PCI DSS Fundamentals Exam Latest Update Questions and Correct Answers A cross-site scripting (XSS) attacks happens when - Correct Answer: A perpetrator discovers a website vulnerability and enables a script injection.
A Sustainable Compliance Program must: - Correct Answer: Be implemented into Business-as-usual (BAU) activities as part of the organizations overall security strategy.
Access to queries and actions on data bases are through - Correct Answer:
programmatic methods only
Accounts used by 3rd parties used for remote access are: - Correct Answer: Disabled when not in use, monitored while being used.
All segmentation controls must be penetration tested at least - Correct Answer:
Annually
An Admin workstation should be protected by: - Correct Answer: firewall software, multi-factor authentication
An indication that strong cryptography and security protocols like TLS, IPSEC, SSH are
in place is - Correct Answer: HTTPS
Can the Corporate LAN connect with the CDE - Correct Answer: No, this is actively blocked, no traffic that originated in the Corporate LAN is allowed into the CDE.
Common Shared Services may include: - Correct Answer: Directory & authentication (e.g. Active Directory, LDAP/AAA) NTP-Network Time Protocol, DNS-Domain Name Service, SMTP- Simple Mail Transfer Protocol, monitoring and scanning tools, backup tools, anti-virus & patch deployment servers
Control-failure response processes should include: - Correct Answer: minimizing the impact of the incident, restoring controls, performing root-cause analysis and remediation, implementing hardening standards and enhancing monitoring.
Corporate LAN is a - Correct Answer: Untrusted Network
Critical vendor supplied security patches must be installed within - Correct Answer: 1 month
Direct access to data bases are restricted to - Correct Answer: database administrators
Documentation of cryptographic architecture should include: - Correct Answer: Detailed algorithms, protocols and keys including key strength and expiry date, how keys are used and inventory of HSMS and other SCDs used for Key Mgt. 1 / 2
E-Commerce infrastructure may include: - Correct Answer: consumers browser, application servers, database servers and any other underlying servers or devices such as network devices.
E-commerce infrastructure typically follows what 3-tier computing model - Correct Answer: 1) Presentation layer (web) 2) processing layer (application) 3) data-storage layer
E-commerce Payment Gateway/Payment Processor - Correct Answer: may facilitate
payment authorization by forwarding transactions to the processors/acquirers that perform the actual payment authorization.
E-Commerce supporting infrastructure includes all computers and networking technologies such as - Correct Answer: web servers, application servers, database servers, routers, firewalls and intrusion-detection systems/intrusion-prevention systems
(IDS/IDP)
Effective metrics program can provide useful data for: - Correct Answer: Allocation of resources to minimize risk occurrence and measure the business consequences of security events.
Examine firewall and router configurations to verify that a DMZ is implemented to limit - Correct Answer: inbound traffic to only a system components that provide authorized publicly accessible services, protocols, and ports
Examine firewall and router configurations to verify that inbound internet traffic is limited
to - Correct Answer: IP addresses within the DMZ
Examine software-development P&P & interview responsible personnel to verify that cross-site scripting (XSS) is addressed by coding techniques that in include - Correct Answer: Validating all parameters before inclusion & utilizing context-sensitive escaping.
Executive management and board of directors meeting minutes regarding compliance
should occur - Correct Answer: At least every 6 months
Factors that can impact the scope of CDE: - Correct Answer: changes to network infrastructure affecting segmentation controls, changes to operational processes, implementation of new business, in-sourcing, outsourcing, mergers and acquisitions.
Financial institutions, processors, merchants and service providers should only use
devices or components that are tested and approved by - Correct Answer: PCI SSC
- / 2