PCI Payment Card Industry Professional 認定 PCIP3.0 試験問題:
1. PCI compliance do not apply on Virtualized environments
A) True
B) False
2. For initial PCI DSS compliance, it's not required that four quarters of passing scans must be completed if the assessor verifies that 1) the most recent scan result was a passing scan, 2) the entity has documented policies and procedures requiring quarterly scanning, and 3) vulnerabilities noted in the scan results have been corrected as shown in a re-scan(s).
A) True
B) False
3. What are best practices for implementing PCI DSS into Business-as-Usual (BAU) Processes? (Select
ALL that apply)
A) Building security into business-as-usual helps organizations to maintain their PCI DSS compliant environment in between PCI DSS assessments
B) Don't forget about people
C) Focus on security, not on compliance
D) PCI DSS is not a once-a-year activity
4. Restrict access to cardholder data by business need-to-know
A) Requirement 8
B) Requirement 9
C) Requirement 10
D) Requirement 7
5. All users and administrators access to, queries and actions on databases must be through programmatic methods only. Never direct access or queries to database
A) True
B) False
質問と回答:
質問 # 1 正解: B | 質問 # 2 正解: A | 質問 # 3 正解: A、B、C、D | 質問 # 4 正解: D | 質問 # 5 正解: B |