PCI SSC Assessor_New_V4 試験概要:
| 認定ベンダー: | PCI Security Standards Council |
|---|---|
| 試験名: | PCI Qualified Security Assessor V4 試験 (QSA_New_V4) |
| 試験番号: | QSA_New_V4 |
| 関連資格: | Qualified Security Assessor (QSA) 認定 PCI DSS Fundamentals |
| 対応言語: | English |
| 出題数: | 約40-70問(実施セッションにより異なる) |
| 試験形式: | シナリオベース問題, 多肢選択式, アセスメント意思決定 |
| 試験時間: | 300-360 |
| 推奨トレーニング: | PCI DSS Fundamentalsトレーニング PCI SSCトレーニングプログラム |
| 受験申し込み: | PCI SSC QSAプログラム登録 |
| サンプル問題: | PCI SSC Assessor_New_V4 サンプル問題 |
| 受験方法: | インストラクター主導のトレーニング(対面またはバーチャル)と、PCI Security Standards Councilが実施する最終資格試験 |
| 前提条件: | PCI SSC認定のQualified Security Assessor (QSA) 企業に雇用されている必要があり、通常はセキュリティ/監査の資格(CISSP、CISA、CISMなど)を保有していること。 |
| 公式シラバスのURL: | https://www.pcisecuritystandards.org/program_training_and_qualification/qsa_certification/ |
PCI SSC Assessor_New_V4 試験シラバストピック:
| セクション | 目標 |
|---|---|
| レポートとドキュメント作成 | - 準拠報告書 (ROC)
|
| 高度なアセスメントトピック | - カスタマイズされたアプローチ (PCI DSS v4.0)
|
| アセスメント手法 | - PCI DSSテスト手順
|
| PCI DSSの基礎 | - クレジットカード業界の概要
|
PCI SSC Assessor_New_V4 認定 Assessor_New_V4 試験問題:
問題 #1
Which of the following is true regarding internal vulnerability scans?
A. They must be performed by QSA personnel
B. They must be performed after a significant change
C. They must be performed at least annually
D. They must be performed by an Approved Scanning Vendor (ASV)
問題 #2
Which scenario meets PCI DSS requirements for critical systems to have correct and consistent time?
A. Access to time configuration settings is available to all users of the system.
B. Central time servers receive time signals from specific, approved external sources
C. Each internal system is configured to be its own time server.
D. Each internal system peers directory with an external source to ensure accuracy of time updates
問題 #3
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?
A. Application IDs for database applications can only be used by database administrators
B. Direct queries to the database are restricted to shared database administrator accounts
C. User access to the database is only through programmatic methods
D. User access to the database is restricted to system and network administrators
問題 #4
What must the assessor verify when testing that PAN is protected whenever it is sent over the Internet?
A. The PAN is encrypted with strong cryptography
B. The security protocol is configured to accept all digital certificates
C. The PAN is securely deleted once the transmission has been sent
D. The security protocol is configured to support earlier versions
問題 #5
Which of the following parties is responsible for completion of the Controls Matrix for the Customized Approach?
A. Only a Qualified Security Assessor (QSA)
B. Card brands or acquirer
C. Entity being assessed
D. Either a QSA, AQSA, or PClP.
解説:
| 問題 #1 正解: B | 問題 #2 正解: B | 問題 #3 正解: C | 問題 #4 正解: A | 問題 #5 正解: C |














920 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
