DSS?
- A username and a strong password
- A password plus a security question
- A PIN plus a one-time passcode sent to a registered mobile device (Correct answer)
- Two different passwords on two separate systems
Correct answer: A PIN plus a one-time passcode sent to a registered mobile device
MFA requires at least two independent factors from different categories (something you know, something you have, something you are), such as a PIN plus an OTP token.
An e-commerce organization implements point-to-point encryption (P2PE) using a PCI-validated P2PE solution.
What is the PRIMARY scope reduction benefit?