PCI fundamentals (2022/2023) Graded A
PCI fundamentals (2022/2023) Graded A
ASV ✔✔Approved Scanning Vendor
PCI ✔✔Payment Card Industry
PTS ✔✔PIN Transaction Security (device)
QSA ✔✔Qualified Security Assessor
ROC ✔✔Report on Compilance
ROV ✔✔Report on Validation
QIR ✔✔Qualified Integrator Reseller
Which entity is responsible for developing and enforcing compliance programs? ✔✔Payment
Brands
Which entity is responsible for forensic investigations of account data compromise? ✔✔Payment
Brands
Which entity is response to Accept validation documentation from QSAs, PA-QSAs and ASVs
✔✔Payment Brands
Which entity is response Endorse QSA, PA-QSA and ASV company qualification criteria
✔✔Payment Brands
Merchant obligations may include submitting their compliance status to multiple entities. True or
false? ✔✔True
The decision about a merchant's level is made by the ✔✔Merchant's aquirer
Level 1 and 2 merchants must include ___________ as part of their PCI DSS compliance
validation reporting process? ✔✔Level 1 and 2 merchants need quarterly external vulnerability
scans to be performed by an ASV. Level 2 merchants may use SAQs to validate compliance.
SAQ ✔✔Self-assessment Questionaire
Type of SAQ? Card-Not-Present (e-commerce or MO/TO) merchants, all cardholder data
functions outsourced to PCI DSS compliant service providers.
Not applicable to face-to-face channels. ✔✔A
Type of SAQ? E-commerce merchants who outsource all payment processing to PCI DSS
validated third parties, and who have a website(s) that doesn't directly receive cardholder data
but that can impact the security of the payment transaction. No electronic storage, processing, or
transmission of any cardholder data on the merchant's systems or premises.
Applicable only to e-commerce channels. ✔✔A-EP
Type of SAQ? Imprint-only merchants with no electronic cardholder data storage, or standalone,
dial-out terminal merchants with no electronic cardholder data storage.
Not applicable to e-commerce channels. ✔✔B
Type of SAQ? Merchants using only stand-alone, PTS-approved payment terminals with an IP
connection to the payment processor, with no electronic cardholder data storage.
Not applicable to e-commerce channels. ✔✔B-IP
Type of SAQ? Merchants with segmented payment application systems connected to the
Internet, with no electronic cardholder data storage.
Not applicable to e-commerce channels. ✔✔C
Category | Exams and Certifications |
Comments | 0 |
Rating | |
Sales | 0 |