PCI SSC QSA_New_V4 - Qualified Security Assessor V4 Exam
A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has implemented a badge access-control system that identifies who entered and exited the room, on what date, and at what time. There are no video cameras located in the server room. Based on this information, which statement is true regarding PCI DSS physical security requirements?
Viewing of audit log files should be limited to?
An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA, while also ensuring that the customized control is implemented securely. Which of the following statements is true?
An entity wants to know if the Software Security Framework can be leveraged during their assessment. Which of the following software types would this apply to?
Assigning a unique ID to each person is intended to ensure?
An internal NTP server that provides time services to the Cardholder Data Environment is?
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?
An LDAP server providing authentication services to the cardholder data environment is?
Which of the following can be sampled for testing during a PCI DSS assessment?
Which statement is true regarding the PCI DSS Report on Compliance (ROC)?