최신 PCI Qualified Professionals Assessor_New_V4 무료샘플문제:
1. Could an entity use both the Customized Approach and the Defined Approach to meet the same requirement?
A) Yes if the entity is eligible to use both approaches
B) No because a single approach must be selected
C) Yes if the entity uses no compensating controls
D) No. because only compensating controls can be used with the Defined Approach
2. What must the assessor verify when testing that PAN is protected whenever it is sent over the Internet?
A) The PAN is encrypted with strong cryptography
B) The security protocol is configured to support earlier versions
C) The PAN is securely deleted once the transmission has been sent
D) The security protocol is configured to accept all digital certificates
3. Which of the following is required to be included in an incident response plan?
A) Procedures for launching a reverse-attack on the individual(s) responsible for the security incident
B) Procedures for responding to the detection of unauthorized wireless access points
C) Procedures for securely deleting incident response records immediately upon resolution of the incident
D) Procedures for notifying PCI SSC of the security incident
4. Assigning a unique ID to each person is intended to ensure?
A) Individual users are accountable for their own actions
B) Access is assigned to group accounts based on need-to-know
C) Strong passwords are used for each user account
D) Shared accounts are only used by administrators
5. An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?
A) Certificates are logged so they can be retrieved when the employee leaves the company
B) A different certificate is assigned to each individual user account, and certificates are not shared
C) Change control processes are in place to ensue certificates are changed every 90 days
D) Certificates are assigned only to administrative groups and not to regular users
질문과 대답:
질문 # 1 정답: C | 질문 # 2 정답: A | 질문 # 3 정답: D | 질문 # 4 정답: A | 질문 # 5 정답: B |