PCIP EXAM 2023-2024 ACTUAL EXAM 150 QUESTIONS
AND CORRECT ANSWERS/PAYMENT CARD
INDUSTRY PROFESSIONAL NEWEST EXAM
(VERIFIED ANSWERS) |AGRADE
PCI DSS Requirement 3.4 states the PAN must be rendered unreadable when
stored, using___________.
A. Encryption, Truncation, or Obfuscating
B. Hashing, Scrambling, or Encrypting
C. Encryption, Hashing, or Truncation
D. Truncation, Scrambling, or Encrypting – ANSWER- Correct Answer: C
Requirement 2.2.2 states “Enable only necessary and secure services, protocols,
daemons, etc., as required
for the function of the system”. Which of the following is considered secure?
A. SSH
B. RLogon
C. Telnet
D. FTP – ANSWER- Correct Answer: A
When scoping an environment for a PCI DSS assessment, it is important to
identify ___.
A. All flows of cardholder data
B. All of the options
C. Components that store cardholder data
D. Business facilities involved in processing transactions – ANSWER- Correct
Answer: B
Merchants involved with only e-commerce transactions that are completely
outsourced to a PCI DSS compliant
service provider would use which SAQ?
A. SAQ C/VT
B. SAQ B
C. SAQ D
D. SAQ A – ANSWER- Correct Answer: D
Imprint-Only Merchants with no electronic storage of cardholder data would use
which SAQ?
A. SAQ C/VT
B. SAQ B
C. SAQ A
D. SAQ D – ANSWER- Correct Answer: B
When a Service Provider has been defined by a payment brand as eligible to
complete a SAQ, which SAQ is
used?
A. SAQ D
B. SAQ B
C. SAQ A
D. SAQ C – ANSWER- Correct Answer: A
Information Supplements provided by the PCI SSC may “supersede” requirements.
A. True
B. False – ANSWER- Correct Answer: B
If virtualization technologies are used in a cardholder data environment, PCI DSS
requirements apply to those
virtualization technologies.
A. False
B. True – ANSWER- Correct Answer: B
The presumption of P2PE is that cardholder data in transit is protected when it is
encrypted to the extent that
an entity in possession of the ciphertext alone can easily reverse the encryption
process
A. False
B. True – ANSWER- Correct Answer: A
Encrypting account data at the point of capture is one way an entity involved in
payment card processing via
mobile devices can actively help in controlling risks to the security of cardholder
data.
A. True
B. False – ANSWER- Correct Answer: A