100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4,6 TrustPilot
logo-home
Exam (elaborations)

PCI-DSS Fundamentals questions & answer 2023

Rating
-
Sold
-
Pages
7
Grade
A+
Uploaded on
29-12-2022
Written in
2022/2023

PCI-DSS Fundamentals questions & answer 2023Methods for Stealing Payment card data include: a) Weak Passwords b) Malware c) Physical skimming d) All of the options are correct d) All of the options are correct The PCI DSS applies to: a) Any entity that stores, processes, or transmits payment card account data b) Service Providers only c) Merchants only d) Merchants and third party processors (TTPs) only a) Any entity that stores, processes, or transmits payment card account data The PCI DSS applies to: a) Any entity that stores, processes, or transmits payment card account data b) Service Providers only c) Merchants only d) Merchants and third party processors (TTPs) only a) Any entity that stores, processes, or transmits payment card account data The P2PE Standard Covers: a) Secure payment applications for processing transactions b) Encryption, decryption, and key management requirements for point-to-point encryption solutions c) Physical security requirements for manufacturing payment cards d) Mechanisms used to protect the PIN and encrypted PIN Blocks b) Encryption, decryption, and key management requirements for point-to-point encryption solutions The standard for validating off-the-shelf payment applications used in authorizations and settlement is: a) PCI P2PE b) PA-DSS c) PCI PTS d) PCI DSS b) PA-DSS Merchants using PA-DSS validated payment applications are automatically PCI DSS compliant. a) True b) False b) False Which of the below functions is associated with acquirers? a) Provide settlement services to a merchant b) Provide clearing services to a merchant c) Provide authorization services to a merchant d) All of the options d) All of the options Which of the following entities will ultimately approve a purchase? a) Issuer b) Acquirer c) Payment Transaction Gateway d) Merchant a) Issuer Which step does the payment brand network provide complete reconciliation to the merchants' bank? a) Settlement b) Authorization c) Approval d) Clearing d) Clearing A company that _____________________ is considered to be a service provider. a) Controls or could impact the security of another entity's cardholder data b) Is a payment card brand c) Is a founding member of PCI SSC d) Is not also a merchant a) Controls or could impact the security of another entity's cardholder data Which of the following are examples of service providers? (choose all that apply) a) Data Center hosting providers b) Telcom providers (only communication link) c) Payment Gateways d) ISOs a) Data Center hosting providers c) Payment Gateways d) ISOs Which of the following are parts of the Payment Brand role? (Select all that apply) a) Offer training for QSAs, PA-QSA and ASVs b) Endorse QSA, PA-QSA and ASV company qualification criteria c) Develop and enforce compliance programs d) Accept validation documentation from QSAs, PA-QSA and ASVs b) Endorse QSA, PA-QSA and ASV company qualification criteria c) Develop and enforce compliance programs d) Accept validation documentation from QSAs, PA-QSA and ASVs Merchant obligations may include submitting their compliance status to multiple entities. a) True b) False a) True The decision about a merchant's level is made by the : a) Merchant's acquirer b) Merchant's QSA c) Merchant d) Payment Brands a) Merchant's acquirer Level 1 and 2 merchants must include ______________ as part of their PCI DSS compliance validation reporting process? a) A report from their QSA b) sensitive authentication data (SAD) c) ASV scan results d) A copy of their risk assessment c) ASV scan results Which SAQ best applies to the entities below? (Assume that none of the entities store any cardholder data electronically) Service provider using only web-based virtual terminal MO/TO merchant with all payment functions outsourced to a compliant service provider Merchant with standalone payment application connected to the internet Merchant with only card-present dial-out terminals Service provider using only web-based virtual terminal SAQ D MO/TO merchant with all payment functions outsourced to a compliant service provider SAQ A Merchant with standalone payment application connected to the internet SAQ C Merchant with only card-present dial-out terminals SAQ D Which SAQ best applies to the entities below? (Assume that none of the entities store any cardholder data electronically) Merchant who is using a validated P2PE solution listed on the PCI SSC website An online merchant with a payment page that accepts cardholder data, but transmits the data to a PCI DSS-compliant service provider An online merchant that displays a PCI-DSS-compliant service provider's payment page in a IFRAME, all page content is from PSP. Merchant using an end-to-end encryption solution (E2EE) that utilizes PCI PTC-approved POI devices which communicate with the acquirer over an IP network. Merchant who is using a validated P2PE solution listed on the PCI SSC website SAQ P2PE An online merchant with a payment page that accepts cardholder data, but transmits the data to a PCI DSS-compliant service provider SAQ-A-EP An online merchant that displays a PCI-DSS-compliant service provider's payment page in a IFRAME, all page content is from PSP. SAQ-A Merchant using an end-to-end encryption solution (E2EE) that utilizes PCI PTC-approved POI devices which communicate with the acquirer over an IP network. SAQ B-IP Which of the following could PA-DSS apply to? a) Custom payment application endorsed by the PCI SSC b) Third-party payment application designed for one company c) Third-party, "off-the-shelf" payment application d) Custom payment application used by one company c) Third-party, "off-the-shelf" payment application The presumption of P2PE is that: a) The data connect be decrypted between the source and the destination points b) The data can never be decrypted c) The data can be decrypted between the source and the destination points d) Any entity in possession of the ciphertext can easily reversed the encryption process. a) The data connect be decrypted between the source and the destination points Merchants using P2PE solutions are still required to validate to PCI-DSS a) True b) False a) True Which entity is responsible for developing and enforcing compliance programs? a) Issuers b) Acquirers c) PCI SSC d) Payment card brands d) Payment card brands Which entity is responsbile for forensic investigations of account data compromise? a) Payment brands b) QSA/ISA c) PCI SSC d) QIR a) Payment brands Account data consists of _______________and _________________? a) Cardholder Names, PANs b) PANs, PINs c) Cardholder Data, PANs d) Cardholder Data, Sensitive Authentication Data d) Cardholder Data, Sensitive Authentication Data

Show more Read less
Institution
PCI DSS
Course
PCI DSS









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
PCI DSS
Course
PCI DSS

Document information

Uploaded on
December 29, 2022
Number of pages
7
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BravelRadon Havard School
View profile
Follow You need to be logged in order to follow users or courses
Sold
903
Member since
4 year
Number of followers
540
Documents
44762
Last sold
2 days ago
EXAM HUB

Welcome to Exam Hub Are you looking for high-quality, exam-ready notes, past papers, Test Banks, and well-researched study materials to boost your grades? You’re in the right place! I create and upload detailed, easy-to-understand, and well-structured documents across multiple subjects. All my materials are designed to help you study , save time, and excel in your coursework and exams! On this page NURSING EXAMS,STUDY GUIDES,TESTBANKS AND QUALITY EXAMS IS THE KEY TO STUDENTS CAREER EXCELLENCE, you find all documents, package deals, and flashcards offered by BravelRadon (EXAM HUB STORES!)....kindly recommend a friend for A+ GARANTEEd either you are a first-year student or final-year graduation! best of luck!

Read more Read less
3.5

159 reviews

5
57
4
30
3
33
2
8
1
31

Trending documents

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can immediately select a different document that better matches what you need.

Pay how you prefer, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card or EFT and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions