PCI DSS Requirements Overview Flashcards

1
Q

___________ applies wherever account data is stored, processed, or transmitted.

A

PCI DSS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Account data consists of 1️⃣_______________ and/or 2️⃣_____________

A

1️⃣ cardholder data

2️⃣ sensitive authentication data (SAD)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Many people refer to All account data to simply __________

A

Cardholder Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

PCI DSS requirements are applicable wherever 1️⃣_____________ or 2️⃣_____________ is stored, processed, or transmitted

A

1️⃣ Primary Account Number (PAN)

2️⃣ Sensitive Authentication Data (SAD)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PCI DSS requirements also apply to systems that provide 1️⃣____________ or could impact the security of 2️⃣__________

A

1️⃣ Security Services

2️⃣ Account data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Account data includes all of the information printed on 1️⃣__________ as well as the data on the 2️⃣__________or 3️⃣________

A

1️⃣ physical card
2️⃣ magnetic stripe
3️⃣ chip

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

______________ cannot be stored after authorization

A

Sensitive Authentication Data (SAD)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Encrypting cardholder data or sensitive authentication data does NOT necessarily remove it from scope. (True/False)

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

PAN, Cardholder Name, Expiration Date, and service code are example of

A

Cardholder Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Full magnetic stripe data (for equivalent on chip), CAV2/CVC2/CVV2/CID, and PINs/PIN blocks are example of

A

sensitive authentication data (SAD)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Merchants are not permitted to store the track equivalent data following authorization (True/False)

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Track equivalent data found on the chip ________ from the track data found on the magnetic stripe, as the chip track data contains a unique Chip CVV/CVC Code.

This prevents criminals from producing cloned magnetic stripe cards from chip track data.

A

Differs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Cardholder data flows between and through 1️⃣__________,2️⃣___________,3️⃣_____________________

A

1️⃣applications
2️⃣systems
3️⃣network infrastructure devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

It is very important to document all cardholder data flows prior to beginning any assessment activities (True/False)

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

An ____________ should be developed to identify all systems that store, process, or transmit cardholder data

A

Inventory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Information to be maintained in the inventory could include:

A
⚫️System name
⚫️Cardholder data stored 
⚫️Reason for storage 
⚫️ Retention period
⚫️Protection mechanism
17
Q

Cardholder data is stored in both 1️⃣____________ and 2️⃣___________ locations on most networks.

A

1️⃣known

2️⃣unknown

18
Q

Cardholder data can ___________ on known storage locations

A

Leak out

19
Q

Having a good ________ could be the starting point to identify cardholder data storage locations

A

Inventory

20
Q

It is not permitted to store full track data or other sensitive authentication data after authorization. (True/False)

A

True