Browse all practice questions for the PCI Data Security Standard Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the PCI Data Security Standard Challenge 2026 – Protect and Perfect Your Cyber Skills! course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which statement is true about database application IDs?
  • How often must the incident response plan be tested?
  • Which PCI DSS requirement includes a sub-requirement that specifies a formal process for approving and testing all network connections and changes to the firewall and router configurations?
  • Which option specifies the acceptable network locations for the technologies?
  • 12.3.4 requires?
  • What is the policy regarding reusing previous passwords?
  • What is required for wireless networks in relation to the cardholder data environment?
  • Which sub-requirement concerns administering user accounts, including additions, deletions, and modifications?
  • Which vulnerability type is described as enabling attacker-executed scripts within a user's browser?
  • Which statement correctly reflects time data handling?
  • Under what conditions may compensating controls be considered for PCI DSS requirements?
  • What does Requirement 12.1.1 require?
  • What condition should apply to new data added to logs when monitoring integrity?
  • Where should system components that store cardholder data be placed?
  • If a session is idle for more than 15 minutes, what should happen?
  • Which PCI DSS requirement requires assigning all users a unique ID before accessing system components or cardholder data?
  • Which statement best describes the purpose of audit trails under PCI DS?
  • Before modifying any authentication credential (such as a password reset or token provisioning), what action must be performed?
  • Which technology is listed as an example of two-factor authentication?
  • Which sub-requirement focuses on monitoring and controlling all access to data?
  • Which statement best describes the goal of authentication policy documentation?
  • Which statement best describes the overarching requirement for protecting stored cardholder data from a policy perspective?
  • What does 3.6.6 require if manual clear-text key-management operations are used?
  • Time data must be protected; which option best reflects this requirement?
  • What must be in place for SSL/early TLS implementations prior to the transition date and for new implementations?
  • Which items are examples of insecure services, protocols, or ports?
  • Who should have access to audit trails?
  • What does PCI require for monitoring access to sensitive areas under 9.1.1?
  • Which PCI DSS requirement focuses on restricting and monitoring access to network resources and cardholder data?
  • Which item is an example of improper access control?
  • What does requirement say about storing media backups regarding location and security review?
  • How is an untrusted network defined in this context?
  • What is the maximum number of failed login attempts allowed before a user ID is locked out?
  • Which PCI DSS requirement maintains a policy that addresses information security for all personnel?
  • Which document details the additional PCI DSS requirements for Shared Hosting Providers?
  • Which statement best describes requirement 9.7.1 regarding media inventories?
  • Penetration testing should be conducted from which network perspectives?
  • What is a direct outcome of proper time synchronization across critical systems?
  • Which statement best describes the requirement for encrypting transmissions of cardholder data?
  • Internal penetration testing must be performed at least annually and after significant upgrades or modifications.
  • What does Requirement 3.6.1 specifically require?
  • Do not allow any direct connections inbound or outbound for traffic between the Internet and the cardholder data environment.
  • Which statement best describes the Issuer?
  • Which PCI DSS requirement covers protecting all systems against malware and regularly updating anti-virus software?
  • Do not disclose private IP addresses and routing information to unauthorized parties.
  • Which statement best describes vendor remote access controls under PCI DSS?
  • Which PCI DSS requirement specifically requires installing and maintaining a firewall configuration to protect cardholder data?
  • Which statement reflects requirement 9.8.1 regarding hard-copy materials?
  • Which PCI DSS requirement restricts access to cardholder data by business need to know?
  • Which sub-requirement requires establishing, documenting, and distributing security policies and procedures?
  • What function does the Acquirer provide to merchants?
  • Which signs indicate that a device may have been tampered with or substituted?
  • What does requirement 1.3 prohibit?
  • What does it require to define access needs for each role?
  • Which PCI DSS requirement is explicitly cited for logging and audit trails in the context of cardholder data environments?
  • Which PCI DSS requirement is about establishing and implementing firewall and router configuration standards?
  • What should be done to audit trail files to prevent tampering?
  • What should be described for network management responsibilities?
  • Which statement correctly describes the status of SSL and early TLS with respect to strong cryptography after 2016?
  • Which Appendix provides a worksheet for defining compensating controls?
  • What item must be included in the alerts used by the incident response process under 12.10.5?
  • Which organization examples are cited as current best practices to use for vulnerability management?
  • Testing must validate segmentation and scope-reduction controls. Which statement is true?
  • External penetration testing must be performed at least annually and after any significant upgrades or modifications.
  • Which statement about time synchronization across critical systems is true?
  • For systems not commonly affected by malicious software, what is required regarding anti-virus applicability?
  • Which requirement specifies maintaining strict control over the storage and accessibility of media?
  • Which statement about magnetic stripe data retention after authorization is true?
  • Which statement best describes suspicious behavior around payment devices?
  • Shared hosting providers must protect each entity's hosted environment and cardholder data and meet Appendix A: Additional PCI DSS Requirements for Shared Hosting Providers. Which option correctly reflects this obligation?
  • Which of the following is included in 10.2.5 regarding account management?
  • What is the recommended approach to server roles to minimize risk?
  • What does PCI DSS say about vulnerability lists 6.5.1-6.5.10 and best practices?
  • Which statement best represents a time data management requirement under PCI DSS?
  • What must be documented to specify privileges granted to a user?
  • Which PCI DSS requirement focuses on implementing an incident response plan to respond to a system breach?
  • What is the minimum password change interval?
  • Penetration testing scope must cover which of the following?
  • Which vulnerability is described by PCI DSS Requirement 6.5.5?
  • Which tools may be used to meet Requirement 10.6?
  • Two-factor authentication requires two of the three methods. Which statement is true?
  • What should you do with the initial credentials assigned to a user or after a reset?
  • Which risk assessment methodologies are provided as examples?
  • What is the requirement for firewall and router configurations in relation to untrusted networks?
  • What is the default setting described for the access control system?
  • Which statement best reflects wireless network security when transmitting cardholder data?
  • What does PCI DSS Requirement 6.5.6 require you to address?
  • For systems not commonly affected by malware, which action aligns with best practice regarding anti-virus applicability?
  • Which statement is accurate about the allocation of PCI DSS responsibilities under 12.8.5?
  • Which statement matches the anti-spoofing example described in the requirements?
  • Which sub-requirement requires establishing, documenting, and distributing security incident response and escalation procedures to ensure timely and effective handling of all situations?
  • Penetration testing must review threats and vulnerabilities experienced in the last 12 months.
  • Where should logs for external-facing technologies be written?
  • 12.3.5 requires?
  • Which PCI DSS requirement requires restricting physical access to cardholder data?
  • Which option is not a required element of change control procedures for patches?
  • Who must perform external vulnerability scans?
  • Which statement best describes PCI DSS 6.6 for public-facing web applications?
  • Improper error handling can lead to which risk?
  • Which statement accurately reflects SSL and early TLS policy after the transition date?
  • Which PCI DSS requirement ensures that the security policy and procedures clearly define information security responsibilities for all personnel?
  • Which type of data is categorized as Sensitive Authentication Data?
  • Use intrusion-detection and/or intrusion-prevention techniques to detect and/or prevent intrusions into the network. Monitor all traffic at the perimeter and critical points in the CDE, and alert personnel to suspected compromises. Keep IDS/IPS engines, baselines, and signatures up to date.
  • Which statement best describes the capabilities expected of anti-virus programs?
  • Which PCI DSS requirement focuses on identifying and authenticating access to system components?
  • Which statement about data retention and secure deletion is correct?
  • How often must firewall and router rule sets be reviewed?
  • Which statement is correct about annual acknowledgment under 12.6.2?
  • A risk assessment must identify which elements?
  • Which statement best describes controls over the distribution of media?
  • What is the primary reason to restrict access to a cardholder data environment?
  • What migration planning requirement applied to SSL or early TLS implementations is true for prior to the specified date?
  • What is the primary purpose of audit trails?
  • Which of the following is a Cardholder Data element?
  • What is required regarding firewall management policies?
  • Which practice describes Requirement 6.4.2 in PCI DSS?
  • Which PCI DSS requirement involves regularly testing security systems and processes?
