
更新されたPDF(2022年最新)実際にあるPCI PCIP3.0試験問題
検証済みのPCIP3.0試験問題集PDF[2022年最新] 成功の秘訣はPassTest
質問 41
SELECT ALL THAT APPLY
To be compliant with requirement 9.9 an updated list of all card-reading devices used in card-present transactions at the point of sale must be kept by June 30 2015 including the following:
- A. Make, model of device
- B. Location of device
- C. Device serial number or other unique identification
- D. Proof of purchase
正解: A,B,C
質問 42
Requirement 11.3 - Implement a methodology for penetration testing is a best practice until June 30 2015
- A. True
- B. False
正解: A
質問 43
Passwords/Passphrases should not be allowed if the same of the last ____ used passwords/passphrases.
(Requirement 8.2.5)
- A. 0
- B. 1
- C. 2
- D. 3
正解: C
質問 44
Requirement 3.5 requires document and implement procedures to protect keys used to secure stored cardholder data against disclose and misuse. This requirement applies to keys used to encrypt stored cardholder data, and also applies to key-encrypting keys used to protect data-encrypting keys. Such key-encrypting keys must be
- A. stronger than the data-encrypting keys
- B. stored at the same location of the data-encrypting key
- C. less stronger as the data-encrypting keys
- D. at least as strong as the data-encrypting keys
正解: D
質問 45
Protect stored cardholder data is the ____________
- A. Requirement 4
- B. Requirement 5
- C. Requirement 3
- D. Requirement 2
正解: C
質問 46
Encrypt transmission of cardholder data across open, public networks is the ______
- A. Requirement 5
- B. Requirement 1
- C. Requirement 2
- D. Requirement 4
正解: D
質問 47
SELECT ALL THAT APPLY
Select all audit trails that must be recorded for all system components according to requirement 10.3
- A. User identification
- B. Date and time
- C. Type of event
- D. Origination of event
- E. Success or failure identification
- F. Identity or name of affected data, system component, or resource
正解: A,B,C,D,E,F
質問 48
An user should be required to re-authenticate to activate the terminal or session if it's been idle for more than
- A. 60 minutes
- B. 30 minutes
- C. 15 minutes
- D. 10 minutes
正解: C
質問 49
What is the Appendix B on PCI DSS 3.0?
- A. Segmentation and Sampling of Business Facilities/System Components
- B. Additional PCI DSS Requirements for Shared Hosting Providers
- C. Compensating Controls
- D. Compensating Controls Worksheet
正解: C
質問 50
Which of the following lists the correct "order" for the flow of a payment card transaction?
- A. Clearing, Authorization, Settlement
- B. Clearing, Settlement, Authorization
- C. Authorization, Clearing, Settlement
- D. Authorization, Settlement, Clearing
正解: C
質問 51
Protect all systems against malware and regularly updated anti-virus software or programs is the
____________
- A. Requirement 4
- B. Requirement 5
- C. Requirement 6
- D. Requirement 7
正解: B
質問 52
Requirement 8.2.3 states that passwords/phrases must contain both numeric and alphabetic characters and a minimum length of at least
- A. 6 characters
- B. 8 characters
- C. 14 characters
- D. 7 characters
正解: D
質問 53
What is the NIST standards that provides password complexity requirements
- A. 800-57
- B. 800-53
- C. 800-61
- D. 800-63
正解: D
質問 54
Merchants with segmented payment application systems connected to the Internet, no electronic cardholder data storage, may be eligible to use what SAQ?
- A. SAQ A
- B. SAQ B
- C. SAQ C-VT
- D. SAQ D
- E. SAQ C
正解: E
質問 55
In order to be considered a compensating control, which of the following must exist:
- A. A legitimate technical constraint or a documented business constraint
- B. A documented business constraint
- C. A legitimate technical constraint and a documented business constraint
- D. A legitimate technical constraint
正解: A
質問 56
The PCI DSS Requirement most closely associated with "Logging" is ____________
- A. Requirement 10
- B. Requirement 2
- C. Requirement 11
- D. Requirement 8
正解: A
質問 57
To be compliant with requirement 8.1.4 you have to remove/disable inactive user accounts at least every
- A. 180 days
- B. 90 days
- C. 60 days
- D. 30 days
正解: B
質問 58
PCI compliance do not apply on Virtualized environments
- A. True
- B. False
正解: B
質問 59
Who can perform quarterly external vulnerability scans meeting requirement 11.2.2?
- A. Any employee
- B. Qualified personnel
- C. IT Security personnel
- D. Approved Scanning Vendor (ASV) approved by PCI SSC
正解: D
質問 60
The lockout of an user ID should be set until an administrator re-enables the user or to a minimum of
- A. 60 minutes
- B. 30 minutes
- C. 15 minutes
- D. 10 minutes
正解: B
質問 61
......
ベストを体験せよ!PCIP3.0試験問題トレーニングを提供しています:https://www.passtest.jp/PCI/PCIP3.0-shiken.html
練習サンプルと問題集と秘訣には2022年最新のPCIP3.0有効なテスト問題集:https://drive.google.com/open?id=1BLC0hSuAJF6dtjutiNSrm0hwun1xZw7e