
[Sep-2025] PCI SSC QSA_New_V4 Exam Practice Test Questions - PassCollection
Updated Certification Exam QSA_New_V4 Dumps - Practice Test Questions
NEW QUESTION # 34
An internal NTP server that provides time services to the Cardholder Data Environment is?
- A. Only in scope if it provides time services to database servers.
- B. Only in scope if it stores, processes or transmits cardholder data.
- C. Not in scope for PCI DSS.
- D. In scope for PCI DSS.
Answer: D
Explanation:
Scope definition in PCI DSS v4.0.1 (Section 4)includesany system that can impact the security of the CDE.
Time synchronization servers such asNTParecritical to log integrity(Requirement 10.6), and if they provide services to CDE systems,they are in scopeeven if they do not directly process cardholder data.
* Option A:#Incorrect. Scope is broader than just databases.
* Option B:#Incorrect. Time serversimpact log security, so they are in scope.
* Option C:#Incorrect. PCI DSS scope includes systems thataffect the securityof CDE, not just those storing card data.
* Option D:#Correct. Internal NTP servers providing services to the CDE arein scope.
NEW QUESTION # 35
Which of the following can be sampled for testing during a PCI DSS assessment?
- A. Compensating controls.
- B. PCI DSS requirements and testing procedures.
- C. Business facilities and system components.
- D. Security policies and procedures.
Answer: C
Explanation:
Sampling is a legitimate method under PCI DSS for assessing a representative subset of system components and locations.Section 6 - Sampling for PCI DSS Assessmentsoutlines thatsampling of business facilities and system componentsis allowed, as long as it's justified, consistent, and documented.
* Option A:Incorrect. PCI DSS requirements themselvescannotbe sampled.
* Option B:Incorrect.Compensating controls must be assessed in full, not sampled.
* Option C:Correct. Sampling may apply tobusiness facilities and system componentsto make the assessment more efficient.
* Option D:Incorrect.Policies and proceduresmust be evaluated in full.
NEW QUESTION # 36
According to the glossary, "bespoke and custom software" describes which type of software?
- A. Any software developed by a third party.
- B. Any software developed by a third party that can be customized by an entity.
- C. Software developed by an entity for the entity's own use.
- D. Virtual payment terminals.
Answer: C
Explanation:
As per thePCI DSS Glossary, "bespoke and custom software" is defined assoftware that is developed specifically for, and often by, the entity using it. This includes internally developed applications and externally developed applications created specifically for the entity.
* Option A:#Incorrect. Not all third-party software is custom - much is commercial off-the-shelf (COTS).
* Option B:#Incorrect. Customisability does not equal bespoke development.
* Option C:#Correct. Bespoke software is tailoredby or forthe entity's specific needs.
* Option D:#Incorrect. Virtual terminals are payment interfaces, not types of software.
NEW QUESTION # 37
Which systems must have anti-malware solutions?
- A. Any in-scope system except for those identified as 'not at risk' from malware.
- B. All CDE systems, connected systems, NSCs, and security-providing systems.
- C. All portable electronic storage.
- D. All systems that store PAN.
Answer: A
Explanation:
Requirement 5.2.1.1clarifies thatanti-malware solutions are requiredonall in-scope systems,unlessthe system is evaluated asnot at risk for malware(e.g., Linux-based appliances with no Internet access). These risk evaluations must be documented and justified (5.2.3.1).
* Option A:#Incorrect. PCI DSS allows exceptions for systems not at risk.
* Option B:#Incorrect. Anti-malware applies to systems, not portable media per se.
* Option C:#Incorrect. Anti-malware scope is broader than just PAN-storing systems.
* Option D:#Correct. Systems not at risk can be excluded if justified and documented.
Reference:PCI DSS v4.0.1 - Requirement 5.2.1.1 and 5.2.3.1.
NEW QUESTION # 38
Which of the following statements Is true whenever a cryptographic key Is retired and replaced with a new key?
