PCI
QSA_New_V4
Q1:
What do PCI DSS requirements for protecting cryptographic keys include?
○
A
Public keys must be encrypted with a key-encrypting key.○
B
Data-encrypting keys must be stronger than the key-encrypting key that protects it.○
C
Private or secret keys must be encrypted, stored within an SCD, or stored as key components.○
D
Key-encrypting keys and data-encrypting keys must be assigned to the same key custodian.
PCI
QSA_New_V4
Q2:
Which of the following meets the definition of "quarterly" as Indicated In the description of timeframes used In PCI DSS requirements?
○
A
Occurring at some point in each quarter of a year.○
B
At least once every 95-97 days○
C
On the 15th of each third month.○
D
On the 1st of each fourth month.
PCI
QSA_New_V4
Q3:
An organization wishes to implement multi-factor authentication for remote access, using the user's Individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?
○
A
Certificates are assigned only to administrative groups, and not to regular users.○
B
A different certificate is assigned to each individual user account, and certificates are not shared.○
C
Certificates are logged so they can be retrieved when the employee leaves the company.○
D
Change control processes are In place to ensure certificates are changed every 90 days.
PCI
QSA_New_V4
Q4:
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?
○
A
User access to the database Is only through programmatic methods.○
B
User access to the database Is restricted to system and network administrators.○
C
Application IDs for database applications can only be used by database administrators.○
D
Direct queries to the database are restricted to shared database administrator accounts.
PCI
QSA_New_V4
Q5:
Which statement about the Attestation of Compliance (AOC) is correct?
○
A
There are different AOC templates for service providers and merchants.○
B
The AOC must be signed by both the merchant/service provider and by PCI SSC.○
C
The same AOC template is used W ROCs and SAQs.○
D
The AOC must be signed by either the merchant/service provider or the QSA/ISA.