PCI SSC Assessor_New_V4 Sample Questions:
1. What does the PCI PTS standard cover?
A) Development of strong cryptographic algorithms
B) Secure coding practices for commercial payment applications.
C) Point-of-interaction devices used to protect account data
D) End-to-end encryption solutions for transmission of account data
2. Which of the following meets the definition of 'quarterly' as indicated in the description of timeframes used in PCI DSS requirements?
A) On the 1st of each fourth month
B) Occurring at some point in each quarter of a year
C) On the 15th of each third month
D) At least once every 95 97 days.
3. Assigning a unique ID to each person is intended to ensure?
A) Strong passwords are used for each user account
B) Shared accounts are only used by administrators
C) Individual users are accountable for their own actions
D) Access is assigned to group accounts based on need-to-know
4. Which of the following statements is true whenever a cryptographic key is retired and replaced with a new key?
A) All data encrypted under the retired key must be securely destroyed
B) The retired key must not be used for encryption operations
C) Cryptographic key components from the retired key must be retained for 3 months before disposal
D) A new key custodian must be assigned
5. What do PCI DSS requirements for protecting cryptographic keys include?
A) Private or secret keys must be encrypted, stored within an SCD or stored as key components
B) Key-encrypting keys and data-encrypting keys must be assigned to the same key custodian
C) Public keys must be encrypted with a key-encrypting key.
D) Data-encrypting keys must be stronger than the key-encrypting key that protects it.
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: C | Question # 3 Answer: C | Question # 4 Answer: B | Question # 5 Answer: A |
We're so confident of our products that we provide no hassle product exchange.


By Baldwin

