PCI SSC Assessor_New_V4 試験概要:
| 認定ベンダー: | PCI Security Standards Council (PCI SSC) |
| 試験名: | Assessor New V4 試験 |
| 試験番号: | Assessor_New_V4 |
| 関連資格: | PCI Qualified Security Assessor (QSA) |
| 対応言語: | 英語 |
| 出題数: | 40-62 |
| 試験形式: | 多肢選択式, シナリオベースの問題, アセスメントおよびコンプライアンス分析 |
| サンプル問題: | PCI SSC Assessor_New_V4 サンプル問題 |
| 受験方法: | 講師主導のトレーニングの後、監督下で試験を受けます。PCI SSC の資格プログラムを通じて受験可能です。 |
| 前提条件: | 通常は、PCI SSC 承認の QSA 企業に勤務するセキュリティ専門家を対象としています。QSA の資格取得ルートでは、PCI Fundamentals のトレーニングと、関連するセキュリティ認定資格(CISSP、CISA、CISM など)が一般的に必要です。 |
| 公式シラバスのURL: | https://www.pcisecuritystandards.org/program_training_and_qualification/qsa_certification/ |
PCI SSC Assessor_New_V4 試験シラバストピック:
| セクション | 目標 |
|---|---|
| コンプライアンスおよびセキュリティ運用 | - セキュリティ管理
|
| PCI DSSの要件とテスト手順 | - PCI DSS管理要件
|
| カスタマイズされたアプローチとリスク分析 | - カスタマイズされたコントロール
|
| PCIアセスメント手法 | - 証拠収集
|
| PCI報告要件 | - コンプライアンス報告書(ROC)
|
| ペイメントカード業界エコシステム | - 決済処理の基礎
|
PCI SSC Assessor_New_V4 認定 Assessor_New_V4 試験問題:
1. Which of the following is an example of multi-factor authentication?
A) A user fingerprint and a user thumbprint
B) A token that must be presented twice during the login process
C) A user passphrase and an application level password.
D) A user password and a PIN-activated smart card
2. Which statement about the Attestation of Compliance (AOC) is correct?
A) There are different AOC templates for service providers and merchants
B) The AOC must be signed by both the merchant/service provider and by PCI SSC
C) The AOC must be signed by either the merchant service provider or the QSA'ISA
D) The same AOC template is used for ROCs and SAQs
3. An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA. while also ensuing that the customized control is implemented securely. Which of the following statements is true?
A) Assessors are not allowed to assist an entity with the completion of the Controls Matrix or the TRA.
B) You must document the work on the customized control in the ROC but you can not assess the control or the documentation.
C) You can assess the customized control but another assessor must verify that you completed the TRA correctly.
D) You can assess the customized control and verify that the customized approach was correctly followed but you must document this in the ROC.
4. What must be included m an organization's procedures for managing visitors?
A) Visitors are escorted at all times within areas where cardholder data is processed or maintained
B) Visitor log includes visitor name, address, and contact phone number
C) Visitor badges are identical to badges used by onsite personnel
D) Visitors retain their identification (for example a visitor badge) for 30 days after completion of the visit
5. An entity accepts e-commerce payment card transactions and stores account data in a database The database server and the web server are both accessible from the Internet The database server and the web server are on separate physical servers. What is required for the entity to meet PCI DSS requirements7
A) The database server should be moved to a separate segment from the web server to allow for more concurrent connections
B) The web server and the database server should be installed on the same physical server
C) The database server should be relocated so that it is not accessible from untrusted networks
D) The web server should be moved into the internal network
質問と回答:
| 質問 # 1 正解: D | 質問 # 2 正解: D | 質問 # 3 正解: D | 質問 # 4 正解: A | 質問 # 5 正解: C |














1172 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