- A. All data encrypted under the retired key must be securely destroyed.
- B. The retired key must not be used for encryption operations.
- C. Cryptographic key components from the retired key must be retained for 3 months before disposal.
- D. Anew key custodian must be assigned.
Answer: B
NEW QUESTION # 39
Which of the following is true regarding internal vulnerability scans?
- A. They must be performed by an Approved Scanning Vendor (ASV).
- B. They must be performed after a significant change.
- C. They must be performed by QSA personnel.
- D. They must be performed at least annually.
Answer: B
Explanation:
Internal vulnerability scanning is addressed underRequirement 11.3.1. According to PCI DSS, internal vulnerability scansmust be conducted at least once every three monthsandafter any significant changein the environment, such as new system components, changes in network topology, firewall rule changes, or product upgrades.
* Option A:Correct. Scans must be performed after significant changes.
* Option B:Incorrect. Internal scansdo not require an ASV. ASVs are required for external vulnerability scans (Requirement 11.3.2).
* Option C:Incorrect. A QSA is not required to perform internal scans. They can be performed by qualified internal staff or third-party providers.
* Option D:Incorrect. Internal scans arerequired quarterly, not annually.
NEW QUESTION # 40
An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity's PCI DSS assessment?
- A. It automatically makes an entity PCI DSS compliant.
- B. There is no impact to the entity.
- C. It may help the entity to meet several requirements in Requirement 6.
- D. The custom software can be excluded from the PCI DSS assessment.
Answer: C
Explanation:
TheSecure Software Lifecycle (SLC) Standardis part of PCI'sSoftware Security Framework (SSF). If an entity's software is developed under aPCI-recognised Secure SLC process, it maysatisfy parts of Requirement
6, especially around secure coding practices and vulnerability management.
* Option A:#Incorrect. SLC compliance alone doesn't grant full PCI DSS compliance.
* Option B:#Correct. Secure SLC can help meetmany of the development-related controls.
* Option C:#Incorrect. There isimpact- potentially reducing scope/testing.
* Option D:#Incorrect. The software remainsin scope, but fewer controls may need to be separately validated.
NEW QUESTION # 41
If segmentation is being used to reduce the scope of a PCI DSS assessment, the assessor will?
- A. Verify the segmentation controls allow only necessary traffic into the cardholder data environment.
- B. Verify the controls used for segmentation are configured properly and functioning as intended.
- C. Verify that approved devices and applications are used for the segmentation controls.
- D. Verify the payment card brands have approved the segmentation.
Answer: B
Explanation:
PCI DSS clearly states inRequirement 11.4.5and in theScoping Guidancethat if segmentation is used, the assessor must verify thesegmentation is effective- meaning it must be technically and operationally validated to ensure that it properly isolates the Cardholder Data Environment (CDE) from out-of-scope networks.
* Option A:Too narrow. While allowing only necessary traffic is important, the verification involves more than that.
* Option B:Incorrect. Payment brands do not "approve" segmentation.
* Option C:Incorrect. PCI DSS focuses on effectiveness, not brand-specific device use.
* Option D:Correct. Assessor must ensure that segmentation controls areproperly configured and function as intended.
NEW QUESTION # 42
A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has Implemented a badge access-control system that Identifies who entered and exited the room, on what date, and at what time. There are no video cameras located in the server room.Based on this information, which statement is true regarding PCI DSS physical security requirements?
- A. The merchant must install motion-sensing alarms In addition to the existing access-control system.
- B. The merchant must Install video cameras in addition to the existing access-control system.
- C. Data from the access-control system must be securely deleted on a monthly basis.
- D. The badge access-control system must be protected from tampering or disabling.
Answer: D
Explanation:
Physical Security Requirements:
* PCI DSS Requirement 9.1.1 mandates that physical access control systems (like badge readers) must be protected against tampering or disabling to ensure continuous security.
