Pass the PCI SSC PCI Qualified Professionals QSA_New_V4 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

An entity wants to know if the Software Security Framework can be leveraged during their assessment. Which of the following software types would this apply to?

Options:

A.

Any payment software in the CDE.


B.

Only software which runs on PCI PTS devices.


C.

Validated Payment Applications that are listed by PCI SSC and have undergone a PA-DSS assessment.


D.

Software developed by the entity in accordance with the Secure SLC Standard.


Expert Solution
Questions # 12:

Which of the following is true regarding compensating controls?

Options:

A.

A compensating control is not necessary if all other PCI DSS requirements are in place.


B.

A compensating control must address the risk associated with not adhering to the PCI DSS requirement.


C.

An existing PCI DSS requirement can be used as compensating control if it is already implemented.


D.

A compensating control worksheet is not required if the acquirer approves the compensating control.


Expert Solution
Questions # 13:

What should the assessor verify when testing that cardholder data Is protected whenever It Is sent over open public networks?

Options:

A.

The security protocol Is configured to accept all digital certificates.


B.

A proprietary security protocol is used.


C.

The security protocol accepts only trusted keys.


D.

The security protocol accepts connections from systems with lower encryption strength than required by the protocol.


Expert Solution
Questions # 14:

In the ROC Reporting Template, which of the following is the best approach for a response where the requirement was “In Place”?

Options:

A.

Details of the entity’s project plan for implementing the requirement.


B.

Details of how the assessor observed the entity's systems were compliant with the requirement.


C.

Details of the entity's reason for not implementing the requirement.


D.

Details of how the assessor observed the entity's systems were not compliant with the requirement.


Expert Solution
Questions # 15:

Which of the following can be sampled for testing during a PCI DSS assessment?

Options:

A.

PCI DSS requirements and testing procedures.


B.

Compensating controls.


C.

Business facilities and system components.


D.

Security policies and procedures.


Expert Solution
Questions # 16:

What must be included in an organization's procedures for managing visitors?

Options:

A.

Visitors are escorted at all times within areas where cardholder data is processed or maintained.


B.

Visitor badges are identical to badges used by onsite personnel.


C.

Visitor log includes visitor name, address, and contact phone number.


D.

Visitors retain their identification (for example, a visitor badge) for 30 days after completion of the visit.


Expert Solution
Questions # 17:

Viewing of audit log files should be limited to?

Options:

A.

Individuals who performed the logged activity.


B.

Individuals with read/write access.


C.

Individuals with administrator privileges.


D.

Individuals with a job-related need.


Expert Solution
Questions # 18:

A "Partial Assessment" is a new assessment result. What is a “Partial Assessment"?

Options:

A.

A ROC that has been completed after using an SAQ to determine which requirements should be tested, as per FAQ 1331.


B.

An interim result before the final ROC has been completed.


C.

A term used by payment brands and acquirers to describe entities that have multiple payment channels, with each channel having its own assessment.


D.

An assessment with at least one requirement marked as “Not Tested".


Expert Solution
Questions # 19:

An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA, while also ensuring that the customized control is implemented securely. Which of the following statements is true?

Options:

A.

You can assess the customized control, but another assessor must verify that you completed the TRA correctly.


B.

You can assess the customized control and verify that the customized approach was correctly followed, but you must document this in the ROC.


C.

You must document the work on the customized control in the ROC, but you can not assess the control or the documentation.


D.

Assessors are not allowed to assist an entity with the completion of the Controls Matrix or the TRA.


Expert Solution
Questions # 20:

Where can live PANs be used for testing?

Options:

A.

Production (live) environments only.


B.

Pre-production (test) environments only if located outside the CDE.


C.

Pre-production environments that are located within the CDE.


D.

Testing with live PANs must only be performed in the QSA Company environment.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions