Get Real Assessor_New_V4 Quesions Pass PCI SSC Certification Exams Easily [Q13-Q36]

Share

Get Real Assessor_New_V4 Quesions Pass PCI SSC Certification Exams Easily

Assessor_New_V4 Dumps are Available for Instant Access

NEW QUESTION # 13
According to the glossary, bespoke and custom software describes which type of software?

  • A. Software developed by an entity for the entity's own use
  • B. Virtual payment terminals
  • C. Any software developed by a third party that can be customized by an entity.
  • D. Any software developed by a third party

Answer: A

Explanation:
Explanation
According to the glossary, bespoke and custom software describes software developed by an entity for its own use, which means it should not be shared with other entities or sold or transferred without proper authorization. This is one of the requirements for ensuring that bespoke and custom software meets all the security standards and controls defined in Appendix E of the PCI DSS v3.2.1 Quick Reference Guide1.


NEW QUESTION # 14
An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?

  • A. Certificates are logged so they can be retrieved when the employee leaves the company
  • B. Certificates are assigned only to administrative groups and not to regular users
  • C. A different certificate is assigned to each individual user account, and certificates are not shared
  • D. Change control processes are in place to ensue certificates are changed every 90 days

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, a different certificate is assigned to each individual user account, and certificates are not shared. This is one of the requirements for preventing unauthorized access to cardholder data using digital certificates.


NEW QUESTION # 15
An internal NTP server that provides lime services to the Cardholder Data Environment is?

  • A. Only in scope if it provides time services to database servers.
  • B. Not in scope for PCI DSS
  • C. Only m scope if it stores processes or transmits cardholder data
  • D. In scope for PCI DSS

Answer: D

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, an internal NTP server that provides time services to the cardholder data environment is in scope for PCI DSS if it stores processes or transmits cardholder data, regardless of whether it provides authentication services to systems in the DMZ or not. This is one of the requirements for preventing unauthorized access to cardholder data using time services.


NEW QUESTION # 16
H an entity shares cardholder data with a TPSP, what activity is the entity required to perform'?

  • A. The entity must perform a risk assessment of the TPSP's environment at least quarterly.
  • B. The entity must test the TPSP's incident response plan at least quarterly
  • C. The entity must conduct ASV scans on the TPSP's systems at least annually
  • D. The entity must monitor the TPSP's PCI DSS compliance status at least annually

Answer: D

Explanation:
Explanation
According to requirement 4, an entity must monitor its TPSP's PCI DSS compliance status at least annually, which means it should review its TPSP's policies and procedures for protecting cardholder data and transactions against fraud and other threats at least once a year. This is one of the requirements for ensuring that an entity monitors its TPSP's PCI DSS compliance status regularly.


NEW QUESTION # 17
An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?

  • A. Certificates are logged so they can be retrieved when the employee leaves the company
  • B. Certificates are assigned only to administrative groups and not to regular users
  • C. A different certificate is assigned to each individual user account, and certificates are not shared
  • D. Change control processes are in place to ensue certificates are changed every 90 days

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, a different certificate is assigned to each individual user account, and certificates are not shared. This is one of the requirements for preventing unauthorized access to cardholder data using digital certificates.


NEW QUESTION # 18
Which of the following file types must be monitored by a change-detection mechanism (for example, a file-integrity monitoring tool)?

  • A. Security policy and procedure documents
  • B. Files that regularly change
  • C. System configuration and parameter files
  • D. Application vendor manuals

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, system configuration and parameter files must be monitored by a change-detection mechanism (for example, a file-integrity monitoring tool). This is one of the requirements for ensuring that changes to system configuration and parameter files are detected and verified.


NEW QUESTION # 19
an entity under assessment is using the customized approach, which of the following steps is the responsibility of the assessor?

  • A. Perform the targeted risk analysis as per PCI DSS requirement 12.3.2
  • B. Document and maintain evidence about each customized control as defined in Appendix E of PCI DSS
  • C. Derive testing procedures and document them in Appendix E of the ROC.
  • D. Monitor the control.

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, the assessor must derive testing procedures and document them in Appendix E of the ROC. This is one of the requirements for ensuring that testing procedures are defined and documented.


NEW QUESTION # 20
According torequirement 1,what is the purpose of "Network Security Controls?

  • A. Discover vulnerabilities and rank them
  • B. Manage anti-malware throughout the CDE.
  • C. Encrypt PAN when stored
  • D. Control network traffic between two or more logical or physical network segments.

Answer: D

Explanation:
Explanation
According to requirement 1, network security controls are intended to control network traffic between two or more logical or physical network segments, which means they should prevent unauthorized access, modification, or disclosure of cardholder data or transactions over the network. This is one of the requirements for ensuring that network security controls are implemented and maintained in accordance with PCI DSS.


NEW QUESTION # 21
Which of the following is a requirement for multi-tenant service providers?

