Question 1
Which entity is described as the 'merchant bank' in payment card transactions?
Correct Answer:
Acquirer
Explanation:
In card payment terms, the “merchant bank” is the acquirer. The acquirer is the bank or financial institution that signs a contract with the merchant to enable card acceptance, maintains the merchant account, and handles the flow of funds from cardholders’ banks to the merchant. When a payment is made, the acquirer submits the transaction through the card networks to the issuer for authorization, and, once approved, settles the funds to the merchant’s account (minus the processor’s and network fees). The issuer is the cardholder’s bank that issued the card and funds come from that bank if the transaction is approved. The processor is the party that routes the payment data and manages communication between the acquirer, networks, and issuer. The cardholder is the consumer who holds the card.
Question 2
Which practice is commonly included to mitigate broken authentication and session management?
Correct Answer:
Flagging session tokens as secure
Explanation:
Protecting session tokens is essential to preventing session hijacking. Marking the session cookie as Secure ensures it is sent only over HTTPS, so the token isn’t exposed in plaintext on insecure connections. This reduces the risk of interception during transmission and helps keep authenticated sessions protected, especially when paired with HttpOnly (to block access from scripts) and SameSite (to mitigate cross-site request forgery). Exposing session IDs in the URL is risky because URLs can be logged in browser history, server logs, and referred by headers, making the token easily discoverable. Using a fixed, long‑lived session ID means a stolen token could be reused for a long time, increasing impact. Disabling timeouts leaves sessions open indefinitely, allowing ongoing use if a token is compromised. Marking the session token as Secure directly addresses the risk of token theft in transit and aligns with proper session management practices.
Question 3
Which statement describes a criterion for compensating controls?
Correct Answer:
They meet the intent and rigor of the original PCI DSS requirement
Explanation:
Compensating controls are allowed when you can’t meet a PCI DSS requirement as written, but they must deliver protection that is equivalent to the original requirement. The key test is that the compensating controls meet the intent and rigor of the original PCI DSS control, providing at least the same level of protection and being verifiable as such. That’s why stating that they meet the original requirement’s intent and rigor is the best description. It captures both the purpose (protecting cardholder data in the same way the original control would) and the standard for acceptance (they must be as strong as, or stronger than, the original control and demonstrably achieve its protective goals). Relying on existing PCI DSS requirements alone isn’t enough on its own to justify compensating controls, because they must specifically demonstrate equivalent protection to the original requirement. Cost differences don’t determine eligibility, since a compensating control can be more or less expensive and still be valid if it preserves the same level of risk mitigation. Finally, the idea that they don’t need to be above and beyond other PCI DSS requirements isn’t correct; the focus is on achieving equivalent protection, which may involve strengthening controls beyond the bare minimum in some areas to compensate for the gap.
Question 4
Magnetic-Stripe Data is also known as what?
Correct Answer:
Track Data
Explanation:
Magnetic-stripe data refers to the information stored on the card’s magnetic stripe, which is read as Track 1 and Track 2 data. In PCI DSS and common card-technology terminology, this data is called Track Data. That’s why the option “Track Data” is the best fit. The other terms aren’t standard. “Card Information” is too generic, “Magnetic Track” isn’t the common label used, and “Stripe Contents” isn’t the usual term for the data stored on the stripes.
Question 5
Which statement is NOT a criterion for compensating controls?
Correct Answer:
They do not need to be above and beyond other PCI DSS requirements
Explanation:
When you can’t meet a PCI DSS requirement, compensating controls are alternative measures that must achieve the same level of protection as the original control. They work by preserving the security goal of the requirement even though the exact control wasn’t feasible. They must reflect the intent and rigor of the original requirement, meaning they should address the same risk with an approach that matches how strong the original control would have been. They also have to provide a similar level of defense, not a weaker substitute, so the overall protection remains equivalent. Additionally, compensating controls should add protection beyond other PCI DSS requirements, rather than simply reusing existing controls. This extra strength is what makes them an acceptable substitute when the normal control can’t be implemented. Therefore, the statement claiming they do not need to be above and beyond other PCI DSS requirements is not a criterion for compensating controls.
Question 1
Exam overview

About this Exam

Prepare with the PCI DSS Requirements Practice Test practice quiz. This question bank includes 10 questions covering authentication, describes, criterion, compensating, and controls. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

PCI DSS Requirements Practice Test

This practice set contains 10 questions from the matching question bank and focuses on authentication, describes, criterion, compensating, and controls. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions