New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

Assessor_New_V4 Assessor_New_V4 Exam Questions and Answers

Questions 4

Which of the following is true regarding compensating controls?

Options:

A.

A compensating control is not necessary if all other PCI DSS requirements are in place

B.

A compensating control must address the risk associated with not adhering to the PCI DSS requirement

C.

An existing PCI DSS requirement can be used as compensating control if it is already implemented

D.

A compensating control worksheet is not required if the acquirer approves the compensating control

Buy Now
Questions 5

According to requirement 1, what is the purpose of "Network Security Controls?

Options:

A.

Manage anti-malware throughout the CDE.

B.

Control network traffic between two or more logical or physical network segments.

C.

Discover vulnerabilities and rank them

D.

Encrypt PAN when stored

Buy Now
Questions 6

Which of the following is a requirement for multi-tenant service providers?

Options:

A.

Ensure that customers cannot access another entity s cardholder data environment

B.

Provide customers with access to the hosting provider s system configuration files.

C.

Provide customers with a shared user ID for access to critical system binaries

D.

Ensure that a customer's log files are available to all hosted entities

Buy Now
Questions 7

Security policies and operational procedures should be?

Options:

A.

Encrypted with strong cryptography

B.

Stored securely so that only management has access

C.

Reviewed and updated at least quarterly

D.

Distributed to and understood by all affected parties

Buy Now
Questions 8

What must the assessor verify when testing that PAN is protected whenever it is sent over the Internet?

Options:

A.

The security protocol is configured to support earlier versions

B.

The PAN is encrypted with strong cryptography

C.

The security protocol is configured to accept all digital certificates

D.

The PAN is securely deleted once the transmission has been sent

Buy Now
Questions 9

An entity accepts e-commerce payment card transactions and stores account data in a database The database server and the web server are both accessible from the Internet The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements7

Options:

A.

The web server and the database server should be installed on the same physical server

B.

The database server should be relocated so that it is not accessible from untrusted networks

C.

The web server should be moved into the internal network

D.

The database server should be moved to a separate segment from the web server to allow for more concurrent connections

Buy Now
Questions 10

A network firewall has been configured with the latest vendor security patches What additional configuration is needed to harden the firewall?

Options:

A.

Remove the default 'Firewall Administrator account and create a shared account for firewall administrators to use.

B.

Configure the firewall to permit all traffic until additional rules are defined

C.

Synchronize the firewall rules with the other firewalls m the environment

D.

Disable any firewall functions that are not needed in production

Buy Now
Questions 11

Which scenario describes segmentation of the cardholder data environment (CDE) for the purposes of reducing PCI DSS scope?

Options:

A.

Routers that monitor network traffic flows between the CDE and out-of-scope networks

B.

Firewalls that log all network traffic flows between the CDE and out of-scope networks

C.

Virtual LANs that route network traffic between the CDE and out-of-scope networks

D.

A network configuration that prevents all network traffic between the CDE and out-of-scope networks

Buy Now
Questions 12

An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity's PCI DSS assessment?

Options:

A.

It automatically makes an entity PCI DSS compliant

B.

It may help the entity to meet several requirements in Requirement 6.

C.

There is no impact to the entity

D.

The custom software can be excluded from the PCI DSS assessment

Buy Now
Questions 13

At which step in the payment transaction process does the merchants bank pay the merchant for the purchase and the cardholder s bank bill the cardholder?

Options:

A.

Authorization

B.

Clearing

C.

Settlement

D.

Chargeback

Buy Now
Questions 14

Which statement is true regarding the use of intrusion detection techniques, such as intrusion detection systems and/or intrusion protection systems (IDS'IPS)?

Options:

A.

Intrusion detection techniques are required on all system components

B.

Intrusion detection techniques are required to alert personnel of suspected compromises

C.

Intrusion detection techniques are required to isolate systems in the cardholder data environment from all other systems

D.

Intrusion detection techniques are required to identify all instances of cardholder data

Buy Now
Questions 15

If an entity shares cardholder data with a TPSP, what activity is the entity required to perform'?

Options:

A.

The entity must conduct ASV scans on the TPSP's systems at least annually

B.

The entity must perform a risk assessment of the TPSP's environment at least quarterly.

C.

The entity must test the TPSP's incident response plan at least quarterly

D.

The entity must monitor the TPSP's PCI DSS compliance status at least annually

Buy Now
Questions 16

Which of the following is an example of multi-factor authentication?

Options:

A.

A token that must be presented twice during the login process

B.

A user passphrase and an application level password.

C.

A user password and a PIN-activated smart card

D.

A user fingerprint and a user thumbprint

Buy Now
Questions 17

Which of the following parties is responsible for completion of the Controls Matrix for the Customized Approach?

Options:

A.

Only a Qualified Security Assessor (QSA)

B.

Either a QSA, AQSA, or PClP.

C.

Entity being assessed

D.

Card brands or acquirer

Buy Now
Questions 18

Which of the following can be sampled for testing during a PCI DSS assessment?

Options:

A.

PCI DSS requirements and testing procedures.

B.

Compensating controls

C.

Business facilities and system components

D.

Security policies and procedures

Buy Now
Exam Code: Assessor_New_V4
Exam Name: Assessor_New_V4 Exam
Last Update: Dec 21, 2024
Questions: 60
Assessor_New_V4 pdf

Assessor_New_V4 PDF

$25.5  $84.99
Assessor_New_V4 Engine

Assessor_New_V4 Testing Engine

$30  $99.99
Assessor_New_V4 PDF + Engine

Assessor_New_V4 PDF + Testing Engine

$40.5  $134.99