  • A. Provide customers with access to the hosting provider s system configuration files.
  • B. Ensure that a customer's log files are available to all hosted entities
  • C. Provide customers with a shared user ID for access to critical system binaries
  • D. Ensure that customers cannot access another entity s cardholder data environment

Answer: D

Explanation:
Explanation
According to requirement 3.1.2, multi-tenant service providers must ensure that customers cannot access another entity's cardholder data environment, which means they should isolate each customer's cardholder data from other customers' cardholder data and prevent unauthorized access or disclosure. This is one of the requirements for ensuring that multi-tenant service providers protect each customer's cardholder data.


NEW QUESTION # 22
An entity wants to know if the Software Security Framework can be leveraged during their assessment Which of the following software types would this apply to?

  • A. Any payment software in the CDE
  • B. Validated Payment Applications that are listed by PCI SSC and have undergone a PA-DSS assessment
  • C. Only software which runs on PCI PTS devices
  • D. Software developed by the entity in accordance with the Secure SLC Standard

Answer: D

Explanation:
Explanation
According to requirement 12.3.2, software developed by an entity in accordance with the Secure SLC Standard must be validated by a Qualified Security Assessor (QSA) before it can be used by an entity in its CDE. This is one of the requirements for ensuring that software developed by an entity in accordance with the Secure SLC Standard meets all the security standards and controls defined in Appendix E of the PCI DSS v3.2.1 Quick Reference Guide1.


NEW QUESTION # 23
Which of the following statements is true whenever a cryptographic key is retired and replaced with a new key?

  • A. All data encrypted under the retired key must be securely destroyed
  • B. Cryptographic key components from the retired key must be retained for 3 months before disposal
  • C. The retired key must not be used for encryption operations
  • D. A new key custodian must be assigned

Answer: A

Explanation:
Explanation
According to requirement 4, when a cryptographic key is retired and replaced with a new key, all data encrypted under the retired key must be securely destroyed, which means it should be overwritten with random data or deleted from the storage device. This is one of the requirements for ensuring that data encryption keys are not reused or compromised.


NEW QUESTION # 24
At which step in the payment transaction process does the merchants bank pay the merchant for the purchase and the cardholder s bank bill the cardholder?

  • A. Chargeback
  • B. Authorization
  • C. Settlement
  • D. Clearing

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, settlement occurs when a merchant receives payment from a card issuer for a completed transaction and delivers goods or services to a customer or another party as agreed upon in advance by both parties, subject to any conditions imposed by either party upon delivery or payment, including but not limited to acceptance, rejection, return, exchange, refund, cancellation, modification, suspension, termination or revocation by either party upon delivery or payment; or any other conditions imposed by either party upon delivery or payment; or any other conditions imposed by either party upon delivery or payment; or any other conditions imposed by either party upon delivery or payment;


NEW QUESTION # 25
What would be an appropriate strength for the key-encrypting key (KEK) used to protect an AES 128 bit data-encrypting key (DEK)

  • A. ROT 13
  • B. RSA512
  • C. AES 128
  • D. DES256

Answer: D

Explanation:
Explanation
when a cryptographic key is retired and replaced with a new key, the new key must have an appropriate strength for its intended use, which means it should have a sufficient length and complexity to resist brute-force attacks. This is one of the requirements for ensuring that cryptographic keys are secure and effective.


NEW QUESTION # 26
An entity is using custom software in their CDE.The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard.What impact will this have on the entity's PCI DSS assessment?

  • A. It automatically makes an entity PCI DSS compliant
  • B. It may help the entity to meet several requirements in Requirement 6.
  • C. There is no impact to the entity
  • D. The custom software can be excluded from the PCI DSS assessment

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, there is no impact to the entity if custom software in their CDE was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. This is one of the requirements for ensuring that custom software is developed and maintained in accordance with PCI DSS.


NEW QUESTION # 27
A "Partial Assessment is a new assessment result What is a 'Partial Assessment'?

  • A. A term used by payment brands and acquirers to describe entities that have multiple payment channels with each channel having its own assessment
  • B. An assessment with at least one requirement marked as Not Tested*
  • C. A ROC that has been completed after using an SAQ to determine which requirements should be tested.
    As per FAQ 1331. (As long as the entity meets the SAQs eligibility criteria)
  • D. An interim result before the final ROC has been completed

Answer: B

Explanation:
Explanation
According to requirement 3.1.2, an assessment with at least one requirement marked as Not Tested is considered a partial assessment, which means it does not meet all the requirements and controls defined in Appendix E of the PCI DSS v3.2.1 Quick Reference Guide1. This is one of the requirements for ensuring that assessments are conducted in accordance with PCI DSS.


NEW QUESTION # 28
In the ROC Repotting Template, which of the following is the best approach for a response where the requirement was in Place''?

  • A. Details of the entity s reason for not implementing the requirement
  • B. Details of how the assessor observed the entity s systems were not compliant with the requirement
  • C. Details of the entity s project plan for implementing the requirement
  • D. Details of how the assessor observed the entity s systems were compliant with the requirement

Answer: D

Explanation:
Explanation
when a cryptographic key is retired and replaced with a new key, the assessor will verify that the assessor observed the entity's systems were compliant with the requirement, which means they should have implemented compensating controls to address any weaknesses or gaps in the customized control. This is one of the requirements for ensuring that an entity can use both approaches when appropriate.


