In accordance with PCI DSS Requirement 10. how long must audit logs be retained?
A. At least 3 months with the most recent month immediately available
B. At least 2 years with the most recent month immediately available
C. At least 1 year, with the most recent 3 months immediately available
D. At least 2 years, with the most recent 3 months immediately available
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Viewing of audit log files should be limited to?
A. Individuals with a job-related need
B. Individuals who performed the logged activity
C. Individuals with read/write access
D. Individuals with administrator privileges
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which of the following is true regarding compensating controls?
A. An existing PCI DSS requirement can be used as compensating control if it is already implemented
B. A compensating control is not necessary if all other PCI DSS requirements are in place
C. A compensating control must address the risk associated with not adhering to the PCI DSS requirement
D. A compensating control worksheet is not required if the acquirer approves the compensating control
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which of the following can be sampled for testing during a PCI DSS assessment?
A. Compensating controls
B. Security policies and procedures
C. PCI DSS requirements and testing procedures.
D. Business facilities and system components
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
An entity accepts e-commerce payment card transactions and stores account data in a database The database server and the web server are both accessible from the Internet The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements7
A. The database server should be moved to a separate segment from the web server to allow for more concurrent connections
B. The web server should be moved into the internal network
C. The database server should be relocated so that it is not accessible from untrusted networks
D. The web server and the database server should be installed on the same physical server
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
According to requirement 1, what is the purpose of "Network Security Controls?
A. Encrypt PAN when stored
B. Manage anti-malware throughout the CDE.
C. Discover vulnerabilities and rank them
D. Control network traffic between two or more logical or physical network segments.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
What should the assessor verify when testing that cardholder data is protected whenever it is sent over open public networks?
A. The security protocol accepts connections from systems with lower encryption strength than required by the protocol
B. A proprietary security protocol is used
C. The security protocol accepts only trusted keys
D. The security protocol is configured to accept all digital certificates
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
1116 お客様のコメント





Wagure -
私も受かりました。
模擬問題をやって自信をつけて、自分の弱いところのチェックを繰り返しされました。
いい結果がでました。ありがとうございました。