QSA Quick shot! Flashcards

1
Q

What are the 3 continual processes of QSA?

A

Assess, Report, Remediate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What requirements are needed to build and maintain a secure network?

A

1) Install and maintain a firewall configuration to protect cardholder data
2) Do Not use vendor supplied default passwords and other security parameters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What requirements are needed to protect cardholder data?

A

3) Protect stored cardholder data

4) Encrypt transmission of cardholder data across open, public networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is needed to maintain a vulnerability management program

A

5) use and regularly update anti-virus software or programs

6) develop and maintain secure systems and applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do you implement strong access control measures?

A

7) Restrict access to cardholder data by business need-to-know
8) Assign unique IDs to each person with computer access
9) Restrict physical access to cardholder data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you regularly monitor and test networks?

A

10) track and monitor all access to network resources and cardholder data
11) regularly test security systems and processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is required to maintain an info sec policy?

A

12) Maintain a policy that addresses information security for employees and contractors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the validation tool for organizations to get a rough idea of how they are doing with card security?

A

the Self- Assessment Questionnaire. (SAQ)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a PAN?

A

The Primary Account Number on the card.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the CID?

A

A unique identifier to the particular card. American Express only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which goal does the establishment of firewall and router configurations support?

A

Goal 1: Install and maintain a firewall and router configuration to protect cardholder data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What Cardholder data requires PCI DSS Req 3.4?

A

the Primary Account Number (PAN)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is considered Sensitive Au Data?

A

full Track data (stripe), CAV2, CVC2, CVV, CID, PINs/ PIN Blocks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the defining factor for cardholder data?

A

PAN or primary account number (the number on the card

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the scope of cardholder data environment?

A

People, processes, and technologies that store process or transmit CH data or Au Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is segmenting?

A

isolating portions of the network through FWs, ACLs, Etc. Not currently required by the DSS

17
Q

What goal does requirement 10 support?

A

Regularly Monitor and Test networks

18
Q

What goal does requirement 12 support?

A

Maintain an Info Sec. Policy

19
Q

What goal does requirement 1 support?

A

Build and Maintain a Secure Network

20
Q

What goal does requirement 11 support?

A

Regularly Monitor and Test Networks

21
Q

What Goal does requirement 2 support?

A

Build and Maintain a Secure network

22
Q

What goal does requirement 10 support?

A

Regularly Monitor and Test Networks

23
Q

What goal does requirement 3 support?

A

Protect Cardholder data

24
Q

What goal does requirement 9 support

A

Implement Strong Access Control Measures

25
Q

What goal does requirement 4 support?

A

Protect Card holder data

26
Q

What goal does requirement 8 support?

A

Implement Strong Access Control Measures

27
Q

What goal does requirement 5 support

A

Maintain a vulnerability management program

28
Q

What goal does requirement 7 support?

A

Implement Strong Access Control Measures

29
Q

What goal does requirement 6 support?

A

Maintain a vulnerability management program

30
Q

What is the periodicity for the Continuous Process Timeline?

A

Annually, (with community meetings in Septeber/ October each year)

31
Q

What is the periodicity for the PCI-DSS Life cycle?

A

Every 3 years