▸case-01 We are building an e-commerce checkout backend and want to store credit card Primary Account Numbers (PAN) in Postgres so customer service can assist with telephone re-orders. A developer suggested storing PANs using un-salted SHA-256 hashes so we can look them up quickly. Evaluate this proposed PAN storage mechanism against PCI DSS Requirement 3 standards and specify compliant storage options. | pass→pass | 17,846 | 28,953 | +62% | 1 | 1 | 0% | 2,980 | 4,391 | +47% | 0 | 0 | — |
▸case-02 Our payment processing service receives the 3-digit CVV/CVC security code during transaction authorization. To facilitate one-click recurring subscription renewals without asking the user for their card again, our architect proposed storing the CVV code encrypted with AES-256 in a secure Vault secrets store. Evaluate whether storing sensitive authentication data post-authorization is permitted under PCI DSS. | pass→pass | 13,119 | 17,246 | +31% | 1 | 1 | 0% | 2,173 | 2,451 | +13% | 0 | 0 | — |
▸case-03 Our payment gateway REST API currently supports TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3 to maintain backward compatibility with old IoT POS terminals. Recommend the minimum allowed TLS protocol version for protecting cardholder data during transmission over public networks according to PCI DSS Requirement 4. | pass→pass | 15,218 | 12,653 | -17% | 1 | 1 | 0% | 1,772 | 2,658 | +50% | 0 | 0 | — |
▸case-04 Our internal engineers connect to servers inside the Cardholder Data Environment via SSH from our corporate VPN. The VPN already uses multi-factor authentication. The team argues that MFA is not required for the SSH login into CDE servers because VPN login already satisfied MFA. Evaluate this setup against PCI DSS v4.0 Requirement 8. | pass→pass | 20,068 | 25,468 | +27% | 1 | 1 | 0% | 3,281 | 3,659 | +12% | 0 | 0 | — |
▸case-05 We are configuring local account password policies for linux hosts in our Cardholder Data Environment. The sysadmin wants to set the minimum password length to 8 characters with upper, lower, and special characters to match our standard corporate policy. Validate this minimum length setting against PCI DSS v4.0 Requirement 8.3.6. | pass→pass | 16,510 | 16,967 | +3% | 1 | 1 | 0% | 1,967 | 2,604 | +32% | 0 | 0 | — |
▸case-06 Our web application hosting the payment page runs automated internal vulnerability scans monthly. The DevOps lead asks if these internal scans satisfy PCI DSS Requirement 11.3.2 for external vulnerability scanning, or if an Approved Scanning Vendor (ASV) is required, and at what minimum frequency. | pass→pass | 16,904 | 15,819 | -6% | 1 | 1 | 0% | 2,028 | 2,327 | +15% | 0 | 0 | — |
▸case-07 We have segmented our payment network using VLANs and firewall rules. To verify that non-CDE systems cannot reach CDE systems, the network team conducted a static firewall rule review. Is a firewall configuration review alone sufficient to validate network segmentation under PCI DSS Requirement 11.4.5? | pass→pass | 12,707 | 14,566 | +15% | 1 | 1 | 0% | 2,198 | 2,637 | +20% | 0 | 0 | — |
▸case-08 During an audit of new database servers deployed in the CDE, we found PostgreSQL running with default superuser credentials on port 5432. The operations team created a firewall rule blocking external access to 5432 and argues that default credentials are fine as long as port 5432 is not exposed to the internet. Evaluate this position under PCI DSS Requirement 2. | pass→pass | 14,047 | 18,217 | +30% | 1 | 1 | 0% | 2,257 | 2,524 | +12% | 0 | 0 | — |
▸case-09 Our public-facing e-commerce web application processes credit card transactions. We perform manual security code reviews every 6 months. The developer believes this manual code review eliminates the need for an automated Web Application Firewall (WAF) under PCI DSS v4.0 Requirement 6.4.1. Evaluate this assertion. | fail→pass | 16,747 | 19,677 | +17% | 1 | 1 | 0% | 2,989 | 3,063 | +2% | 0 | 0 | — |
▸case-10 Our SIEM solution retains Cardholder Data Environment audit logs in active online storage for 30 days and discards them after 90 days to save S3 storage costs. Evaluate this log retention schedule against PCI DSS Requirement 10.5.1. | pass→pass | 16,284 | 12,894 | -21% | 1 | 1 | 0% | 2,030 | 2,713 | +34% | 0 | 0 | — |
▸case-11 In our Cardholder Data Environment, individual Linux nodes set their system clocks independently via local hardware real-time clocks without external network time synchronization to minimize network traffic. Evaluate whether un-synchronized system clocks satisfy PCI DSS Requirement 10.6. | pass→pass | 12,828 | 20,224 | +58% | 1 | 1 | 0% | 2,158 | 2,703 | +25% | 0 | 0 | — |
▸case-12 To simplify key management, our application developer stored both the AES-256 Data Encryption Keys used to encrypt PAN data and the Key Encryption Keys used to wrap the DEKs under the same IAM role permissions in AWS KMS. Evaluate this key separation model under PCI DSS Requirement 3.6. | pass→pass | 20,648 | 24,027 | +16% | 1 | 1 | 0% | 3,378 | 3,629 | +7% | 0 | 0 | — |
▸case-13 We monitor application deployment logs in CloudWatch to track changes to binary files in our payment processing application. The team claims this deployment log tracking satisfies PCI DSS Requirement 11.5.2 for change detection on critical system files. Evaluate whether deployment logging fulfills File Integrity Monitoring requirements. | pass→pass | 21,760 | 21,354 | -2% | 1 | 1 | 0% | 2,758 | 2,927 | +6% | 0 | 0 | — |
▸case-14 Our application underwent an external penetration test 18 months ago. Since no high-severity vulnerabilities were found, management decided to postpone the next penetration test until 36 months after the initial test. Validate this testing interval under PCI DSS Requirement 11.4. | pass→pass | 15,521 | 13,001 | -16% | 1 | 1 | 0% | 2,039 | 2,623 | +29% | 0 | 0 | — |
▸case-15 Our e-commerce checkout page loads third-party analytics scripts directly from external content delivery networks without Subresource Integrity hashes or script management controls. Evaluate this practice under PCI DSS v4.0 Requirement 6.4.3 regarding payment page scripts. | pass→pass | 17,921 | 26,092 | +46% | 1 | 1 | 0% | 2,862 | 3,952 | +38% | 0 | 0 | — |
▸case-16 An office location connected to the corporate network has a guest Wi-Fi router running WPA2-Personal. The network team states that because guest Wi-Fi is for visitors, it does not need quarterly rogue wireless access point detection or scanning. Evaluate this statement under PCI DSS Requirement 11.2. | pass→pass | 20,779 | 21,462 | +3% | 1 | 1 | 0% | 2,511 | 2,927 | +17% | 0 | 0 | — |
▸case-17 A merchant processes 50,000 credit card transactions per year purely through an iframe payment gateway hosted entirely by a PCI DSS Level 1 Service Provider. The merchant's web server never receives, processes, or transmits cardholder data. Determine which Self-Assessment Questionnaire type applies to this merchant model. | pass→pass | 14,349 | 15,030 | +5% | 1 | 1 | 0% | 1,567 | 2,002 | +28% | 0 | 0 | — |
▸case-18 An analyst exports database backup files containing credit card primary account numbers to an external USB hard drive for offsite disaster recovery storage without full-disk encryption, relying instead on physical lockboxes during transit. Assess this backup process against PCI DSS Requirement 3.4.1. | pass→pass | 19,026 | 12,905 | -32% | 1 | 1 | 0% | 2,270 | 2,445 | +8% | 0 | 0 | — |
▸case-19 Our CDE user authentication policy locks out user accounts after 15 consecutive failed login attempts and resets the lock after 1 minute. Evaluate these threshold parameters against PCI DSS v4.0 Requirement 8.3.7. | pass→pass | 13,525 | 13,026 | -4% | 1 | 1 | 0% | 1,555 | 1,826 | +17% | 0 | 0 | — |
▸case-20 We are preparing for a SOC 2 Type II audit covering Security and Confidentiality. Draft a control description for Trust Services Criteria CC6.1 regarding logical access security for our multi-tenant SaaS application hosted on AWS, including user provisioning and quarterly access reviews. | pass→pass | 20,714 | 23,212 | +12% | 1 | 1 | 0% | 2,430 | 4,292 | +77% | 0 | 0 | — |
▸case-21 A healthcare platform stores electronic Protected Health Information including patient diagnosis records in Amazon S3. Define the requirements under the HIPAA Security Rule 45 CFR section 164.312 for technical safeguards regarding ePHI encryption at rest and Business Associate Agreement execution. | pass→pass | 23,338 | 21,466 | -8% | 1 | 1 | 0% | 3,422 | 3,384 | -1% | 0 | 0 | — |
▸case-22 Our European Union organization transfers EU citizen personal data to a cloud provider located in the United States. Outline the compliance requirements under GDPR Article 46 for Standard Contractual Clauses and Transfer Impact Assessments. | pass→pass | 17,782 | 21,525 | +21% | 1 | 1 | 0% | 3,124 | 3,373 | +8% | 0 | 0 | — |