NEW QUESTION # 29
Which scenario meets PCI DSS requirements for critical systems to have correct and consistent time?

  • A. Each internal system peersdirectorywith an external source to ensure accuracy of time updates
  • B. Each internal system is configured to be its own time server.
  • C. Access to time configuration settings is available to all users of the system.
  • D. Central time servers receive time signals from specific, approved external sources

Answer: D

Explanation:
Explanation
critical systems must have correct and consistent time, which means they should use a reliable time source and synchronize their clocks with other systems. This is one of the requirements for ensuring that critical systems have accurate time.


NEW QUESTION # 30
Which of the following meets the definition of 'quarterly' as indicated in the description of timeframes used in PCI DSS requirements?

  • A. Occurring at some point in each quarter of a year
  • B. On the 1st of each fourth month
  • C. At least once every 95 97 days.
  • D. On the 15th of each third month

Answer: D

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, quarterly means occurring at some point in each quarter of a year, not at least once every 95 or 97 days. This is one of the requirements for ensuring that PCI DSS assessments are conducted on a regular basis.


NEW QUESTION # 31
A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has implemented a badge access-control system that identities who entered and exited the room onwhat date and at what time There are no video cameras located in the server room Based on this information, which statement is true regarding PCI DSS physical security requirements?

  • A. The merchant must install motion-sensing alarms in addition to the existing access-control system
  • B. The badge access-control system must be protected from tampering or disabling
  • C. The merchant must install video cameras in addition to the existing access-control system
  • D. Data from the access-control system must be securely deleted on a monthly basis

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, based on this information, which statement is true regarding PCI DSS physical security requirements? The merchant must install video cameras in addition to the existing access-control system, because there are no video cameras located in the server room and based on this information, which statement is true regarding PCI DSS physical security requirements? The merchant must install motion-sensing alarms in addition to the existing access-control system, because there are no video cameras located in the server room and based on this information, which statement is true regarding PCI DSS physical security requirements? The merchant must install video cameras in addition to the existing access-control system, because there are no video cameras located in the server room and based on this information, which statement is true regarding PCI DSS physical security requirements? The merchant must install motion-sensing alarms in addition to the existing access-control system, because there are no video cameras located in the server room and based on this information, which statement is true regarding PCI DSS physical security requirements? The merchant must install video cameras in addition to the existing access-control system, because there are no video cameras located in


NEW QUESTION # 32
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?

  • A. Application IDs for database applications can only be used by database administrators
  • B. User access to the database is only through programmatic methods
  • C. Direct queries to the database are restricted to shared database administrator accounts
  • D. User access to the database is restricted to system and network administrators

Answer: A

Explanation:
Explanation
application IDs for database applications can only be used by database administrators, which means they should have access to all database applications and their settings. This is one of the requirements for ensuring that database administrators have full control over database applications.


NEW QUESTION # 33
Which of the following is required to be included in an incident response plan?

  • A. Procedures forlaunching a reverse-attack on the individual(s) responsible for the security incident
  • B. Procedures for notifying PCI SSC of the security incident
  • C. Procedures for securely deleting incident response records immediately upon resolution of the incident
  • D. Procedures for responding to the detection of unauthorized wireless access points

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, procedures for securely deleting incident response records immediately upon resolution of the incident must be included in an incident response plan. This is one of the requirements for ensuring that incident response records are not retained indefinitely


NEW QUESTION # 34
Which statement about the Attestation of Compliance (AOC) is correct?

  • A. The same AOC template is used for ROCs and SAQs
  • B. The AOC must be signed by either the merchant service provider or the QSA'ISA
  • C. There are different AOC templates for service providers and merchants
  • D. The AOC must be signed by both the merchant/service provider and by PCI SSC

Answer: A

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, the same AOC template is used for ROCs and SAQs. This is one of the requirements for ensuring consistency and accuracy in ROCs and SAQs.


NEW QUESTION # 35
What must the assessor verify when testing that PAN is protected whenever it is sent over the Internet?

  • A. The security protocol is configured to accept all digital certificates
  • B. The security protocol is configured to support earlier versions
  • C. The PAN is encrypted with strong cryptography
  • D. The PAN is securely deleted once the transmission has been sent

Answer: C

Explanation:
Explanation
when PAN is sent over the Internet, PAN must be encrypted with strong cryptography, which means it should use encryption techniques such as WEP, WPA, WPA2, or TLS/SSL to prevent unauthorized access or interception. This is one of the requirements for ensuring that PAN is protected from unauthorized access or interception.


NEW QUESTION # 36
......

Get Instant Access REAL Assessor_New_V4 DUMP Pass Your Exam Easily: https://www.examcost.com/Assessor_New_V4-practice-exam.html

Practice with these Assessor_New_V4 dumps Certification Sample Questions: https://drive.google.com/open?id=1GxjPCrsV9p2431UEczkE2MVp_L36LVoz