PCI SSC Assessor_New_V4 試験概要:
| 認定ベンダー: | PCI Security Standards Council (PCI SSC) |
|---|---|
| 試験名: | Assessor New V4 試験 |
| 試験番号: | Assessor_New_V4 |
| 試験形式: | 多肢選択式, シナリオベースの問題, アセスメントおよびコンプライアンス分析 |
| 出題数: | 40-62 |
| 対応言語: | 英語 |
| 関連資格: | PCI Qualified Security Assessor (QSA) |
| サンプル問題: | PCI SSC Assessor_New_V4 サンプル問題 |
| 受験方法: | 講師主導のトレーニングの後、監督下で試験を受けます。PCI SSC の資格プログラムを通じて受験可能です。 |
| 前提条件: | 通常は、PCI SSC 承認の QSA 企業に勤務するセキュリティ専門家を対象としています。QSA の資格取得ルートでは、PCI Fundamentals のトレーニングと、関連するセキュリティ認定資格(CISSP、CISA、CISM など)が一般的に必要です。 |
| 公式シラバスのURL: | https://www.pcisecuritystandards.org/program_training_and_qualification/qsa_certification/ |
PCI SSC Assessor_New_V4 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: PCIアセスメント手法 | - 証拠収集
|
| トピック 2: PCI DSSの要件とテスト手順 | - PCI DSS管理要件
|
| トピック 3: ペイメントカード業界エコシステム | - 決済処理の基礎
|
| トピック 4: コンプライアンスおよびセキュリティ運用 | - セキュリティ管理
|
| トピック 5: カスタマイズされたアプローチとリスク分析 | - カスタマイズされたコントロール
|
| トピック 6: PCI報告要件 | - コンプライアンス報告書(ROC)
|
PCI SSC Assessor_New_V4 認定 Assessor_New_V4 試験問題:
問題 #1
What is the intent of classifying media that contains cardholder data?
A. Ensuring that all media is consistently destroyed on the same schedule regardless of the contents
B. Ensuring that media is clearly and visibly labeled as 'Confidential so all personnel know that the media contains cardholder data
C. Ensuring that media containing cardholder data is moved from secured areas an a quarterly basis
D. Ensuring that media is property protected according to the sensitivity of the data it contains
問題 #2
Which of the following is required to be included in an incident response plan?
A. Procedures for launching a reverse-attack on the individual(s) responsible for the security incident
B. Procedures for responding to the detection of unauthorized wireless access points
C. Procedures for securely deleting incident response records immediately upon resolution of the incident
D. Procedures for notifying PCI SSC of the security incident
問題 #3
What would be an appropriate strength for the key-encrypting key (KEK) used to protect an AES 128-bit data-encrypting key (DEK)
A. ROT 13
B. RSA512
C. DES256
D. AES 128
問題 #4
Which statement is true regarding the use of intrusion detection techniques, such as intrusion detection systems and/or intrusion protection systems (IDS'IPS)?
A. Intrusion detection techniques are required to alert personnel of suspected compromises
B. Intrusion detection techniques are required to isolate systems in the cardholder data environment from all other systems
C. Intrusion detection techniques are required on all system components
D. Intrusion detection techniques are required to identify all instances of cardholder data
問題 #5
Which of the following is true regarding internal vulnerability scans?
A. They must be performed by QSA personnel
B. They must be performed after a significant change
C. They must be performed at least annually
D. They must be performed by an Approved Scanning Vendor (ASV)
解説:
| 問題 #1 正解: D | 問題 #2 正解: D | 問題 #3 正解: D | 問題 #4 正解: A | 問題 #5 正解: B |














1182 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
