Assessor_New_V4 Exam Questions and Answers
What is the intent of classifying media that contains cardholder data?
What does the PCI PTS standard cover?
A sample of business facilities is reviewed during the PCI DSS assessment What is the assessor required to validate about the sample?
Which statement about PAN is true?
An internal NTP server that provides time services to the Cardholder Data Environment is?
An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA. while also ensuing that the customized control is implemented securely. Which of the following statements is true?
Where can live PANs be used for testing?
Passwords for default accounts and default administrative accounts should be?
If an entity shares cardholder data with a TPSP, what activity is the entity required to perform'?
An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity's PCI DSS assessment?
Which statement about the Attestation of Compliance (AOC) is correct?
Viewing of audit log files should be limited to?
Which statement is true regarding the PCI DSS Report on Compliance (ROC)?
Which of the following is true regarding internal vulnerability scans?
The intent of assigning a risk ranking to vulnerabilities is to?
What must the assessor verify when testing that PAN is protected whenever it is sent over the Internet?
Which of the following types of events is required to be logged?
An LDAP server providing authentication services to the cardholder data environment is