Winter Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

Assessor_New_V4 Assessor_New_V4 Exam Questions and Answers

Questions 4

Which statement about PAN is true?

Options:

A.

It must be protected with strong cryptography for transmission over private wireless networks

B.

It must be protected with strong cryptography (or transmission over private wired networks

C.

It does not require protection for transmission over public wireless networks

D.

It does not require protection for transmission over public wired networks

Buy Now
Questions 5

A "Partial Assessment is a new assessment result What is a ‘Partial Assessment’?

Options:

A.

A ROC that has been completed after using an SAQ to determine which requirements should be tested. As per FAQ 1331. (As long as the entity meets the SAQs eligibility criteria)

B.

An interim result before the final ROC has been completed

C.

A term used by payment brands and acquirers to describe entities that have multiple payment channels with each channel having its own assessment

D.

An assessment with at least one requirement marked as Not Tested”

Buy Now
Questions 6

If disk encryption is used to protect account data what requirement should be met for the disk encryption solution?

Options:

A.

Access to the disk encryption must be managed independently of the operating system access control mechanisms

B.

The disk encryption system must use the same user account authenticator as the operating system

C.

The decryption keys must be associated with the local user account database

D.

The decryption keys must be stored within the local user account database

Buy Now
Questions 7

An LDAP server providing authentication services to the cardholder data environment is

Options:

A.

in scope for PCI DSS.

B.

not in scope for PCI DSS

C.

in scope only if it stores processes or transmits cardholder data

D.

in scope only if it provides authentication services to systems in the DMZ

Buy Now
Questions 8

According to requirement 1, what is the purpose of "Network Security Controls?

Options:

A.

Manage anti-malware throughout the CDE.

B.

Control network traffic between two or more logical or physical network segments.

C.

Discover vulnerabilities and rank them

D.

Encrypt PAN when stored

Buy Now
Questions 9

Passwords for default accounts and default administrative accounts should be?

Options:

A.

Changed within 30 days after installing a system on the network.

B.

Reset to the default password before installing a system on the network

C.

Changed before installing a system on the network

D.

Configured to expire in 30 days

Buy Now
Questions 10

Which of the following is true regarding internal vulnerability scans?

Options:

A.

They must be performed after a significant change

B.

They must be performed by an Approved Scanning Vendor (ASV)

C.

They must be performed by QSA personnel

D.

They must be performed at least annually

Buy Now
Questions 11

Which statement is true regarding the PCI DSS Report on Compliance (ROC)?

Options:

A.

The ROC Reporting Template and instructions provided by PCI SSC should be used for all ROCs.

B.

The assessor may use either their own template or the ROC Reporting Template provided by PCI SSC

C.

The assessor must create their own ROC template for each assessment report

D.

The ROC Reporting Template provided by PCI SSC is only required for service provider assessments

Buy Now
Questions 12

A network firewall has been configured with the latest vendor security patches What additional configuration is needed to harden the firewall?

Options:

A.

Remove the default 'Firewall Administrator account and create a shared account for firewall administrators to use.

B.

Configure the firewall to permit all traffic until additional rules are defined

C.

Synchronize the firewall rules with the other firewalls m the environment

D.

Disable any firewall functions that are not needed in production

Buy Now
Questions 13

An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity's PCI DSS assessment?

Options:

A.

It automatically makes an entity PCI DSS compliant

B.

It may help the entity to meet several requirements in Requirement 6.

C.

There is no impact to the entity

D.

The custom software can be excluded from the PCI DSS assessment

Buy Now
Questions 14

In accordance with PCI DSS Requirement 10. how long must audit logs be retained?

Options:

A.

At least 1 year, with the most recent 3 months immediately available

B.

At least 2 years, with the most recent 3 months immediately available

C.

At least 2 years with the most recent month immediately available

D.

At least 3 months with the most recent month immediately available

Buy Now
Questions 15

What process is requited by PCI DSS for protecting card-reading devices at the point-of-sale?

Options:

A.

Devices are periodically inspected to detect unauthorized card stammers.

B.

The serial number of each device is periodically verified with the device manufacturer

C.

Device identifiers and security labels are periodically replaced

D.

Devices are physically destroyed if there is suspicion of compromise

Buy Now
Questions 16

What should the assessor verify when testing that cardholder data is protected whenever it is sent over open public networks?

Options:

A.

The security protocol is configured to accept all digital certificates

B.

A proprietary security protocol is used

C.

The security protocol accepts only trusted keys

D.

The security protocol accepts connections from systems with lower encryption strength than required by the protocol

Buy Now
Questions 17

An entity accepts e-commerce payment card transactions and stores account data in a database The database server and the web server are both accessible from the Internet The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements7

Options:

A.

The web server and the database server should be installed on the same physical server

B.

The database server should be relocated so that it is not accessible from untrusted networks

C.

The web server should be moved into the internal network

D.

The database server should be moved to a separate segment from the web server to allow for more concurrent connections

Buy Now
Questions 18

In the ROC Repotting Template, which of the following is the best approach for a response where the requirement was in Place’’?

Options:

A.

Details of the entity s project plan for implementing the requirement

B.

Details of how the assessor observed the entity s systems were compliant with the requirement

C.

Details of the entity s reason for not implementing the requirement

D.

Details of how the assessor observed the entity s systems were not compliant with the requirement

Buy Now
Exam Code: Assessor_New_V4
Exam Name: Assessor_New_V4 Exam
Last Update: Dec 3, 2024
Questions: 60

PDF + Testing Engine

$66  $164.99

Testing Engine

$50  $124.99
buy now Assessor_New_V4 testing engine

PDF (Q&A)

$42  $104.99
buy now Assessor_New_V4 pdf