PCI DSS Assessment Flashcards

1
Q

What does PCI DSS stand for?

A) Personal Card Information Data Security Standard
B) Payment Card Information Data System Security
C) Payment Card Industry Data Security Standard
D) Personal Card Industry Data System Security

A

C) Payment Card Industry Data Security Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How often should you empty your deleted items?

A) Daily
B) Weekly
C) Hourly
D) It is cleared automatically

A

A) Daily

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When can you open email attachments in your personal outlook inbox from an unknown source?

A) Never
B) When you know or are informed by the IT department that the attachment has been anti-virus checked
C) When it is forwarded by an Elevate colleague
D) When it has been encrypted

A

B) When you know or are informed by the IT department that the attachment has been anti-virus checked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which is a correct statement?

A) un-obscured PANS can be transmitted externally from the business
B) Mobile phones must never be connected to a company computer
C) You can install software onto a company PC if it has been anti-virus checked and has encryption and protection built in
D) All staff members should have the highest access privilege set to allow them to complete their role

A

B) Mobile phones must never be connected to a company computer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Where should a visitor never be left unattended?

A) A quiet area on the operational floor
B) The toilets
C) Stairwells
D) Staff room

A

A) A quiet area on the operational floor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is NOT a requirement of IT security?

A) No staff member is to attempt to gain access to any system, directory, file or pc which they are not authorised to access

B) No customer information can be stored on external devices

C) All staff members should have the highest access privilege set to allow them to complete their role

D) Always lock your PC when you are away from your desk

A

C) All staff members should have the highest access privilege set to allow them to complete their role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who can you share your system password with?

A) No-one
B) Information Security
C) Your manager
D) IT when they need remote access

A

A) No-one

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

All visitors must

A) Have passed a CRB check
B) Wait outside until the person they have arranged to meet can sign for them
C) Be signed into the visitors book and escorted at all times.
D) Have their mobile phones and any other external devices scanned by IT

A

C) Be signed into the visitors book and escorted at all times.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which statement is not correct regarding the use of email?

A) Customer card information can be transmitted out of the business if you need to work from home urgently
B) Company email must not be used for personal communication
C) Any email received that contains card information must be deleted
Email attachments from an unknown source should not be downloaded unless it has been anti-virus checked

A

A) Customer card information can be transmitted out of the business if you need to work from home urgently

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

If you are requested to write down customer card details on paper, what should you do?

A) Inform the requestor that card details should never be written down
B) Write them on coloured paper and shred them within 30 minutes
C) Make an electronic note and then delete the note as soon as possible
D) Write them on a post it note and shred as soon as they have been used

A

A) Inform the requestor that card details should never be written down

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does MSP stand for?

A) Merchant Service Provider
B) Monetary Standard Payments
C) Multiple Service Payments
D) Minimum Security Precautions

A

A) Merchant Service Provider

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the maximum amount of time we can retain printed emails containing card details

A) 2 days
B) Emails with card details should not be printed
C) 2 hours to a maximum of 2 days
D) 6 months with full PAN then PAN obscured

A

B) Emails with card details should not be printed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When must IT be informed so an entry card/fob can be cancelled?

A) When someone goes on holiday for two weeks
B) When someone is suspended
C) When someone is on sick leave
D) When you accidentally leave your entry card/fob at home

A

B) When someone is suspended

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which of the following would be a secure password?

A) K(TR*6T7
B) monday123!
C) 5uP3rSPeCi3)
D) jEleviS&W

A

C) 5uP3rSPeCi3)

Password needs to be 7 or more characters long
Have uppercase and lowercase letters
Have some numbers
Have some symbols ie )(:£&@?!-/
Cannot contain a word ie Monday, Tuesday etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is NOT a requirement of building security?

A) The front door must be kept shut
B) You must keep your entry card with you at all times
C) When the building is empty, all doors must be locked and the alarm set
D) If you lose your entry card/fob, this must be reported to a colleague immediately

A

D) If you lose your entry card/fob, this must be reported to a colleague immediately

How well did you know this?
1
Not at all
2
3
4
5
Perfectly