PCIP Security Monitoring 4 — Questions and Answers
Question 1: What does 'baselining' mean in the context of PCI DSS security monitoring?
- Setting the lowest acceptable password complexity standard
- Establishing normal traffic and behavior patterns to identify anomalies (Correct answer)
- Installing the minimum required security patches
- Documenting the initial scope of the CDE
Correct answer: Establishing normal traffic and behavior patterns to identify anomalies
Baselining captures normal system behavior and network traffic so that deviations — which may signal attacks — can be detected more accurately.
Question 2: Which PCI DSS control requires verifying that security policies and operational procedures for monitoring are documented and in use?
- Requirement 10.9 (Correct answer)
- Requirement 7.3
- Requirement 4.2
- Requirement 9.5
Correct answer: Requirement 10.9
Requirement 10.9 requires that security policies and operational procedures for monitoring all access to network resources and cardholder data are documented and implemented.
Question 3: A SIEM generates 5,000 alerts per day. Which tuning strategy BEST reduces alert fatigue while maintaining security coverage?
- Disable all low-severity alert rules
- Suppress all alerts that fire more than 10 times per hour
- Adjust thresholds and create correlation rules to surface high-fidelity alerts (Correct answer)
- Limit log ingestion to firewall and IDS sources only
Correct answer: Adjust thresholds and create correlation rules to surface high-fidelity alerts
Correlation rules and threshold tuning reduce false positives and surface actionable, high-confidence alerts without eliminating monitoring coverage.
Question 4: Under PCI DSS, which action is required when a critical security control such as a firewall fails?
- Continue operations normally until the next maintenance window
- Notify the card brands within 24 hours
- Implement compensating controls and document the failure immediately (Correct answer)
- Suspend all card transactions until the control is restored
Correct answer: Implement compensating controls and document the failure immediately
PCI DSS requires that failures of critical security controls be detected promptly and addressed with compensating controls until the primary control is restored.
Question 5: Which log source is MOST important for detecting unauthorized lateral movement within a CDE network?
- Web server access logs
- Internal firewall and network flow logs (Correct answer)
- Application error logs
- DNS query logs from external resolvers
Correct answer: Internal firewall and network flow logs
Internal firewall and network flow logs capture east-west traffic between CDE systems, revealing unusual connection patterns that indicate lateral movement.
Question 6: A penetration test reveals that an attacker with CDE access can clear system logs. Which PCI DSS control would BEST mitigate this risk?
- Increase log rotation frequency
- Forward logs in real time to a centralized, write-protected log server (Correct answer)
- Encrypt logs using symmetric encryption
- Require two-factor authentication to view logs
Correct answer: Forward logs in real time to a centralized, write-protected log server
Sending logs to a separate, hardened log server in real time prevents attackers who compromise a CDE system from destroying forensic evidence by clearing local logs.
Question 7: Which metric BEST measures the effectiveness of a security monitoring program in a PCI DSS environment?
- Number of log entries generated per day
- Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents (Correct answer)
- Total number of SIEM rules deployed
- Percentage of systems with agents installed
Correct answer: Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents
MTTD and MTTR measure how quickly threats are identified and contained, directly reflecting the effectiveness of monitoring and incident response capabilities.
What does 'baselining' mean in the context of PCI DSS security monitoring?