  • Which sources are commonly cited as industry-accepted system hardening standards?
  • Before engaging service providers, 12.8.3 requires what?
  • As of June 30, 2015, which vulnerability becomes a formal requirement?
  • What should enforcement of onsite personnel and visitor identification procedures include?
  • If both hashed and truncated versions of the same PAN exist in an entity's environment, what must be in place?
  • Which term describes an organization that accepts the payment card for payment during a purchase?
  • What does emphasis on storage location and annual review of media backups imply?
  • Which timing requirement applies to removing or disabling inactive user accounts?
  • Which aspect is addressed when the access control system covers all system components?
  • What is required of cryptographic key custodians under the key management requirements?
  • Requirement 9.9 provides protection for devices that capture card data; when did this become a formal requirement?
  • Where must a firewall be located according to PCI requirements?
  • Which statement describes restricting physical access to network devices?
  • Which statement about Service Providers is correct?
  • What is stateful inspection in firewall filtering?
  • Which is an explicit example of time synchronization technology?
  • During initial PCI DSS compliance, which statement about quarterly vulnerability scans is true?
  • 6.4.5.4 requires what to ensure rollback capability?
  • What should be reviewed to identify anomalies or suspicious activity?
  • According to 12.6, awareness methods should vary based on what?
  • What action must be taken before applications become active or released to customers?
  • Which PCI DSS requirement emphasizes documenting security policies and procedures for restricting access to cardholder data?
  • PCI DSS 6.5.9 covers which threat?
  • Which requirement governs activation of remote-access technologies for vendors and business partners only when needed by vendors and business partners, with immediate deactivation after use?
  • Which issue is covered by PCI DSS Requirement 6.5.3?
  • For each role, which two elements must be defined regarding access?
  • Two-factor authentication examples include which option?
  • Which statement best reflects malware protection policy?
  • Which statement best describes the intent of Requirement 3.6 (key-management processes)?
  • What should happen to a user ID when access is no longer required due to termination or role change?
  • For wireless environments connected to the cardholder data environment, what action is required at installation?
  • Data retention and disposal policies for cardholder data storage must include which elements?
  • Which statement describes how access should be assigned with respect to job role and minimal privileges?
  • Which statement describes facility entry controls for the cardholder data environment?
  • Which PCI DSS requirement is associated with logging and audit trails that are unique to each entity's cardholder data environment?
  • Which device is explicitly cited as a secure cryptographic device for key storage?
  • Which practice best aligns with Requirement 3.5.3 for cryptographic keys?
  • Regarding 3.6.5, what is required when keys are retired or replaced and possibly retained?
  • Public keys do not require storage in one of these forms; which statement is true about public keys?
  • What is the primary objective of the requirement to prevent unauthorized substitution of cryptographic keys?
  • What does PCI DSS require regarding file-integrity monitoring for logs?
  • Which option is used to verify that a change does not adversely impact security?
  • Under 6.5.1, which types of injection flaws are considered?
  • What is the purpose of configuring system security parameters?
  • Which PCI DSS requirement addresses protecting stored cardholder data?
  • Which requirement mandates providing appropriate training to staff with security breach response responsibilities?
  • 10.2.5 requires tracking of which items?
  • Which statement describes vulnerability identification and risk ranking?
  • What policy describes outbound CHD traffic to the Internet?
  • Which item is NOT considered Cardholder Data?
  • In PCI DS, what is required for documentation and communication of physical access policies?
  • Which PCI DSS standard is primarily concerned with regularly monitoring and testing networks?
  • Which statement best describes time data in the PCI DSS context?
  • What must be maintained for wireless infrastructure to comply with the policy?
  • Deploy a change-detection mechanism to alert unauthorized modification of critical files, with weekly comparisons.
  • Which PCI DSS requirement covers developing and maintaining secure systems and applications?
  • Which action related to audit logs is specified as needing control?
  • Which Appendix name discusses compensating controls in PCI DSS?
  • In PCI DSS terminology, what does the term 'cardholder data environment' describe?
  • Requirement 12.10.3 mandates that an organization designate personnel to be available on a 24/7 basis to respond to security alerts.
  • Which PCI DSS requirement specifies automatic disconnect of remote-access sessions after inactivity?
  • Under PCI DSS, what is true about storing sensitive authentication data after authorization?
  • Which requirement ensures information security responsibilities are defined for all personnel?
  • From what source should time settings be obtained for security event logging?
  • What is the primary purpose of time synchronization in PCI DSS context?
  • Which action is explicitly associated with the audit logs and should be controlled?
  • Which requirement requires management approval for any and all media moved from a secured area?
  • What is required regarding access to audit trails?
  • Which information should be maintained about service providers under 12.8.5?
  • What must happen to access for onsite personnel upon termination?
  • Which statement describes 12.8.4's monitoring requirement?
  • Which method is acceptable for sending media to ensure traceability?
  • Which item includes sub-requirements 1.1.1 and 1.1.2?
  • Which PCI DSS requirement states to develop and maintain secure systems and applications?
  • What does assigning access based on job classification and function mean?
  • Which area is considered sensitive for monitoring access under facility controls?
  • In the context of hosted merchants or service providers, what process should be enabled to support investigations?
  • Which of the following describes how to enable services on a system?
  • Which statement best describes the relationship between key-management procedures and encryption of cardholder data?
  • What is the primary purpose of PCI DSS Standard 1?
  • If segmentation isolates the CDE, penetration tests must be performed at least annually and after changes to segmentation controls to verify segmentation methods are operational and isolate out-of-scope systems.
  • When handling media, which approach aligns with securing backups?
  • Which PCI DSS item requires a current network diagram that identifies all connections between the cardholder data environment and other networks, including any wireless networks?
  • What is the intended outcome of Requirement 7.3 in PCI DSS?
  • Which statement best describes the service provider acknowledgment required by PCI DSS Requirement 12.9?
  • What is required for internal vulnerability scans in the quarterly cycle?
  • Which PCI DSS requirement addresses the use of unique identities and authentication methods to access system components?
  • Which PCI DSS requirement focuses on proper user identification management for non-consumer users and administrators on all system components?
  • Which actions require audit trail coverage according to 10.2.2?
  • Which statement best describes the requirement for methods used to test for the presence of wireless access points?
  • Which statement about time data protection is correct?
  • Which term describes the mechanism to control device access to the network and cardholder data?
  • Before production systems become active, what must be done with test data and accounts?
  • How should non-console administrative access be protected?
  • Where should anti-virus software be deployed according to the practice guidelines?
  • Which item is NOT required to be included in the incident response plan under 12.10.1?
  • What is required by documenting approvals for privileges?
  • What is the main aim of restricting each entity's access to its own cardholder data environment?
  • Which statement describes secure software development requirements?
  • What must be reviewed at least daily under 10.6.1?
  • Which option best describes Requirement 3.6.3 for key storage?
  • Under Appendix A.1, which statement is true about hosting providers?
  • How should vendor IDs be managed when vendors need remote access to system components?
  • What is the purpose of maintaining a visitor log in this context?
  • Which statement about a visitor log is correct?
  • What separation is required between development and production environments?
  • Which technology is an example of time synchronization used for acquiring, distributing, and storing time?
  • According to 9.9.1, which information should be included in the device inventory?
  • What must be true about security policies and procedures for identification and authentication?
  • Which statement is accurate about 12.8.5's requirement?
  • What does Requirement 10.1 require regarding audit trails?
  • When a service is considered insecure but required, what should be done?
  • Which practice is required for first-time use credentials or after resets?
  • Penetration testing results and remediation activities must be retained.
  • What is the requirement for service providers that have remote access to customer premises?
  • Which PCI DSS requirement covers encrypting transmission of cardholder data across open, public networks?
  • Which statement describes how time should be acquired, distributed, and stored?
  • What must each entity ensure regarding processes and access to cardholder data environment under A.1.1?
  • Where can organizations find standards for key-management practices, such as guidance from NIST?
  • Which statement about vulnerability risk rankings is true?
  • Which statement best describes Requirement 3.6.2 for cryptographic keys?
  • Which PCI DSS requirement restricts physical access to cardholder data?
  • How often must personnel be educated under 12.6.1?
  • After a significant network change, which statement is true about scanning?
  • Which elements may be considered when ranking vulnerabilities?
  • What documentation is required for all services, protocols, and ports allowed?
  • Which PCI DSS requirement requires maintaining a policy that addresses information security for all personnel?
  • Where should audit trail files be backed up?
  • External vulnerability scans must be performed quarterly by which type of vendor?
  • Where should compensating controls be documented when used to meet a PCI DSS requirement?
  • What should be done with router configuration files?
  • Application-layer penetration tests should address which of the following?
  • Which of the following should be included in a service provider written agreement under 12.8.2?
  • Which statement about keys for stored cardholder data is true?
  • What is recommended for publicly accessible network jacks?
  • What does requirement 1.2.1 specify about inbound and outbound traffic?
  • What is required for access to the cardholder data environment in relation to job function and termination?
  • What should be included in personnel training about tampering and substitution?
  • Which statement is NOT an acceptable form for storing secret and private keys used to encrypt/decrypt cardholder data?
  • The incident response plan must cover which of the following components?
  • Which is NOT listed as an example of critical technologies?
  • What must PCI DSS require regarding inventory of system components?
  • In which scenario is background screening considered a recommendation rather than a requirement?
  • Which of the following is a Payment Brand example?
  • Which statement accurately describes the policy for visitors entering areas where cardholder data is processed?
  • Which diagram must exist to map cardholder data flows across systems and networks?
  • How often must passwords be changed?
  • Which PCI DSS requirement assigns to an individual or team the information security management responsibilities?
  • What is the primary purpose of implementing a DMZ in a network security architecture?
  • Which statement is correct about storing the card verification code after authorization?
  • What should procedures to distinguish onsite personnel and visitors include?
  • Which PCI DSS sub-requirement directs monitoring and distribution of security alerts to the appropriate personnel?
  • Which responsibility is associated with an Acquirer?
  • Which practice obscures IP addressing as part of network security controls?
  • Which statement best describes the requirements for maintaining anti-virus mechanisms?
  • Which term refers to the person who holds the payment card and initiates a purchase?
  • How long should the visitor log be retained, unless law requires otherwise?
  • Which action is a PCI DSS Standard 1 requirement?
  • According to the password policy, what is the minimum length and character requirement for passwords?
  • What is required regarding patching known vulnerabilities?
  • Before installing a system on the network, which security practice should be performed regarding vendor defaults?
  • Which statement best describes the requirement for critical system clocks?
  • Where should system components that store cardholder data be placed in relation to network zones?
  • Which entity issues payment cards on behalf of a Payment Brand?
  • Which requirement governs the control over the addition, deletion, and modification of user IDs, credentials, and other identifier objects?
  • For third-party repair or maintenance personnel, what action is required before granting access to devices?
  • Which statement best describes when compensating controls are used in PCI DSS?
  • PCI DSS 6.5.7 identifies which vulnerability?
  • How often must you monitor service providers' PCI DSS compliance status?
  • Which statement best describes the requirement for security policies and procedures protecting stored cardholder data?
  • Who must know the security policies and operational procedures?
  • Which statement accurately describes handling of insecure protocols in documentation?
  • Which statement best describes the requirement for security policies and procedures to monitor access to network resources and cardholder data?
  • What is the required minimum lockout duration, or when must an administrator re-enable a locked account?
  • What does the assignment of privileges to individuals based on job classification and function imply?
  • Which requirement covers assigning information security management responsibilities to individuals or teams?
  • Which PCI DSS requirement mandates regularly testing security systems and processes?
  • Which items must be included in an up-to-date list of devices per 9.9.1?
  • Daily review must include logs of all system components that store, process, or transmit CHD and/or SAD.
  • What is the purpose of having a current diagram of cardholder data flows?
  • Under PCI DSS, which requirement requires restricting access to cardholder data by business need to know?
  • Which option is a typical example for a time source in time synchronization?
  • 12.3.3 requires?
  • Which PCI DSS requirement addresses ensuring current network diagrams identify all connections between the cardholder data environment and other networks, including wireless networks?
  • Which statement best describes the aim of access control for system components and cardholder data?
  • What must be done with development, test, and custom application accounts before activation?
  • Which practice helps ensure separation of duties between development and production environments?
  • Under 3.6.4, when should cryptographic keys be changed?
  • Security policies and operational procedures for security monitoring and testing must be documented, in use, and known to all affected parties.
  • What is required about security policies and operational procedures for developing and maintaining secure systems and applications?
  • What should happen to a visitor's badge or identification before leaving the facility or at expiration?
  • What must be true about compensating controls when used?
  • Which practice is recommended when dealing with devices during maintenance?
  • What is the maximum number of PAN digits that can be displayed, and what note applies to POS receipts?
  • Which sub-requirement enumerates the need for a formal process for approving and testing network connections and changes to firewall configurations?
  • Which describes the due diligence before engaging service providers?
  • Which statement best describes the goal of Requirement 12.6 in PCI DSS?
  • Which statement best describes the PCI DSS requirement for security policies related to vendor defaults and other security parameters?
  • Which role processes a merchant's payment card transactions and forwards authorization requests to the Issuer?
  • Who should have access to audit trails?
  • Which constraints justify the use of compensating controls?
  • Which statement accurately reflects the restriction on group, shared, and generic IDs?
  • Change control procedures for security patches must include which element?
  • Which option represents the requirement for authentication for use of the technology?
  • How should media be sent to ensure it can be accurately tracked?
  • If there is an authorized business need to access cardholder data via remote-access technologies, what must the usage policies require?
  • Which statement best describes anti-spoofing measures?
  • What is the purpose of 12.10.6 in PCI DSS?
  • What does restricting access to privileged user IDs require?
  • 12.3.7 requires?
  • Which statement about time data is accurate?
  • Can multiple scan reports be combined to show quarterly coverage?
  • What should be done when unauthorized wireless access points are detected?
  • Which statement about encryption keys and key-encrypting keys is correct?
  • What is the retention requirement for video security data collected under facility monitoring?
  • Which PCI DSS requirement identifies and authenticates access to system components?
  • Masking PAN when displayed is implemented; which is true?
  • Which approach to software development security aligns with PCI DSS and industry best practice?
  • Under 10.2.1, which events must be captured by automated audit trails?
  • What is the stated policy for limiting repeated access attempts before a lockout occurs?
  • Inbound Internet traffic should be limited to IP addresses within which zone?
  • Which action helps reduce the attack surface by removing unnecessary functionality?
  • Which item is explicitly included in 12.10.1 as part of incident response planning?
  • For Requirement 12.2, how often is risk assessment performed and when else?
  • PCI DSS 6.5.8 addresses which security issue?
  • Which is the focus of PCI DSS Requirement 6.5.4?
  • Which statement best describes the policy for sending PANs using end-user messaging technologies?
  • Under PCI requirements, which statement best describes the policy for restricting physical access to cardholder data?
  • As of which date does the service provider acknowledgment requirement become mandatory?
  • Which statement best describes a Service Provider?
  • Under PCI DSS 6.5, which action is required to address vulnerabilities?
  • 12.3.1 requires?
  • When other authentication mechanisms are used, what must be ensured?
  • 6.4.5.3 requires what for changes?
  • What is the core principle of the access control system described as denying all by default unless allowed?
  • Within the incident response plan, which party must be notified at a minimum?
  • What process should be followed for changes to system components?
  • Periodic review of all other components should be based on what?
  • What is the default behavior of the access control system in terms of allowing access?
  • Which activity concerning system-level objects must be auditable?
  • In wireless environments connected to the cardholder data environment, which action should be taken at installation?
  • The penetration testing methodology should be based on an industry-accepted approach such as which of the following?
  • Which requirement is explicitly described as protecting all systems against malware and regularly updating anti-virus software or programs?
  • What must organizations maintain when dealing with service providers?
  • Inbound Internet traffic should be limited to IP addresses within the DMZ. Which option reflects this rule?
  • How should onsite personnel access to sensitive areas be controlled?
