DumpsFree provides high-quality dumps PDF & dumps VCE for candidates who are willing to pass exams and get certifications soon. We provide dumps free download before purchasing dumps VCE. 100% pass exam!

Assessor_New_V4 Dumps - Grab Out For [NEW-2024] PCI SSC Exam [Q15-Q30]

Share

Assessor_New_V4 Dumps - Grab Out For [NEW-2024] PCI SSC Exam

Assessor_New_V4 Exam Dumps PDF Guaranteed Success with Accurate & Updated Questions

NEW QUESTION # 15
Security policies and operational procedures should be?

  • A. Encrypted with strong cryptography
  • B. Reviewed and updated at least quarterly
  • C. Distributed to and understood by all affected parties
  • D. Stored securely so that only management has access

Answer: C


NEW QUESTION # 16
Which of the following statements is true whenever a cryptographic key is retired and replaced with a new key?

  • A. All data encrypted under the retired key must be securely destroyed
  • B. A new key custodian must be assigned
  • C. The retired key must not be used for encryption operations
  • D. Cryptographic key components from the retired key must be retained for 3 months before disposal

Answer: C

Explanation:
Explanation
PCI DSS Requirement 3.6.4 states that entities must retire or replace keys when the keys have reached the end of their cryptoperiod, which is the time span during which a specific key can be used for cryptographic operations1. The retired key must not be used for encryption operations, as it may have been compromised or weakened by cryptanalysis, and may not provide adequate protection for the data. The retired key may still be used for decryption operations, if needed, to access historical data that was encrypted under the retired key2.
Therefore, the correct answer is option A.
The other options are not true regarding the cryptographic key retirement and replacement. Option B is not true because PCI DSS does not specify a retention period for the cryptographic key components from the retired key, although it requires entities to securely delete cryptographic material when it is no longer needed for business or legal reasons1. Option C is not true because PCI DSS does not require a new key custodian tobe assigned, although it requires entities to define and document the roles, responsibilities, and accountability of all key custodians1. Option D is not true because PCI DSS does not require all data encrypted under the retired key to be securely destroyed, although it requires entities to render cardholder data unreadable when it is no longer needed for business or legal reasons1. References:
PCI DSS v3.2.1
Cryptographic Key Blocks - PCI Security Standards Council


NEW QUESTION # 17
Which of the following parties is responsible for completion of the Controls Matrix for the Customized Approach?

  • A. Either a QSA, AQSA, or PClP.
  • B. Only a Qualified Security Assessor (QSA)
  • C. Card brands or acquirer
  • D. Entity being assessed

Answer: D

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, assigning a unique ID to each person is intended to ensure individual users are accountable for their own actions, rather than shared accounts or group accounts based on need-to-know. This is one of the requirements for ensuring that user accounts are properly managed and controlled.


NEW QUESTION # 18
An LDAP server providing authentication services to the cardholder data environment is

  • A. in scope for PCI DSS.
  • B. not in scope for PCI DSS
  • C. in scope only if it provides authentication services to systems in the DMZ
  • D. in scope only if it stores processes or transmits cardholder data

Answer: A

Explanation:
Explanation
An LDAP server is a type of directory service that provides authentication and authorization data to the cardholder data environment (CDE)1. According to the PCI DSS scoping and segmentation guidance2, any system that provides a security service to the CDE, such as authentication, is considered a connected or security-impacting system (Category 2) and is in scope for PCI DSS. This is because such systems can affect the security and controls of the CDE and the cardholder data (CHD) or sensitive authentication data (SAD) that it contains. Therefore, an LDAP server providing authentication services to the CDE is in scope for PCI DSS, regardless of whether it stores, processes, or transmits CHD or SAD, or whether it provides authentication services to systems in the DMZ or not. References:
Guidance for PCI DSS Scoping and Network Segmentation
What Are the Effects of Using Active Directory as a Shared Service on PCI Compliance?
The Ultimate Guide To PCI DSS Scoping and Segmentation
LDAP - PCI Security Standards Council


NEW QUESTION # 19
If segmentation is being used to reduce the scope of a PCI DSS assessment the assessor will?

  • A. Verify that approved devices and applications are used for the segmentation controls
  • B. Verify the controls used for segmentation are configured properly and functioning as intended
  • C. Verify the segmentation controls allow only necessary traffic into the cardholder data environment.
  • D. Verify the payment card brands have approved the segmentation

Answer: B

Explanation:
Explanation
Segmentation is a method of isolating system components that store, process, or transmit cardholder data from systems that do not, by using security controls such as firewalls, routers, switches, or other devices1. Segmentation can reduce the scope of the cardholder data environment (CDE) and thus reduce the scope of the PCI DSS assessment, as only the systems and networks within the CDE or connected to the CDE are subject to PCI DSS requirements2. However, segmentation is not mandatory for PCI DSS compliance, and it is the responsibility of the entity to define and document the scope of their CDE and the segmentation controls they use2.
The assessor's role is to verify the scope of the CDE and the effectiveness of the segmentation controls, as specified in PCI DSS Requirement 11.3.43. The assessor must verify that the segmentation controls are configured properly and functioning as intended, and that they allow only necessary traffic into the CDE. The assessor must also perform penetration testing on the segmentation controls at least annually and after anychanges to the segmentation methods, to confirm that there are no exploitable vulnerabilities that could allow an attacker to access the CDE from out-of-scope systems3. Therefore, the correct answer is option D.
The other options are not true regarding the role of the assessor in verifying segmentation for PCI DSS. Option A is not true because the assessor must verify not only that the segmentation controls allow only necessary traffic into the CDE, but also that they are configured properly and functioning as intended, as stated in option D: Option B is not true because the assessor does not need to verify that the payment card brands have approved the segmentation, as PCI DSS does not require such approval, although the payment card brands may have their own policies and procedures for segmentation that the entity must follow2. Option C is not true because the assessor does not need to verify that approved devices and applications are used for the segmentation controls, as PCI DSS does not mandate the use of specific devices or applications for segmentation, although it requires the entity to use industry-accepted and strong methods for segmentation2. References:
Network Segmentation - PCI Security Standards Council
Guidance for PCI DSS Scoping and Network Segmentation
PCI DSS v3.2.1


NEW QUESTION # 20
What would be an appropriate strength for the key-encrypting key (KEK) used to protect an AES 128-bit data-encrypting key (DEK)

  • A. AES 128
  • B. RSA512
  • C. DES256
  • D. ROT 13

Answer: A

Explanation:
Explanation
The key-encrypting key (KEK) is used to protect the data-encrypting key (DEK) from unauthorized access or disclosure. The KEK should have a strength that is equal to or greater than the DEK, to prevent a weaker link in the encryption chain. According to the PCI Card Production Logical Security Requirements, section 4.1.1,
"The key-encrypting key (KEK) must be at least as strong as the data-encrypting key (DEK) it protects." Furthermore, section 4.1.2 states, "The KEK must be generated using a secure random number generator (RNG) that meets the requirements of NIST SP 800-90A or equivalent." AES 128 is a symmetric encryption algorithm that uses a 128-bit key and meets the NIST standards. Therefore, it would be an appropriate strength for the KEK used to protect an AES 128-bit DEK. The other options are either weaker or asymmetric encryption algorithms, which are not suitable for the KEK. References: PCI Card Production Logical Security Requirements, [NIST SP 800-90A]


NEW QUESTION # 21
an entity under assessment is using the customized approach, which of the following steps is the responsibility of the assessor?

  • A. Monitor the control.
  • B. Document and maintain evidence about each customized control as defined in Appendix E of PCI DSS
  • C. Derive testing procedures and document them in Appendix E of the ROC.
  • D. Perform the targeted risk analysis as per PCI DSS requirement 12.3.2

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, the assessor must derive testing procedures and document them in Appendix E of the ROC. This is one of the requirements for ensuring that testing procedures are defined and documented.


NEW QUESTION # 22
Which of the following is true regarding compensating controls?

  • A. A compensating control must address the risk associated with not adhering to the PCI DSS requirement
  • B. A compensating control worksheet is not required if the acquirer approves the compensating control
  • C. A compensating control is not necessary if all other PCI DSS requirements are in place
  • D. An existing PCI DSS requirement can be used as compensating control if it is already implemented

Answer: A

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, a compensating control must address the risk associated with not adhering to a PCI DSS requirement and must be approved by an authorized person before implementation. This is one of the requirements for reducing or eliminating a risk that cannot be eliminated by other means


NEW QUESTION # 23
According torequirement 1,what is the purpose of "Network Security Controls?

  • A. Control network traffic between two or more logical or physical network segments.
  • B. Encrypt PAN when stored
  • C. Discover vulnerabilities and rank them
  • D. Manage anti-malware throughout the CDE.

Answer: A

Explanation:
Explanation
According to requirement 1, network security controls are intended to control network traffic between two or more logical or physical network segments, which means they should prevent unauthorized access, modification, or disclosure of cardholder data or transactions over the network. This is one of the requirements for ensuring that network security controls are implemented and maintained in accordance with PCI DSS.


NEW QUESTION # 24
At which step in the payment transaction process does the merchants bank pay the merchant for the purchase and the cardholder s bank bill the cardholder?

