Viewing of audit log files should be limited to?
A. Individuals who performed the logged activity.
B. Individuals with a job-related need.
C. Individuals with read/write access.
D. Individuals with administrator privileges.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Which statement about the Attestation of Compliance (AOC) is correct?
A. The AOC must be signed by either the merchant/service provider or the QSA/ISA.
B. The AOC must be signed by both the merchant/service provider and by PCI SSC.
C. There are different AOC templates for service providers and merchants.
D. The same AOC template is used W ROCs and SAQs.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which of the following can be sampled for testing during a PCI DSS assessment?
A. Security policies and procedures.
B. PCI DSS requirements and testing procedures.
C. Business facilities and system components.
D. Compensating controls.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
What process is required by PCI DSS for protecting card-reading devices at the point-of-sale?
A. Device identifiers and security labels are periodically replaced.
B. Devices are periodically inspected to detect unauthorized card skimmers.
C. The serial number of each device is periodically verified with the device manufacturer.
D. Devices are physically destroyed if there is suspicion of compromise.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
What do PCI DSS requirements for protecting cryptographic keys include?
A. Public keys must be encrypted with a key-encrypting key.
B. Data-encrypting keys must be stronger than the key-encrypting key that protects it.
C. Key-encrypting keys and data-encrypting keys must be assigned to the same key custodian.
D. Private or secret keys must be encrypted, stored within an SCD, or stored as key components.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Which scenario describes segmentation of the cardholder data environment (CDE) for the purposes of reducing PCI DSS scope?
A. Firewalls that log all network traffic flows between the CDE and out-of-scope networks.
B. Virtual LANs that route network traffic between the CDE and out-of-scope networks.
C. Routers that monitor network traffic flows between the CDE and out-of-scope networks.
D. A network configuration that prevents all network traffic between the CDE and out-of-scope networks.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
藤记** -
QSA_New_V4練習問題はすごく有効的なものです。この二ヶ月以来、QSA_New_V4をよく勉強し、意外がなくて、試験に合格しました。それは最高です!