PCIP Security Monitoring 2 — Questions and Answers
Question 1: Under PCI DSS, how long must audit log history be retained?
- 30 days online, 6 months archived
- 3 months online, 12 months archived
- 90 days online, 1 year archived (Correct answer)
- 6 months online, 2 years archived
Correct answer: 90 days online, 1 year archived
PCI DSS requires at least 12 months of audit log history, with the most recent 3 months immediately available for analysis.
Question 2: Which event type MUST be included in PCI DSS audit logs?
- All user web browsing activity
- All successful and failed access attempts to cardholder data (Correct answer)
- CPU utilization metrics for all servers
- Marketing campaign click-through rates
Correct answer: All successful and failed access attempts to cardholder data
PCI DSS Requirement 10 mandates logging all individual user accesses to cardholder data, including both successful and failed attempts.
Question 3: What is the primary purpose of a Security Information and Event Management (SIEM) system in PCI DSS compliance?
- Encrypt cardholder data at rest
- Aggregate and correlate log data to detect security events (Correct answer)
- Manage employee passwords and access credentials
- Scan networks for open ports automatically
Correct answer: Aggregate and correlate log data to detect security events
A SIEM centralizes log collection and correlation to identify suspicious patterns and security incidents across the cardholder data environment.
Question 4: A merchant notices that logs from a point-of-sale terminal are missing for a 4-hour window. What is the BEST immediate action?
- Reboot the terminal to restore logging
- Investigate whether a security incident occurred during the gap (Correct answer)
- Delete all logs from that day and start fresh
- Assume it was a network glitch and take no action
Correct answer: Investigate whether a security incident occurred during the gap
Log gaps are a red flag indicating possible tampering or a breach; the missing window must be investigated as a potential security incident.
Question 5: Which PCI DSS requirement specifically addresses the use of time-synchronization technology?
- Requirement 6
- Requirement 8
- Requirement 10 (Correct answer)
- Requirement 12
Correct answer: Requirement 10
Requirement 10.6 requires all systems to synchronize clocks using NTP or similar technology to ensure accurate timestamps in audit logs.
Question 6: An IDS alert fires on outbound traffic from a CDE server to an unknown external IP. Which action follows the correct incident response order?
- Ignore — outbound traffic is not a PCI concern
- Immediately shut down the entire CDE network
- Contain, investigate, then eradicate and recover (Correct answer)
- Notify card brands before taking any containment action
Correct answer: Contain, investigate, then eradicate and recover
PCI DSS incident response follows the standard contain-investigate-eradicate-recover sequence to limit damage while preserving forensic evidence.
Question 7: What does PCI DSS require regarding daily log reviews?
- All logs must be reviewed manually by a human analyst every day
- Only firewall logs need daily review
- Security events and logs must be reviewed at least daily (Correct answer)
- Weekly review is sufficient if a SIEM is deployed
Correct answer: Security events and logs must be reviewed at least daily
PCI DSS Requirement 10.7 mandates that logs of all system components be reviewed at least daily, typically using automated tools to flag anomalies.
Under PCI DSS, how long must audit log history be retained?