PCIP Risk Management & Data Protection Strategies 5 — Questions and Answers
Question 1: A service provider processes cardholder data for multiple merchants. Under PCI DSS, what document must the service provider supply to each merchant to clarify shared compliance responsibilities?
- A network diagram showing cardholder data flows
- A responsibility matrix (shared responsibility matrix) (Correct answer)
- A penetration test report for the service provider's environment
- A signed merchant agreement acknowledging PCI DSS requirements
Correct answer: A responsibility matrix (shared responsibility matrix)
PCI DSS requires service providers to maintain a documented responsibility matrix that explicitly states which requirements are managed by the provider and which remain the merchant's responsibility.
Question 2: Which cryptographic concept ensures that a sender cannot later deny having sent a message, and is often used in digital payment audit trails?
- Confidentiality
- Integrity
- Non-repudiation (Correct answer)
- Availability
Correct answer: Non-repudiation
Non-repudiation uses digital signatures or audit logs to prove the origin of a transaction, preventing parties from falsely denying their actions.
Question 3: A QSA discovers that an organization's anti-malware solution has not been updated for 45 days on several servers in the cardholder data environment. Which PCI DSS requirement is MOST directly violated?
- Requirement 3 – Protect stored account data
- Requirement 5 – Protect all systems from malicious software (Correct answer)
- Requirement 7 – Restrict access to system components and cardholder data
- Requirement 10 – Log and monitor all access to system components
Correct answer: Requirement 5 – Protect all systems from malicious software
Requirement 5 mandates that anti-malware solutions be kept current, including virus definitions and engine updates, on all in-scope systems.
Question 4: What is the primary goal of data minimization as a risk reduction strategy in payment card environments?
- Reducing storage costs by compressing cardholder data files
- Limiting the volume and retention of cardholder data to reduce breach impact (Correct answer)
- Increasing the speed of payment transaction processing
- Simplifying the encryption key management process
Correct answer: Limiting the volume and retention of cardholder data to reduce breach impact
Data minimization reduces the amount and retention period of cardholder data, shrinking the attack surface and limiting the harm if a breach occurs.
Question 5: An organization's penetration test reveals that an internal system can reach PAN data stores without passing through a network segmentation control. What is the MOST appropriate remediation?
- Add the internal system to the cardholder data environment scope
- Implement and enforce network segmentation to isolate the cardholder data environment from other networks (Correct answer)
- Encrypt the PAN data at rest on the data store
- Increase the password complexity requirements on the internal system
Correct answer: Implement and enforce network segmentation to isolate the cardholder data environment from other networks
Proper network segmentation (e.g., firewalls, VLANs with access controls) isolates the CDE, preventing out-of-scope systems from reaching cardholder data.
Question 6: Under PCI DSS, which role is responsible for overseeing the organization's information security program and is typically designated in writing?
- Qualified Security Assessor (QSA)
- Chief Information Security Officer (CISO) or equivalent executive (Correct answer)
- Payment Card Industry Security Standards Council (PCI SSC)
- Acquiring bank relationship manager
Correct answer: Chief Information Security Officer (CISO) or equivalent executive
PCI DSS Requirement 12.1.3 requires organizations to formally designate a qualified individual (such as a CISO) responsible for managing the information security program.
Question 7: Which of the following BEST describes the purpose of an Internal Vulnerability Scan required by PCI DSS Requirement 11.3?
- To simulate an external attacker's attempt to penetrate the network perimeter
- To identify vulnerabilities within the cardholder data environment by scanning internal IP addresses quarterly (Correct answer)
- To validate that all public-facing applications are free from OWASP Top 10 vulnerabilities
- To test whether intrusion detection systems generate alerts for known attack signatures
Correct answer: To identify vulnerabilities within the cardholder data environment by scanning internal IP addresses quarterly
PCI DSS requires quarterly internal vulnerability scans of in-scope systems to identify and remediate weaknesses that could be exploited by an insider or a compromised internal host.
A service provider processes cardholder data for multiple merchants.
Under PCI DSS, what document must the service provider supply to each merchant to clarify shared compliance responsibilities?