If an entity shares cardholder data with a TPSP, what activity is the entity required to perform'?
A. The entity must monitor the TPSP's PCI DSS compliance status at least annually
B. The entity must test the TPSP's incident response plan at least quarterly
C. The entity must conduct ASV scans on the TPSP's systems at least annually
D. The entity must perform a risk assessment of the TPSP's environment at least quarterly.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Could an entity use both the Customized Approach and the Defined Approach to meet the same requirement?
A. Yes if the entity uses no compensating controls
B. No. because only compensating controls can be used with the Defined Approach
C. No because a single approach must be selected
D. Yes if the entity is eligible to use both approaches
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
What must be included m an organization's procedures for managing visitors?
A. Visitors retain their identification (for example a visitor badge) for 30 days after completion of the visit
B. Visitors are escorted at all times within areas where cardholder data is processed or maintained
C. Visitor log includes visitor name, address, and contact phone number
D. Visitor badges are identical to badges used by onsite personnel
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Security policies and operational procedures should be?
A. Encrypted with strong cryptography
B. Distributed to and understood by all affected parties
C. Stored securely so that only management has access
D. Reviewed and updated at least quarterly
正解:B
質問 5:
Which of the following describes "stateful responses' to communication initiated by a trusted network?
A. Active network connections are tracked so that invalid response' traffic can be identified.
B. Logs of user activity on the firewall are correlated to identify and respond to suspicious behavior
C. A current baseline of application configurations is maintained and any mis-configuration is responded to promptly
D. Administrative access to respond to requests to change the firewall is limited to one individual at a time
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
Morisaki -
Pass4Testの皆様、合格できました。ありがとうございました。