  • A. Clearing
  • B. Chargeback
  • C. Authorization
  • D. Settlement

Answer: D

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, settlement occurs when a merchant receives payment from a card issuer for a completed transaction and delivers goods or services to a customer or another party as agreed upon in advance by both parties, subject to any conditions imposed by either party upon delivery or payment, including but not limited to acceptance, rejection, return, exchange, refund, cancellation, modification, suspension, termination or revocation by either party upon delivery or payment; or any other conditions imposed by either party upon delivery or payment; or any other conditions imposed by either party upon delivery or payment; or any other conditions imposed by either party upon delivery or payment;


NEW QUESTION # 25
Security policies and operational procedures should be?

  • A. Encrypted with strong cryptography
  • B. Reviewed and updated at least quarterly
  • C. Distributed to and understood by all affected parties
  • D. Stored securely so that only management has access

Answer: C

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, security policies and operational procedures should be distributed to and understood by all affected parties, such as management, staff, contractors, vendors, and service providers. This is one of the requirements for ensuring that security policies and operational procedures are communicated and followed consistently.


NEW QUESTION # 26
Which of the following describes "stateful responses' to communication initiated by a trusted network?

  • A. Active network connections are tracked so that invalid response' traffic can be identified.
  • B. Administrative access to respond to requests to change the firewall is limited to one individual at a time
  • C. Logs of user activity on the firewall are correlated to identify and respond to suspicious behavior
  • D. A current baseline of application configurations is maintained and any mis-configuration is responded to promptly

Answer: A

Explanation:
Explanation
According to the PCI DSS v3.2.1 Quick Reference Guide1, active network connections are tracked so that invalid response traffic can be identified. This is one of the requirements for preventing replay attacks and ensuring secure communication.


NEW QUESTION # 27
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?

  • A. Application IDs for database applications can only be used by database administrators
  • B. User access to the database is only through programmatic methods
  • C. User access to the database is restricted to system and network administrators
  • D. Direct queries to the database are restricted to shared database administrator accounts

Answer: A

Explanation:
Explanation
application IDs for database applications can only be used by database administrators, which means they should have access to all database applications and their settings. This is one of the requirements for ensuring that database administrators have full control over database applications.


NEW QUESTION # 28
Which of the following types of events is required to be logged?

  • A. All access to external web sites
  • B. All access to all audit trails
  • C. All network transmissions
  • D. All use of end-user messaging technologies

Answer: B

Explanation:
Explanation
all network transmissions must be logged by an entity's security information and event management (SIEM) system or equivalent tool, which means they should record all network events and activities related to cardholder data processing and transmission. This is one of the requirements for ensuring that network transmissions are monitored and audited.


NEW QUESTION # 29
Which scenario describes segmentation of the cardholder data environment (CDE) for the purposes of reducing PCI DSS scope?

  • A. A network configuration that prevents all network traffic between the CDE and out-of-scope networks
  • B. Firewalls that log all network traffic flows between the CDE and out of-scope networks
  • C. Virtual LANs that route network traffic between the CDE and out-of-scope networks
  • D. Routers that monitor network traffic flows between the CDE and out-of-scope networks

Answer: C

Explanation:
Explanation
Segmentation is a method of isolating system components that store, process, or transmit cardholder data from systems that do not, by using security controls such as firewalls, routers, switches, or other devices1. Segmentation can reduce the scope of the cardholder data environment (CDE) and thus reduce the scope of the PCI DSS assessment, as only the systems and networks within the CDE or connected to the CDE are subject to PCI DSS requirements2. Virtual LANs (VLANs) are one example of such a security control, as they can create logical subnetworks that separate different types of traffic and restrict access between them3.
Therefore, the correct answer is option C.
The other options are not true regarding the scenario that describes segmentation of the cardholder data environment (CDE) for the purposes of reducing PCI DSS scope. Option A is not true because routers that monitor network traffic flows between the CDE and out-of-scope networks are not sufficient to isolate the CDE, as they do not prevent or limit the traffic flows. Option B is not true because firewalls that log all network traffic flows between the CDE and out-of-scope networks are not sufficient to isolate the CDE, as they do not block or filter the traffic flows. Option D is not true because a network configuration that prevents all network traffic between the CDE and out-of-scope networks is not realistic or feasible, as some traffic may be necessary for business or legal reasons, such as payment processing, reporting, or auditing. References:
Network Segmentation - PCI Security Standards Council
Guidance for PCI DSS Scoping and Network Segmentation
VLANs and PCI Compliance: What You Need to Know


NEW QUESTION # 30
......

Get New Assessor_New_V4 Certification Practice Test Questions Exam Dumps: https://www.dumpsfree.com/Assessor_New_V4-valid-exam.html

Pass Assessor_New_V4 Exam - Real Test Engine PDF with 62 Questions: https://drive.google.com/open?id=1lbxxGf9gEsqd_7nSMyk63VAEMQHZieju