Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Qualified Security Assessor V4 Exam

Last Update 8 hours ago Total Questions : 75

The Qualified Security Assessor V4 Exam content is now fully updated, with all current exam questions added 8 hours ago. Deciding to include QSA_New_V4 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our QSA_New_V4 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these QSA_New_V4 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Qualified Security Assessor V4 Exam practice test comfortably within the allotted time.

Question # 11

What would be an appropriate strength for the key-encrypting key (KEK) used to protect an AES 128-bit data-encrypting key (DEK)?

A.

DES 256

B.

RSA 512

C.

AES 128

D.

ROT 13

Question # 12

Which statement about the Attestation of Compliance (AOC) is correct?

A.

There are different AOC templates for service providers and merchants.

B.

The AOC must be signed by both the merchant/service provider and by PCI SSC.

C.

The same AOC template is used for ROCs and SAQs.

D.

The AOC must be signed by either the merchant/service provider or the QSA/ISA.

Question # 13

A network firewall has been configured with the latest vendor security patches. What additional configuration is needed to harden the firewall?

A.

Remove the default “Firewall Administrator” account and create a shared account for firewall administrators to use.

B.

Configure the firewall to permit all traffic until additional rules are defined.

C.

Synchronize the firewall rules with the other firewalls in the environment.

D.

Disable any firewall functions that are not needed in production.

Question # 14

Which of the following describes the intent of installing one primary function per server?

A.

To allow functions with different security levels to be implemented on the same server.

B.

To prevent server functions with a lower security level from introducing security weaknesses to higher-security functions on the same server.

C.

To allow higher-security functions to protect lower-security functions installed on the same server.

D.

To reduce the security level of functions with higher-security needs to meet the needs of lower-security functions.

Question # 15

What must be included in an organization ' s procedures for managing visitors?

A.

Visitors are escorted at all times within areas where cardholder data is processed or maintained.

B.

Visitor badges are identical to badges used by onsite personnel.

C.

Visitor log includes visitor name, address, and contact phone number.

D.

Visitors retain their identification (for example, a visitor badge) for 30 days after completion of the visit.

Question # 16

Which systems must have anti-malware solutions?

A.

All CDE systems, connected systems, NSCs, and security-providing systems.

B.

All portable electronic storage.

C.

All systems that store PAN.

D.

Any in-scope system except for those identified as ‘not at risk’ from malware.

Question # 17

A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has implemented a badge access-control system that identifies who entered and exited the room, on what date, and at what time. There are no video cameras located in the server room. Based on this information, which statement is true regarding PCI DSS physical security requirements?

A.

The badge access-control system must be protected from tampering or disabling.

B.

The merchant must install video cameras in addition to the existing access-control system.

C.

Data from the access-control system must be securely deleted on a monthly basis.

D.

The merchant must install motion-sensing alarms in addition to the existing access-control system.

Question # 18

Which of the following file types must be monitored by a change-detection mechanism (for example, a file-integrity monitoring tool)?

A.

Application vendor manuals

B.

Files that regularly change

C.

Security policy and procedure documents

D.

System configuration and parameter files

Question # 19

Which systems must have anti-malware solutions?

A.

All CDE systems, connected systems. NSCs, and security-providing systems.

B.

All portable electronic storage.

C.

All systems that store PAN.

D.

Any in-scope system except for those identified as ' not at risk ' from malware.

Question # 20

According to the glossary, " bespoke and custom software” describes which type of software?

A.

Any software developed by a third party.

B.

Any software developed by a third party that can be customized by an entity.

C.

Software developed by an entity for the entity’s own use.

D.

Virtual payment terminals.

Go to page: