Browse all practice questions for the PCI Approved Scanning Vendor (ASV) Online Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

PCI Approved Scanning Vendor (ASV) Online Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which PCI DSS compliance program is associated with JCB?
  • Which description best represents what the P2PE Standard covers?
  • What action is recommended for any required services, protocols, or daemons that are insecure?
  • Which statement restricts inbound and outbound traffic to only what is necessary for the cardholder data environment, and denies all other traffic?
  • Which statement about secure development lifecycle is true?
  • What is the primary purpose of a formal Risk Mitigation and Migration Plan for SSL/early TLS usage?
  • What should configuration standards for all system components address?
  • Which vulnerability is described in the 6.5.1 category?
  • Which item is a requirement of PCI P2PE?
  • Which of the following is a component of the CVSS Environmental, General Modifiers?
  • Which item is not listed as a Special Note?
  • Which vulnerability category includes weak authentication and session management?
  • Which statement is true about service providers in PCI context?
  • Where should intrusion-detection and intrusion-prevention systems be deployed?
  • Which vulnerability results in a Special Note?
  • Which statement requires documentation and business justification and approval for use of all services, protocols, and ports allowed?
  • Which of the following is a characteristic of ASV Scans?
  • Which SAQ applies to an online merchant with a payment page that accepts cardholder data, but transmits the data to a PCI DSS compliant service provider?
  • Which mitigation technique is commonly used to defend against cross-site scripting (XSS)?
  • What does it mean to implement only one primary function per server?
  • Which standard covers physical and logical security requirements for systems and business processes?
  • True or False: The scan customer must provide a list of all IPs in a scope for the scan.
  • Which SAQ applies to a merchant with a standalone payment application connected to the Internet?
  • Which CVSS Exploitation metric describes the level of attacker authentication required to access the target?
  • Which statement implements anti-spoofing measures to detect and block forged source IP addresses from entering the network?
  • What is the primary function of a web application firewall in front of public-facing web apps?
  • Which SAQ would apply to an online merchant that displays a PSP's payment page inside an IFRAME, with all page content from the PSP?
  • Which vulnerability is characterized by performing unauthorized actions on a web application using an authenticated user’s credentials?
  • Which of the following statements best matches the content about SSL usage and upgrades?
  • After changes, vulnerability scans can be performed by which of the following?
  • Should private IP addresses and routing information be disclosed to unauthorized parties?
  • Which access must be protected with multi-factor authentication?
  • Which of the following is a valid ASV Scan characteristic?
  • Scan Reporting: Attestation of Scan Compliance — which template appendix is required?
  • A component, as defined on the ASV Scan Report Attestation of Scan Compliance, includes any host, virtual host, IP address, domain, FQDN or unique vector into a system or cardholder data environment.
  • When should development, test, and/or custom application accounts be removed?
  • Which brand uses Account Information Security (AIS) Program as its PCI DSS program?
  • Which standard applies to secure payment applications to support PCI DSS compliance?
  • SSL and/or early TLS must not be introduced into environments where those protocols don't already exist.
  • In Council-listed P2PE, which statement about merchant involvement is correct?
  • Improper error handling can lead to which risk?
  • Which statement best aligns with the upgrade guidance for SSL/early TLS?
  • Which SAQ applies to an online merchant that displays a PCI DSS compliant service provider's payment page in an IFRAME, with all page content coming from the PSP?
  • PA-QSA stands for what?
  • What are the two sections of the CVSS Environmental, General Modifiers Metric?
  • When transmitting cardholder data over open networks, which practice is required?
  • Which CVSS base metric sub-score category includes Confidentiality, Integrity, and Availability?
  • Which of the following is NOT an example of a component listed in the ASV Scan Report?
  • Which two characteristics must passwords meet according to 8.2.1?
  • Which section of the ASV scan report contains the detailed vulnerability findings?
  • What should you do with vendor-supplied defaults before installing a system on the network?
  • Which ASV Scan characteristic identifies the system's services and OS?
  • Which of the following is NOT typically listed as a source of industry-accepted system hardening standards?
  • Which control is established and implemented under 8.2.3?
  • Which SAQ applies to a merchant with only card-present dial-out terminals?
  • Which entity is responsible for developing and enforcing compliance programs?
  • What information is included on the Attestation of Scan Compliance cover page for contact details?
  • SSL/early TLS may be used by POS POI terminals that are verified as not susceptible to known exploits.
  • Which of the following vulnerabilities would cause an automatic failure?
  • What is the target timeframe for installing critical security patches after release?
  • The standard for validating off-the-shelf payment applications used in authorization and settlement is:
  • In the Overall Scan Results, what information is not included?
  • Which standard addresses the protection of sensitive data at the point of interaction devices and their cryptographic keys used with that protection?
  • Which of the following is an example of improper access control?
  • Which wireless control is explicitly prohibited?
  • Which statement limits inbound Internet traffic to IP addresses within the DMZ?
  • Which section contains the dates for scan completion and expiration, the vulnerability summary for each IP, CVSS score, and the pass/fail status?
  • Is a vulnerability with a CVSS score greater than 4.0 automatically considered failing?
  • Insecure direct object references and directory traversal are examples of which vulnerability category?
  • According to requirement 11.2.2, how often must external vulnerability scans be performed by an Approved Scanning Vendor (ASV)?
  • What is the purpose of configuring system security parameters?
  • Which of the following is NOT a responsibility of Payment Brands?
  • Which standard covers encryption, decryption, and Key management requirements for point-to-point encryption solutions?
  • Which type of administrative access must be encrypted using strong cryptography?
  • Can SSL and Early TLS be used to satisfy PCI DSS requirements?
  • A false positive can be issued if evidence shows the vulnerability does not exist, or mitigated by compensating control.
  • In which step does the payment brand network provide complete reconciliation to the merchant's bank?
  • External vulnerability scans must be performed by what type of vendor, approved by which body, and what about rescans?
  • Directory browsing should not be allowed on which scan component?
  • Which of the following functions is associated with acquirers?
  • Which standard covers physical and logical security requirements for card production systems?
  • The PCI SSC Quality Assurance Program requires validation via the ASV Validation Test Bed every two years.
  • Which action is recommended to minimize potential attack surface by removing unnecessary components?
  • What does requirement 8.2 require regarding credentials?
  • Entities using SSL and early TLS for POS POI terminal connections must work toward upgrading to a strong cryptographic protocol as soon as possible.
  • QIR stands for what?
  • Which statement about investigating false positives with CVSS Base score >= 4.0 is true?
  • Which section of the Scan Report provides contact information for both the ASV and the scan customer, overall scan results, and the attestation of the ASV qualified employee?
  • Which statement prohibits unauthorized outbound traffic from the cardholder data environment to the Internet?
  • Which statement prohibits direct public access between the Internet and any system component in the cardholder data environment?
  • Which statement describes the meaning of termination points in POS POI SSL connections?
  • Which statement about CVSS metrics is correct?
  • What are the 3 sections of the CVSS Environmental, Impact Subscore Modifiers Metric?
  • After identifying high-risk vulnerabilities in an internal scan, what action is required?
  • Who ultimately decides the scope for the ASV scan?
  • An ASV must scan everything in the external scope.
  • After vulnerabilities are identified in internal scans, what should be done?
  • Which statement best describes the requirement for avoiding generic and shared IDs in system administration?
  • What is the purpose of industry-accepted system hardening standards?
  • Which of the following is described as an acceptable approach to protect public-facing web applications against known attacks?
  • According to requirement 11.2, vulnerability scans conducted after changes should be performed only by an ASV.
  • Which standard covers the protection of sensitive data at the point of interaction devices and their secure components, including cardholder PINs and account data, and the cryptographic keys used in connection with the protection of that cardholder data?
  • The ASV is ENCOURAGED to investigate inconclusive scans disputed by the scan customer.
  • TLS v1.2 is considered best practice for PCI DSS security.
  • Which SAQ applies to a merchant using an end-to-end encryption solution (E2EE) that utilizes PCI PTS-approved POI devices which communicate with the acquirer over an IP network?
  • When establishing a vulnerability management process, what ranking scheme is suggested for newly discovered vulnerabilities?
  • The PCI SSC's Quality Assurance Program stipulates that quality assurance testing of ASV services and reporting, including validation via the ASV Validation Test Bed, must happen annually.
  • Which tools can be used to categorize and rank vulnerabilities and determine scan compliance?
  • What are the three sections of the CVSS Temporal Metric?
  • What does PCI SSC stand for?
  • How many repeated failed login attempts should be allowed until an account lockout?
  • Which statement prohibits direct public access between the Internet and any system component in the cardholder data environment?
  • For each vulnerability in Vulnerability Details, what must be included?
  • Which of the following is considered secure for system operation?
  • Which element should be included in annual secure coding training for developers?
  • Which PCI DSS compliance program is associated with American Express?
  • Which service is NOT considered secure for use in system operation?
  • Which statement about PA-DSS usage is correct?
  • Executive Summary: Which statement best describes what the Executive Summary contains?
  • Which ASV Scan characteristic accounts for load balancers?
  • Keeping intrusion-detection and prevention engines, baselines, and signatures up to date supports which objective?
  • Which statement reflects requirement 8.3 about IDs?
  • What does CDE stand for in the PCI DSS context?
  • Rescans should verify removal according to which requirement's ranking?
  • Which SAQ applies to a merchant using a validated P2PE solution listed on the PCI SSC website?
  • A vulnerability which exclusively results in denial-of-service, even if it is over the 4.0 score threshold, is not considered a failing vulnerability.
  • SSL/TLS usage is specifically tied to which PCI DSS requirements?
  • Insecure communications refers to which practice?
  • Which statement addresses documentation and business justification and approval for use of all services, protocols, and ports allowed?
  • Which standard is specifically associated with third-party payment applications?
  • Which standard covers physical, logical and device security requirements for securing Hardware Security Modules (HSM)?
  • Who reserves the right to mark any host as out of scope?
  • Which statement mandates installing perimeter firewalls between wireless networks and the cardholder data environment and allowing only authorized traffic?
  • If a host is marked out of scope in the ASV report, what must be documented?
  • Which CVSS metric set does Exploitability belong to according to the material?
  • Which principle should govern connections entering the network?
  • What is the frequency of external vulnerability scans performed by an Approved Scanning Vendor (ASV)?
  • Which requirement restricts inbound and outbound traffic to that which is necessary for the cardholder data environment, and specifically deny all other traffic?
  • Which approach minimizes risk by separating cardholder data from untrusted networks?
  • Which statement about exemptions for scanning systems is true?
  • What must be completed if SSL or early TLS is used?
  • Merchants using PA-DSS validated payment applications are automatically PCI DSS compliant.
  • What are the three items in the CVSS Impact metrics?
  • In PCI P2PE, who performs all cryptographic operations?
  • The ASV's report must include all vulnerabilities found during the scan, even if they were determined to be false positives, out of scope, or remediated prior to a rescan.
  • Which statement best summarizes secure development requirements under PCI DSS?
  • Which statement accurately describes SSL usage on host devices in PCI scanning?
  • Which statement best describes SAQ B-IP?
  • SSL/early TLS is considered strong cryptography and may be used as a security control.
  • The ASV is REQUIRED to investigate false positives with a CVSS Base score at or below 3.9 (a passing score).
  • What is the third phase of the 6 Phases of ASV Scans?
  • Which brand uses Account Information Security (AIS) Program as its PCI DSS program?
  • Injection category identification?
  • Which characteristic is associated with an effective scan solution?
  • By what date did service providers must provide a secure service offering?
  • For wireless networks that transmit cardholder data, which practice is required?
  • Where should system components that store cardholder data be placed?
  • Which of the following are included in cryptographic key operations under PCI P2PE?
  • Which PCI DSS compliance program is associated with Discover?
  • Which statement best describes detection of incomplete or corrupted scans?
  • Which option lists the correct PCI DSS requirement concerns ASVs performing external vulnerability scans?
  • Which two sections comprise the Base Metric in the CVSS scoring system?
  • Which vulnerability is described by injecting malicious scripts into trusted websites to be executed by other users?
  • PCI DSS applies to which entities?
  • Is the merchant not responsible for the results of a scanned host if the merchant marks it out of scope?
  • The lockout duration is a minimum of 2 hours.
  • SSL/early TLS is not considered strong cryptography and may not be used as a security control, except by POS POI terminals verified as not susceptible to known exploits.
  • During a self-assessment, ASVs should assist with all of the following EXCEPT:
  • Which SAQ would apply to a merchant using end-to-end encryption with PCI PTS POI devices and IP network communication?
  • Which statement describes the DMZ’s purpose to limit inbound traffic to authorized publicly accessible services, protocols, and ports?
  • Which of the following is a Special Note defined by the Program Guide when detected?
  • Which section contains the vulnerability details and CVSS scores by IP?
  • Which SAQ would you select for a merchant using a validated P2PE solution?
  • After significant change, who should perform scans and rescans?
  • What must be kept up to date to maintain security effectiveness?
  • Internal vulnerability scans should be performed how often?
  • Which SAQ type applies to a service provider using only web-based virtual terminals?
  • Impact section of the CVSS is made up of which items?
  • Which statement implements a DMZ to limit inbound traffic to only system components that provide authorized publicly accessible services, protocols, and ports?
  • Which statement describes the relationship between PA-DSS and PCI DSS?
  • How should CVSS scores be used to determine whether a vulnerability is failing?
  • The Executive Summary includes a consolidated solution/correction plan provided as a separate line item for each IP address.
  • Who maintains the CVSS scoring system?
  • Merchants may be able to reduce PCI DSS scope when using Council-listed P2PE solutions. Which statement describes the merchant's access to account data in this scenario?
  • What action regarding private IP addresses should you take?
  • Which of the following is a type of injection flaw mentioned?
  • During PA-DSS assessment, assessor must validate installation per which guide?
  • Entities with existing SSL/early TLS implementations must have what in place?
  • Which PCI DSS compliance program is associated with Visa Inc?
  • PA-DSS applications are in scope for PCI DSS?
  • Which of the following is a PCI DSS role?
  • In CVSS, the Environmental modifiers include Confidentiality Requirement, Integrity Requirement, and Availability Requirement.
  • Which PCI standard covers security of environments that store, process or transmit account data?
  • Which statement limits inbound Internet traffic to IP addresses within the DMZ?
  • Which of the following statements best describes the use of 'early TLS'?
  • Which statement describes requirements for a firewall at each Internet connection and between any DMZ and the internal network?
  • Idle session re-authentication threshold is required after how many minutes of inactivity?
  • Which PCI DSS compliance program is associated with Visa Europe?
  • Who manages the decryption environment and all decrypted account data in PCI P2PE solutions?
  • The ASV Program Guide includes guidance on which topics?
  • Which statement best describes the difference between best-practice and compliance?
  • Which of the following is a PCI DSS role that correctly matches 'QSA'?
  • What term is key when discussing SSL/TLS suitability for PCI scanning?
  • It is compulsory to submit scan report results according to each payment brand's compliance reporting requirements.
  • Insecure cryptographic storage is best described as?
  • Which of the following is NOT a characteristic of ASV Scans?
  • Which authentication methods are acceptable to authenticate all users across system components?
  • Which SAQ should a merchant use if they rely on a PCI DSS compliant service provider's hosted payment page and do not store cardholder data?
  • Which PCI DSS compliance program is associated with Mastercard?
  • A formal Risk Mitigation and Migration Plan is required for SSL/early TLS connections.
  • DESV stands for what?
  • Annual secure coding training should include which element?
  • Which of the following is NOT considered an injection flaw?
  • Which frequency is required for external vulnerability scans?
  • When should internal and external vulnerability scans be performed per 11.2.2?
  • The note indicates that vulnerability assessments for public-facing web applications are not the same as vulnerability scans performed for Requirement 11.2. Which statement best describes this distinction?
  • What does DSOP stand for in PCI DSS context?
  • Which standard covers secure management, processing and transmission of PIN data during online and offline payment card transaction processing?
  • Exploitation section of the CVSS is made up of which of the following?
  • A component in the ASV Scan Report can be identified by which of the following?
  • The statement 'Open Access to Databases from the Internet is considered an automatic failure' is true.
  • Which statement describes firewall requirements for restricting connections between untrusted networks and the cardholder data environment?
  • Which Appendix addresses the additional PCI DSS requirements for entities using SSL/early TLS?
  • Which entity will ultimately approve a card purchase?
  • Security training frequency should be:
  • Which entity is responsible for forensic investigations of account data compromise?
  • MO/TO merchant with all payment functions outsourced to a compliant provider should use which SAQ?
  • In wireless environments connected to the cardholder data environment, what must be changed at installation?
  • What should you do with services, protocols, daemons, etc., on a system?
  • How often should internal and external vulnerability scans be performed, and when else?
  • Which vulnerability would automatically fail due to DNS misconfiguration, such as DNS zone transfer issues?
  • Which of the following is NOT considered a service provider?
  • The Attestation of Scan Compliance section includes the signature of the ASV qualified employee.
  • Which statement about PA-DSS applications is true?
  • What is the primary purpose of intrusion-detection and intrusion-prevention systems in PCI DSS guidance?
  • What is the primary goal of monitoring and alerting in the cardholder data environment?
  • What is the primary purpose of applying vendor-supplied security patches?
  • All service providers with existing connection points to POS POI terminals that use SSL and/or early TLS must have a formal Risk Mitigation and Migration Plan in place.
  • Which PCI DSS program is associated with Cardholder Information Security Program?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy