QIR Practice Exam Questions
PCI Stands for? - >>>>Payment Card Industry
CDE stands for... - >>>>Cardholder Data Environment
PCI-SSC stands for? - >>>>Payment Card Industry-Security Standards Council
DSS Stands for? -
...
QIR Practice Exam Questions
PCI Stands for? - >>>>Payment Card Industry
CDE stands for... - >>>>Cardholder Data Environment
PCI-SSC stands for? - >>>>Payment Card Industry-Security Standards Council
DSS Stands for? - >>>>Data Security Standard
PCI DSS covers... - >>>>12 points that Merchants and Service Providers must comply with the
be PCI Certified.
PA-DSS stands for? - >>>>Payment Application-Data Security Standard
PA-DSS certification denotes that... - >>>>the payment application can be configured to meet
PCI DSS requirements.
PA-DSS covers... - >>>>Secure payment applications to support PCI DSS compliance. Payment
application receives account data from PIN-entry devices (PEDs) or other devices and begins
payment transaction
PA-DSS applies to application that perform ____________________ and/or
___________________. - >>>>authorization
settlement
PA-DSS has ___________ requirements - >>>>14
PCI-DSS has ______________ requirements and ____________ goals - >>>>12
6
True or False - PA-DSS supports PCI-DSS - >>>>True
in many requirements but not all apply
True or False - PCI-DSS does not require all transmission of cardholder data be encrypted over
open, public networks. - >>>>False
It is encryption IS required over public networks according to PCI-DSS requirement 4.
True or False - Default passwords are sometimes allowed under certain circumstances with
proper documentation. - >>>>False
Default passwords are NEVER allowed in a Qualified Implementation
Video logs must be kept ___________ days. - >>>>90
True or False - Media does not mean paper - >>>>False
Media can mean paper or electronic media
Audit logs must be kept for ____________ - >>>>1 year
True or False - QIRs are also required to provide troubleshooting for the Payment application -
>>>>False
QIRs may perform troubleshooting and remote support after the installation but it is not required.
The LEAD QIR is responsible for these 4 things... - >>>>(1) Document all tasks that both the
customer and QIR perform
(2) Confirm the responsibilities of the QIR during and after the Implementation
(3) Accept accountability for all tasks
(4) Sign the Implementation Statement
[Show More]