Current Implementation:
* The merchant's badge access-control system provides essential logging of access events but must also be protected against tampering to comply with PCI DSS.
Invalid Options:
* B:Video cameras are recommended but not explicitly required if access controls effectively ensure security.
* C:Secure deletion of access-control logs is not a PCI DSS requirement; logs must be retained as per retention policies.
* D:Motion-sensing alarms are not mandatory under PCI DSS physical security requirements.
NEW QUESTION # 43
An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity's PCI DSS assessment?
- A. It automatically makes an entity PCI DSS compliant.
- B. There is no impact to the entity.
- C. It may help the entity to meet several requirements in Requirement 6.
- D. The custom software can be excluded from the PCI DSS assessment.
Answer: C
Explanation:
TheSecure Software Lifecycle (SLC) Standardis part of PCI'sSoftware Security Framework (SSF). If an entity's software is developed under aPCI-recognised Secure SLC process, it maysatisfy parts of Requirement
6, especially around secure coding practices and vulnerability management.
* Option A:#Incorrect. SLC compliance alone doesn't grant full PCI DSS compliance.
* Option B:#Correct. Secure SLC can help meetmany of the development-related controls.
* Option C:#Incorrect. There isimpact- potentially reducing scope/testing.
* Option D:#Incorrect. The software remainsin scope, but fewer controls may need to be separately validated.
Reference:PCI DSS v4.0.1 - Requirement 6, and Appendix F: PCI Software Security Framework Reference.
NEW QUESTION # 44
Passwords for default accounts and default administrative accounts should be?
- A. Configured to expire in 30 days.
- B. Changed within 30 days after installing a system on the network.
- C. Changed before installing a system on the network.
- D. Reset to the default password before installing a system on the network.
Answer: C
Explanation:
According toRequirement 2.2.6,default passwords must be changed before systems are installed on the network. The use of default credentials (such as "admin/admin") presents a major security risk and is a well- known vector for breaches.
* Option A:#Incorrect. Changing within 30 days is not soon enough per PCI DSS.
* Option B:#Incorrect. Resetting to default would defeat the purpose of secure configuration.
* Option C:#Correct. The requirement is to change default passwordsprior to network connection.
* Option D:#Incorrect. Password expiration policies are a separate topic under Requirement 8.
References:
PCI DSS v4.0.1 - Requirement 2.2.6;
PCI DSS v4.0.1 - Guidance for Requirement 2.2.6.
NEW QUESTION # 45
A sample of business facilities is reviewed during the PCI DSS assessment. What is the assessor required to validate about the sample?
- A. It includes a consistent set of facilities that are reviewed for all assessments.
- B. Every facility where cardholder data is stored is reviewed.
- C. The number of facilities in the sample is at least 10 percent of the total number of facilities.
- D. All types and locations of facilities are represented.
Answer: D
Explanation:
Sampling in Assessments
* PCI DSS v4.0 requires assessors to ensure that sampled business facilities represent all types and locations to provide comprehensive coverage of the entity's operations.
Sampling Considerations
* Assessors must include facilities storing or processing cardholder data and validate controls across diverse locations.
Incorrect Options
* Option A: Consistency does not ensure comprehensive representation.
* Option B: PCI DSS does not mandate a 10% sample size.
* Option C: It is not mandatory to review every facility storing cardholder data.
NEW QUESTION # 46
If segmentation is being used to reduce the scope of a PCI DSS assessment, the assessor will?
- A. Verify the segmentation controls allow only necessary traffic into the cardholder data environment.
- B. Verify the controls used for segmentation are configured properly and functioning as intended.
- C. Verify that approved devices and applications are used for the segmentation controls.
- D. Verify the payment card brands have approved the segmentation.
Answer: B
Explanation:
PCI DSS clearly states inRequirement 11.4.5and in theScoping Guidancethat if segmentation is used, the assessor must verify thesegmentation is effective- meaning it must be technically and operationally validated to ensure that it properly isolates the Cardholder Data Environment (CDE) from out-of-scope networks.
* Option A:Too narrow. While allowing only necessary traffic is important, the verification involves more than that.
* Option B:Incorrect. Payment brands do not "approve" segmentation.
* Option C:Incorrect. PCI DSS focuses on effectiveness, not brand-specific device use.
* Option D:Correct. Assessor must ensure that segmentation controls areproperly configured and function as intended.
Reference:PCI DSS v4.0.1 - Requirement 11.4.5; and "Guidance for PCI DSS Scoping and Network Segmentation," section 3.1.
NEW QUESTION # 47
Where can live PANs be used for testing?
- A. Testing with live PANs must only be performed in the OSA Company environment.
- B. Pre-production environments thatare located within the CDE.
- C. Pre-production (test) environments only it located outside the CDE.
- D. Production (live) environments only.
Answer: B
Explanation:
Testing with Live PANs
* PCI DSS Requirement 6.4.3 requires that live PANs (Primary Account Numbers) only be used in secure and controlled environments within the CDE.
* Pre-production environments located within the CDE must adhere to all PCI DSS requirements for security and monitoring.
Prohibited Uses
* Testing with live PANs in environments outside the CDE violates PCI DSS. Only simulated data should be used in less secure testing environments.
Incorrect Options
* Option A: Production environments are for real transactions, not testing.
* Option B: Test environments outside the CDE are insecure for live PANs.
* Option D: The QSA environment is irrelevant to the organization's CDE testing controls.
NEW QUESTION # 48
What isthe intent of classifying media that contains cardholder data?
- A. Ensuring that media containing cardholder data Is moved from secured areas an a quarterly basis.
- B. Ensuring that media is clearly and visibly labeled as "Confidential" so all personnel know that the media contains cardholder data.
- C. Ensuring that all media is consistently destroyed on the same schedule, regardless of the contents.
- D. Ensuring that media is properly protected according to the sensitivity of the data it contains.
Answer: D
Explanation:
Purpose of Classifying Media
* PCI DSS v4.0 emphasizes the need to classify media based on the sensitivity of the data it contains.
Media classification ensures appropriate handling, storage, and destruction processes.
Media Protection Requirements
* Media containing cardholder data must be securely stored, transferred, and destroyed when no longer needed.
* Classification informs the level of protection required, such as encryption, physical security, or controlled access.
Incorrect Options
* Option B: Moving media quarterly is not a requirement.
* Option C: Labeling as "Confidential" is insufficient without a comprehensive protection strategy.
* Option D: Destruction schedules should depend on retention requirements and data sensitivity, not a universal timeline.
NEW QUESTION # 49
An internal NTP server that provides time services to the Cardholder Data Environment is?
- A. Only in scope if it provides time services to database servers.
- B. Only in scope if it stores, processes or transmits cardholder data.
- C. Not in scope for PCI DSS.
- D. In scope for PCI DSS.
Answer: D
Explanation:
Scope definition in PCI DSS v4.0.1 (Section 4)includesany system that can impact the security of the CDE.
Time synchronization servers such asNTParecritical to log integrity(Requirement 10.6), and if they provide services to CDE systems,they are in scopeeven if they do not directly process cardholder data.
* Option A:#Incorrect. Scope is broader than just databases.
* Option B:#Incorrect. Time serversimpact log security, so they are in scope.
* Option C:#Incorrect. PCI DSS scope includes systems thataffect the securityof CDE, not just those storing card data.
* Option D:#Correct. Internal NTP servers providing services to the CDE arein scope.
References:
PCI DSS v4.0.1 - Section 4: Scope of PCI DSS Requirements;
Requirement 10.6.1.1.
NEW QUESTION # 50
An LDAP server providing authentication services to the cardholder data environment is_____________?
- A. in scope only if itprovides authentication services to systems in the DMZ.
- B. in scope for PCI DSS.
- C. in scope only if it stores, processes or transmits cardholder data.
- D. not In scope for PCI DSS.
Answer: B
Explanation:
Scope of PCI DSS:
* PCI DSS applies to all systems that store, process, or transmit cardholder data (CHD), as well as systems that can impact the security of the CDE. An LDAP server providing authentication services is considered a connected system that could impact the security of CHD and is therefore in scope.
Clarifications on Scope:
* Systems like LDAP servers that do not directly handle CHD but provide critical services to the CDE (e.
g., authentication) are in scope for PCI DSS.
Invalid Options:
* B/C/D:Scoping is not limited to direct storage, processing, or transmission of CHD but includes systems that could affect the CDE's security.
NEW QUESTION # 51
Which of the following describes "stateful responses" to communication initiated by a trusted network?
- A. Active network connections are tracked so that invalid "response" traffic can be identified.
- B. Logs of user activity on the firewall are correlated to identify and respond to suspicious behavior.
- C. A current baseline of application configurations is maintained and any misconfiguration is responded to promptly.
- D. Administrative access to respond to requests to change the firewall is limited to one individual at a time.
Answer: A
Explanation:
Stateful inspection (or stateful packet filtering)tracks the state of active connections and determines which packets are part of a valid session.Requirement 1.4.2references the use of network security controls (NSCs) withstateful filteringcapability to allow legitimate trafficonly in response to trusted requests.
* Option A:#Incorrect. Firewall admin procedures are not what "stateful" refers to.
* Option B:#Correct. "Stateful responses" mean tracking existing connections toblock unauthorised or spoofed responses.
* Option C:#Incorrect. That describes configuration management, not stateful filtering.
* Option D:#Incorrect. Logging is important but not part of stateful inspection.
NEW QUESTION # 52
Assigning a unique ID to each person is intended to ensure?
- A. Access is assigned to group accounts based on need-to-know.
- B. Strong passwords are used for each user account.
- C. Shared accounts are only used by administrators.
- D. Individual users are accountable for their own actions.
Answer: D
Explanation:
According toRequirement 8.2.1, PCI DSS mandates that all users be assigned aunique IDbefore accessing system components or cardholder data. This ensuresaccountability, enabling identification of actions taken by each user.
* Option A:#Incorrect. Password strength is addressed underRequirement 8.3, not unique ID.
* Option B:#Incorrect. Shared accounts areprohibitedregardless of admin status.
* Option C:#Correct. Unique IDs ensure thateach user's actions can be traced.
* Option D:#Incorrect. Group accounts are discouraged in favour of individual accountability.
NEW QUESTION # 53
Viewing of audit log files should be limited to?
- A. Individuals with a job-related need.
- B. Individuals who performed the logged activity.
- C. Individuals with read/write access.
- D. Individuals with administrator privileges.
Answer: A
Explanation:
Audit Log Access Control:
* PCI DSS Requirement 10.7 restricts access to audit logs to individuals with a job-related need to protect the integrity and confidentiality of the logs.
Rationale for Job-Related Need:
* Limiting access reduces the risk of tampering, accidental modification, or exposure of sensitive information.
Invalid Options:
* A:Individuals who performed the activity should not necessarily view logs unless required.
* B/C:Read/write access or administrator privileges are not prerequisites for log viewing.
NEW QUESTION # 54
An entity wants to know if the Software Security Framework can be leveraged during their assessment.
Which of the following software types would this apply to?
- A. Validated Payment Applications that are listed by PCI SSC and have undergone a PA-DSS assessment.
- B. Only software which runs on PCI PTS devices.
- C. Any payment software in the CDE.
- D. Software developed by the entity in accordance with the Secure SLC Standard.
Answer: D
Explanation:
TheSoftware Security Framework (SSF)is intended to support entities usingbespoke and custom softwarewithin the Cardholder Data Environment (CDE). If the software is developed and maintained in accordance with theSecure Software Lifecycle (SLC) Standard, it can help demonstrate secure software development practices and potentially reduce the number of applicable PCI DSS requirements.
