Question 1
From what source should time settings be obtained for security event logging?
Correct Answer:
Industry-accepted time sources
Explanation:
Time stamps in security event logs must line up across all systems so you can accurately trace what happened and when. The reliable way to achieve that is to obtain time settings from industry-accepted time sources—typically through network time protocol (NTP) servers that are synchronized to UTC from trusted reference clocks (like GPS or radio time). This provides a single, authoritative time reference that all devices can use, so every log entry shares a common baseline. Relying on a local server clock invites drift, and clocks on different devices drift at different rates, causing mismatched timestamps that break event correlation. Manually inputting time is slow, error-prone, and not scalable—any lapse in updating times across devices can create gaps or misalignment in logs. Satellite time signals can feed a time service, but the robust approach is to rely on centralized, industry-accepted time sources that your network devices consistently query, ensuring accuracy and redundancy across the logging infrastructure.
Question 2
12.3.7 requires?
Correct Answer:
List of company-approved products
Explanation:
The essential idea here is about controlling what technologies are allowed to be used in the PCI environment. Having a list of company-approved products creates a formal, auditable catalog of hardware and software that have been evaluated and authorized for use. This catalog helps ensure that only vetted, properly configured items are deployed, making it easier to enforce security standards, track changes, and demonstrate compliance during audits. Why this fits best: a defined approved-products list serves as the concrete artifact that organizations can rely on to enforce governance, reduce the risk of introducing untested or insecure components, and simplify ongoing management like patching and configuration verification. It establishes a baseline for what is permitted and provides a clear reference for both IT and security teams. Why the other ideas aren’t as fitting: describing acceptable uses of the technology focuses on user or operational behavior rather than the actual inventory of permitted technologies. A method to determine owner emphasizes ownership responsibility, which is important but does not specify the catalog that enforces what’s allowed in the environment. Explicit approval by authorized parties speaks to who signs off on changes, but the requirement is best satisfied by having a tangible list of approved products as the enforceable artifact.
Question 3
Penetration testing must review threats and vulnerabilities experienced in the last 12 months.
Correct Answer:
Last 12 Months
Explanation:
Penetration testing needs to reflect the current threat landscape and the vulnerabilities that could realistically affect the environment. Reviewing threats and vulnerabilities experienced in the last 12 months keeps the test aligned with recent attacker techniques, newly disclosed CVEs, and changes in the environment, so the scenarios and exploited weaknesses are relevant to today’s risk level. Choosing a window like last quarter would miss many recent developments, while a window of several years includes outdated issues that may no longer be actionable or present. A window of the last 12 months strikes the right balance, ensuring the test evaluates controls against recent and realistic risks.
Question 4
Under 6.5.1, which types of injection flaws are considered?
Correct Answer:
Injection flaws, particularly SQL injection; also consider OS Command Injection, LDAP and XPath injection flaws as well as other injection flaws
Explanation:
The main idea here is that 6.5.1 addresses injection flaws in code and applications. Injection flaws happen when untrusted input is fed into an interpreter as part of a command or query, allowing attackers to alter performance or behavior. SQL injection is the most well-known example, but the scope also includes other types like OS Command Injection, LDAP injection, XPath injection, and similar injection methods. So the best answer recognizes injection flaws in general and lists SQL injection while also calling out other injection types, matching the standard’s broad focus. The other options miss this breadth: cross-site scripting is a different vulnerability class, buffer overflow isn’t about injecting into interpreters, and authentication isn’t related to injection flaws.
Question 5
In which scenario is background screening considered a recommendation rather than a requirement?
Correct Answer:
A recommendation only.
Explanation:
The key idea here is the level of obligation a policy assigns. When background screening is described as a recommendation, it means the organization sees screening as a prudent, risk-reducing practice but does not make it mandatory for every position or scenario. This allows them to tailor decisions based on factors like how sensitive a role is, what data or systems the person can access, and regulatory context. That’s why the best choice is the one that states it as a recommendation only. The other scenarios imply a binding obligation or a strict schedule: making screening mandatory for all such positions, not requiring it at all, or requiring it on a fixed cadence like every six months. Each of those would constitute a requirement or a rigid process, not simply a recommended practice.
Question 1
Exam overview

About this Exam

Prepare with the PCI Data Security Standard Practice Test practice quiz. This question bank includes 10 questions covering considered, source, settings, data, and security. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

PCI Data Security Standard Practice Test

This practice set contains 10 questions from the matching question bank and focuses on considered, source, settings, data, and security. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions