
究極のガイド準備で無料PCI PCIP3.0試験問題と解答
合格させるPCI PCIP3.0テストエンジンPDFで完全版無料問題集
質問 # 18
In the event of a violation of the PCIP Qualification Requirements, disciplinary actions for PCIPs could include:
- A. Verbal warning, one-off fine, revocation
- B. Written warning, remediation, monthly fines
- C. Written warning, suspension, revocation
- D. Verbal warning, suspension, monthly fines
正解:C
質問 # 19
Who can perform quarterly external vulnerability scans meeting requirement 11.2.2?
- A. Approved Scanning Vendor (ASV) approved by PCI SSC
- B. Any employee
- C. IT Security personnel
- D. Qualified personnel
正解:A
質問 # 20
PCI compliance do not apply on Virtualized environments
- A. True
- B. False
正解:B
質問 # 21
PCI DSS Requirement Appendix A is intended for:
- A. Issuing banks and acquirers
- B. Merchants with data center environments
- C. Any third party that stores, processes, or transmits cardholder data on behalf of another entity
- D. Shared hosting providers
正解:D
質問 # 22
According to Requirement 10.4 the use of Time synchronization like NTP should be implemented on all critical systems for acquiring, distributing, and storing time.
- A. False
- B. True
正解:B
質問 # 23
Please select all possible disciplinary actions that may be applicable in case of violation of PCI Code of
Professional Responsibility
- A. Fee
- B. Suspension
- C. Warning
- D. Revocation
正解:B、C、D
質問 # 24
Which statement is true regarding sensitive authentication data?
- A. Sensitive authentication exists in the magnetic strip or chip, and is also printed on the payment card
- B. Encrypt sensitive authentication data removes it from PC DSS scope
- C. Sensitive authentication data includes PAN and service code
- D. Sensitive data is required for recurring transactions
正解:A
質問 # 25
Risk assessments must be implemented in order to meet requirement 12.2. Please select all risk assessments methodologies that can be used in order to meet this requirement.
- A. NIST SP 800-53
- B. NIST SP 800-30
- C. OCTAVE
- D. ISO 27005
正解:B、C、D
質問 # 26
The implementation of a Security Awareness Program (Requirement 12.6) requires that personnel must be educated upon hire and at least
- A. Monthly
- B. Yearly
- C. Every 6 months
- D. Quarterly
正解:B
質問 # 27
Merchants using only web-based virtual payment terminals, no electronic cardholder data storage, may be eligible to use what SAQ?
- A. SAQ D
- B. SAQ C-VT
- C. SAQ C
- D. SAQ B
- E. SAQ A
正解:B
質問 # 28
The presumption of P2PE is that:
- A. The data can never be decrypted
- B. Any entity in possession of the ciphertext can easily reverse the encryption process
- C. The data cannot be decrypted between the source and the destination points
- D. The data can be decrypted between the source and the destination points
正解:C
質問 # 29
PCI DSS Requirement 1 covers:
- A. Secure development of DMZ applications and systems
- B. Masking of PAN wherever it is displayed
- C. Implementation of firewalls between the CDE and untrusted networks
- D. Installation of anti-virus software
正解:C
質問 # 30
An audit trail history should be available immediately for analysis within a minimum of
- A. 6 months
- B. 30 days
- C. 3 months
- D. 1 year
正解:C
質問 # 31
Requirement 3.5 requires document and implement procedures to protect keys used to secure stored cardholder data against disclose and misuse. This requirement applies to keys used to encrypt stored cardholder data, and also applies to key-encrypting keys used to protect data-encrypting keys. Such key-encrypting keys must be
- A. stored at the same location of the data-encrypting key
- B. at least as strong as the data-encrypting keys
- C. less stronger as the data-encrypting keys
- D. stronger than the data-encrypting keys
正解:B
質問 # 32
Maintain a policy that addresses information security for all personnel is the ________
- A. Requirement 10
- B. Requirement 9
- C. Requirement 12
- D. Requirement 11
正解:C
質問 # 33
To render PAN unreadable anywhere it is stored one-way hashes must be implemented based on strong cryptography on
- A. on the last half of the PAN
- B. the entire PAN
- C. on half of the PAN
- D. on the first half of the PAN
正解:B
質問 # 34
What are best practices for implementing PCI DSS into Business-as-Usual (BAU) Processes? (Select
ALL that apply)
- A. PCI DSS is not a once-a-year activity
- B. Don't forget about people
- C. Building security into business-as-usual helps organizations to maintain their PCI DSS compliant environment in between PCI DSS assessments
- D. Focus on security, not on compliance
正解:A、B、C、D
質問 # 35
Track and monitor all access to network resources and cardholder data is the ___________
- A. Requirement 10
- B. Requirement 9
- C. Requirement 8
- D. Requirement 11
正解:A
質問 # 36
Restrict access to cardholder data by business need-to-know
- A. Requirement 10
- B. Requirement 9
- C. Requirement 8
- D. Requirement 7
正解:D
質問 # 37
Encrypt transmission of cardholder data across open, public networks is the ______
- A. Requirement 2
- B. Requirement 5
- C. Requirement 1
- D. Requirement 4
正解:D
質問 # 38
Use of a Qualified Integrator/Reeller (QIR):
- A. ensures PCI DSS compliance
- B. is a good step towards PCI DSS compliance
- C. replaces the need for PCI DSS
- D. is required by PCI DSS
正解:B
質問 # 39
......
Payment Card Industry Professional練習テスト2023年最新のPCIP3.0をストレスなしで合格!:https://drive.google.com/open?id=1PA7nVo3QQRDmT44LuSSaUNlxI-vVpiOY
オンライン試験練習テストと詳細な解説付き!:https://www.passtest.jp/PCI/PCIP3.0-shiken.html