PCI SSC Assessor_New_V4 시험 개요:
| 인증 벤더: | PCI Security Standards Council |
|---|---|
| 시험명: | PCI 자격 보안 심사원 V4 시험(QSA_New_V4) |
| 시험 번호: | QSA_New_V4 |
| 실제 시험 문항 수: | 약 40~70문항(실시 회차에 따라 상이함) |
| 시험 시간: | 300-360 |
| 시험 형식: | 객관식, 시나리오 기반 문항, 심사 판단 능력 평가 |
| 관련 자격증: | 자격 보안 심사원(QSA) 인증 PCI DSS Fundamentals |
| 지원 언어: | English |
| 권장 교육: | PCI SSC 교육 프로그램 PCI DSS Fundamentals 교육 과정 |
| 시험 등록: | PCI SSC QSA 프로그램 등록 |
| 샘플 문제: | PCI SSC Assessor_New_V4 샘플 문제 |
| 응시 방법: | PCI Security Standards Council에서 주관하는 강사 주도 교육(대면 또는 원격) 이수 후 최종 자격 심사 시험에 응시하는 방식입니다. |
| 전제 조건: | PCI SSC의 인가를 받은 자격 보안 심사원(QSA) 소속 기관에 재직 중이어야 하며, 일반적으로 CISSP, CISA, CISM 등 보안·심사 관련 인증을 보유해야 합니다. |
| 공식 요강 URL: | https://www.pcisecuritystandards.org/program_training_and_qualification/qsa_certification/ |
PCI SSC Assessor_New_V4 시험 요강 주제:
| 섹션 | 목표 |
|---|---|
| PCI DSS 기본 지식 | - PCI DSS 핵심 요건 개요
|
| 심사 방법론 | - PCI DSS 테스트 절차
|
| 심사 심화 주제 | - 맞춤형 접근 방식(PCI DSS v4.0)
|
| 보고 및 문서화 | - 규정 준수 보고서(ROC)
|
최신 PCI Qualified Professionals Assessor_New_V4 무료샘플문제
문제 #1
An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?
A. Certificates are logged so they can be retrieved when the employee leaves the company
B. A different certificate is assigned to each individual user account, and certificates are not shared
C. Change control processes are in place to ensue certificates are changed every 90 days
D. Certificates are assigned only to administrative groups and not to regular users
문제 #2
Assigning a unique ID to each person is intended to ensure?
A. Individual users are accountable for their own actions
B. Access is assigned to group accounts based on need-to-know
C. Strong passwords are used for each user account
D. Shared accounts are only used by administrators
문제 #3
If an entity shares cardholder data with a TPSP, what activity is the entity required to perform'?
A. The entity must test the TPSP's incident response plan at least quarterly
B. The entity must perform a risk assessment of the TPSP's environment at least quarterly.
C. The entity must monitor the TPSP's PCI DSS compliance status at least annually
D. The entity must conduct ASV scans on the TPSP's systems at least annually
문제 #4
At which step in the payment transaction process does the merchants bank pay the merchant for the purchase and the cardholder s bank bill the cardholder?
A. Chargeback
B. Settlement
C. Authorization
D. Clearing
문제 #5
An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity's PCI DSS assessment?
A. It automatically makes an entity PCI DSS compliant
B. There is no impact to the entity
C. It may help the entity to meet several requirements in Requirement 6.
D. The custom software can be excluded from the PCI DSS assessment
질문과 대답:
| 문제 #1 정답: B | 문제 #2 정답: A | 문제 #3 정답: C | 문제 #4 정답: B | 문제 #5 정답: C |














1184 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
