1. If your company makes software to accept credit card payments, what standard would you use to measure and audit your software security?
2. Which three PCI requirements are most relevant to the System/Application Domain?
3. Your production system is regularly backed up and some of the data is used for testing and developing a new application interface. Is this in compliance with PCI DSS?
4. What are some options, according to PCI DSS, to protect external-facing Web applications from known attacks?
5. To perform a PCI DSS compliance audit on your e-commerce Web site, what should you incorporate into Requirement #6, "Develop and Maintain Secure Systems & Applications"?
6. What do you recommend this organization implement for privacy data storage in long-term data storage devices?
7. To perform a PCI DSS compliance audit, what elements must be in your audit checklist that pertain to the System/Application Domain?
8. As per the SAQ-D and Attestation of Compliance, what are the four major elements a merchant must achieve as part of PCI DSS compliance?
9. Which requirements in PCI DSS SAQ-D apply to vulnerability assessment and vulnerability management for production credit card transaction-processing servers?
10. Which requirements in PCI DSS SAQ-D apply to performing file integrity monitoring on critical cardholder servers?