  • According to requirement 9.8, when should media be destroyed?
  • Which item is considered sensitive authentication data that should not be stored after authorization?
  • Which action should be taken immediately for any terminated users?
  • Which vulnerability type is addressed by PCI DSS Requirement 6.5.2?
  • To safeguard sensitive cardholder data during transmission over open networks, which of the following best describes the required control?
  • Which requirement states that vendor-supplied defaults for system passwords and other security parameters must not be used?
  • What is the purpose of Appendix C in the PCI DSS documentation?
  • Where should perimeter firewalls be installed in relation to wireless networks?
  • Which of the following is listed as an example of a critical technology?
  • After a significant change, which is required regarding scans?
  • If disk encryption is used instead of file- or column-level encryption, how should logical access and decryption keys be handled?
  • Which process should be enabled to support timely forensic investigation in the event of a compromise?
  • The service provider acknowledgement requirement may be satisfied by:
  • Which statement best describes the purpose of classifying media?
  • On which date did broken authentication and session management become a formal requirement?
  • What must be provided to visitors to distinguish them from onsite personnel and indicate expiration?
  • Which of the following would be considered a time source for synchronization?
  • Which statement best describes audit trail security under these requirements?
  • When transmitting data in transit, which statement correctly describes the requirement for encryption strength?
  • Requirement 10.2 mandates:
  • What is true regarding public-facing web applications and controls?
  • Which statement best describes the usage policy requirements across the seven sub-items?
  • What is the purpose of classifying media in terms of data handling?
  • Which of the following is true about firewall documentation and awareness?
  • As part of change control, what is required for approvals?
  • Which statement reflects PCI DSS requirement 6.4.3 about using production data for testing?
  • Which security function logs are included for daily review under 10.6.1?
  • Which sub-requirement requires monitoring and analyzing security alerts and information, and distributing them to appropriate personnel?
  • How should authentication credentials be protected during transmission and storage according to the policy?
  • Which policy mandates retaining audit trail history for at least one year, with a minimum of three months immediately available for analysis?
  • Which element must be included in usage policies?
  • Which statement best describes the requirement for mobile devices connecting to the network?
  • Under PCI DSS 6.6, which activity is recommended to protect public-facing web applications?
  • Which PCI DSS control specifies the addition, deletion, and modification of user IDs, credentials, and other identifier objects?
  • In secure coding, developers should understand how sensitive data is handled in memory. Which option reflects this statement?
  • Under the form requirements for storing secret and private keys, which method is acceptable for protecting keys used to encrypt/decrypt cardholder data?
  • Which PCI DSS requirement tracks and monitors all access to network resources and cardholder data?
  • What should be developed for all system components to address vulnerabilities and align with industry-accepted hardening standards?
  • Which statement best describes the basis for temporarily disabling anti-virus protection?
  • Under Requirement 3.5.1, how should access to cryptographic keys be restricted?
  • Which statement accurately reflects the handling of generic user IDs and shared IDs in system administration?
  • Which requirement prohibits copying, moving, and storing cardholder data onto local drives and removable media unless explicitly authorized for a defined business need?
  • Network-layer tests must include components that support network functions as well as operating systems.
  • Exploitable vulnerabilities found during penetration testing are corrected and testing is repeated to verify the corrections.
  • Which PCI DSS standard is focused on maintaining a vulnerability management program?
  • Which action satisfies requirement 9.8.2 for electronic media?
  • Which event types must be collected and monitored as part of audit trails?
  • Which sub-requirement requires establishing, documenting, and distributing security policies and procedures?
  • What must be tested for on a quarterly basis to manage wireless security?
  • What does 12.7 require regarding screening before hire?
  • What is required regarding vendor-supplied defaults and unnecessary default accounts before installing a system?
  • What are the requirements for code reviews prior to release?
  • Requirement 9.9 applies to which devices in card-present transactions?
  • Two-factor authentication is required for remote network access from outside the network by personnel and all third parties.
  • Which sub-requirement comprises PCI DSS Requirement 1.1?
  • Which set of methods may be used to detect and identify wireless devices?
  • Which approach is required for distributing media?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy