PCI SSC Assessor_New_V4 Assessor_New_V4 Prüfungsfragen mit Lösungen:
1. Which of the following types of events is required to be logged?
A) All network transmissions
B) All access to all audit trails
C) All use of end-user messaging technologies
D) All access to external web sites
2. Which of the following is true regarding compensating controls?
A) A compensating control must address the risk associated with not adhering to the PCI DSS requirement
B) An existing PCI DSS requirement can be used as compensating control if it is already implemented
C) A compensating control is not necessary if all other PCI DSS requirements are in place
D) A compensating control worksheet is not required if the acquirer approves the compensating control
3. An entity accepts e-commerce payment card transactions and stores account data in a database The database server and the web server are both accessible from the Internet The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements7
A) The web server and the database server should be installed on the same physical server
B) The web server should be moved into the internal network
C) The database server should be moved to a separate segment from the web server to allow for more concurrent connections
D) The database server should be relocated so that it is not accessible from untrusted networks
4. If segmentation is being used to reduce the scope of a PCI DSS assessment the assessor will?
A) Verify that approved devices and applications are used for the segmentation controls
B) Verify the payment card brands have approved the segmentation
C) Verify the segmentation controls allow only necessary traffic into the cardholder data environment.
D) Verify the controls used for segmentation are configured properly and functioning as intended
5. Which systems must have anti-malware solutions'
A) Any in-scope system except for those identified as not at risk from malware
B) All CDE systems, connected systems. NSCs. and security-providing systems
C) All portable electronic storage
D) All systems that store PAN
Fragen und Antworten:
| 1. Frage Antwort: B | 2. Frage Antwort: A | 3. Frage Antwort: D | 4. Frage Antwort: D | 5. Frage Antwort: A |






1027 Kundenbewertungen