* Option A:Incorrect. Not all payment software qualifies unless developed under SSF standards.
* Option B:Incorrect. PCI PTS devices follow different hardware security standards.
* Option C:Incorrect. PA-DSS has been retired; those applications are now listed as "Acceptable Only for Pre-Existing Deployments".
* Option D:Correct. Software developed under the Secure SLC Standard may help an entity meet some requirements in PCI DSS Requirement 6.
Reference:PCI DSS v4.0.1 - Appendix F; Section 3, page 7; Secure Software Lifecycle (Secure SLC) Standard.
NEW QUESTION # 55
An entity wants to know if the Software Security Framework can be leveraged during their assessment.
Which of the following software types would this apply to?
- A. Validated Payment Applications that are listed by PCI SSC and have undergone a PA-DSS assessment.
- B. Only software which runs on PCI PTS devices.
- C. Any payment software in the CDE.
- D. Software developed by the entity in accordance with the Secure SLC Standard.
Answer: D
Explanation:
TheSoftware Security Framework (SSF)is intended to support entities usingbespoke and custom softwarewithin the Cardholder Data Environment (CDE). If the software is developed and maintained in accordance with theSecure Software Lifecycle (SLC) Standard, it can help demonstrate secure software development practices and potentially reduce the number of applicable PCI DSS requirements.
* Option A:Incorrect. Not all payment software qualifies unless developed under SSF standards.
* Option B:Incorrect. PCI PTS devices follow different hardware security standards.
* Option C:Incorrect. PA-DSS has been retired; those applications are now listed as "Acceptable Only for Pre-Existing Deployments".
* Option D:Correct. Software developed under the Secure SLC Standard may help an entity meet some requirements in PCI DSS Requirement 6.
NEW QUESTION # 56
If an entity shares cardholder data with a TPSP, what activity is the entity required to perform?
- A. The entity must test the TPSP's incident response plan at least quarterly.
- B. The entity must perform a risk assessment of the TPSP's environment at least quarterly.
- C. The entity must monitor the TPSP's PCI DSS compliance status at least annually.
- D. The entity must conduct ASV scans on the TPSP's systems at least annually.
Answer: C
Explanation:
PCI DSSRequirement 12.8.4mandates that an entitymonitor the compliance status of third-party service providers (TPSPs) at least annually, especially when those TPSPs store, process, or transmit account data on the entity's behalf.
* Option A:Incorrect. Entities are not responsible for conducting ASV scans on TPSPs.
* Option B:Incorrect. There is no quarterly risk assessment requirement for TPSPs.
* Option C:Incorrect. Incident response testing for TPSPs is not a direct responsibility of the entity.
* Option D:Correct. Annual monitoring of TPSP compliance is explicitly required.
NEW QUESTION # 57
Which of the following is a requirement for multi-tenant service providers?
- A. Provide customers with a shared user ID for access to critical system binaries.
- B. Ensure that a customer's log files are available to all hosted entities.
- C. Ensure that customers cannot access another entity's cardholder data environment.
- D. Provide customers with access to the hosting provider's system configuration files.
Answer: C
Explanation:
Formulti-tenant service providers,isolation and segmentationare critical. As perRequirement 12.10.3, each customer's environment must besegregated and protectedsuch that no tenant can access another's data or systems.
* Option A:#Correct. This is the foundational control -isolation of customer environments.
* Option B:#Incorrect. Exposing system config files is a security risk.
* Option C:#Incorrect. Shared user IDs areexplicitly prohibitedby Requirement 8.2.1.
* Option D:#Incorrect. Customers should only access their own logs.
NEW QUESTION # 58
......
Updated Verified QSA_New_V4 dumps Q&As - Pass Guarantee or Full Refund: https://examtests.passcollection.com/QSA_New_V4-valid-vce-dumps.html

