Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
What must be included in an organization's procedures for managing visitors?
Visitor Management Requirements:
PCI DSS Requirement 9.3 specifies that visitors must be escorted at all times in areas where cardholder data is present to prevent unauthorized access or breaches.
Invalid Options:
B: Visitor badges must be distinguishable from employee badges.
C: Visitor logs are necessary but do not need detailed personal information like addresses.
D: Retaining visitor identification for 30 days is not a requirement.
Which of the following describes "stateful responses" to communication Initiated by a trusted network?
Stateful Inspection
PCI DSS Requirement 1.2 specifies the need for stateful inspection to track the state of active connections. This ensures that only valid responses to communication initiated by trusted networks are allowed.
Invalid or unsolicited response traffic is blocked to prevent exploitation of vulnerabilities.
Key Functionality of Stateful Firewalls
Stateful firewalls maintain session information and only allow traffic that matches an existing session or expected response.
Incorrect Options
Option A: Administrative access restrictions are important but unrelated to stateful responses.
Option C: Baseline configurations are a different security control.
Option D: Logging and correlation are for threat detection, not stateful response.
An LDAP server providing authentication services to the cardholder data environment is_____________?
Scope of PCI DSS:
PCI DSS applies to all systems that store, process, or transmit cardholder data (CHD), as well as systems that can impact the security of the CDE. An LDAP server providing authentication services is considered a connected system that could impact the security of CHD and is therefore in scope.
Clarifications on Scope:
Systems like LDAP servers that do not directly handle CHD but provide critical services to the CDE (e.g., authentication) are in scope for PCI DSS.
Invalid Options:
B/C/D: Scoping is not limited to direct storage, processing, or transmission of CHD but includes systems that could affect the CDE's security.
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?
Restricting Database Access
PCI DSS Requirement 7.2 specifies that access to cardholder data, including databases, must be restricted by business need-to-know.
Restricting access to programmatic methods minimizes the risk of unauthorized queries and data breaches.
Eliminating Direct Access
Direct database access by end-users or administrators poses significant risk unless strictly controlled and monitored. Programmatic methods (e.g., via applications with role-based access controls) align with security best practices.
Incorrect Options
Option B: Administrators might need access, but access should not be limited to system/network administrators.
Option C: Application IDs should not be used directly by individuals, as this circumvents accountability.
Option D: Shared accounts are discouraged due to a lack of traceability.
What is the intent of classifying media that contains cardholder data?
Purpose of Classifying Media
PCI DSS v4.0 emphasizes the need to classify media based on the sensitivity of the data it contains. Media classification ensures appropriate handling, storage, and destruction processes.
Media Protection Requirements
Media containing cardholder data must be securely stored, transferred, and destroyed when no longer needed.
Classification informs the level of protection required, such as encryption, physical security, or controlled access.
Incorrect Options
Option B: Moving media quarterly is not a requirement.
Option C: Labeling as 'Confidential' is insufficient without a comprehensive protection strategy.
Option D: Destruction schedules should depend on retention requirements and data sensitivity, not a universal timeline.
40 questions covering all exam domains, starting from $20
Exam domains verified against: Official PCI QSA_New_V4 exam guide, last checked September 2026.
Measures the skills of PCI Compliance Auditors to assess PCI DSS compliance. Covers testing procedures required to evaluate security controls and identify vulnerabilities ensuring organizations meet compliance requirements.
Focuses on unique security and compliance requirements of payment brands including mandates from Visa, Mastercard, and American Express. Requires familiarity with brand-specific expectations for handling cardholder data.
Evaluates processes for validating PCI DSS compliance across different levels of merchant and service provider validation. Covers reporting obligations including preparation of Reports on Compliance and Self-Assessment Questionnaires with accurate documentation.
Involves analyzing real-world breaches and compliance failures to cover best practices in PCI DSS implementation. Review case studies to understand security applications and lessons learned from actual incidents.
Common questions about the exam itself