Question 11

All other merchants (not included in the descriptions for SAQs A, B, or C) and all service providers defined by a payment brand as eligible to complete an SAQ may be completing what SAQ?
  • Question 12

    What are best practices for implementing PCI DSS into Business-as-Usual (BAU) Processes? (Select
    ALL that apply)
  • Question 13

    Intrusion-detection and/or intrusion-prevention techniques are NOT a requirement to monitor all traffic at the perimeter of the cardholder data environment as well as at critical points in the CDE and alert personnel to suspected compromises.
  • Question 14

    When evaluating "above and beyond" for compensating controls, an existing PCI DSS requirement MAY be considered as compensating controls if they are required for another area, but are not required for the item under review
  • Question 15

    According to requirement 8.1.6 an user ID should be locked out after a maximum how many repeated access attempts?