▸case-08 To streamline customer refund processing and chargeback investigations, our database team wants to store full magstripe track data and CVV/CVC codes in an encrypted database table post-authorization. Is this post-authorization storage compliant with PCI DSS Requirement 3? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 Our executive committee wants a list of mandatory compliance artifacts required for final PCI DSS assessment evidence. Aside from the scope documentation and scan reports, what formal document serves as the official proof of compliance declaration? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 To comply with PCI DSS Requirement 2 for secure system configurations across our CDE Linux and Windows servers, what industry-standard configuration benchmarks are recommended for system hardening? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 For our internal vulnerability management program under PCI DSS 4.0, our team plans to run quarterly unauthenticated network port scans across all internal servers to minimize credential management risk. Does this unauthenticated approach satisfy requirement 11.3.1.1? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 To combat e-commerce web skimming and Magecart attacks, PCI DSS 4.0 introduced Requirement 6.4.3 for payment pages. What technical control and inventory process must be implemented for JavaScript running in customer browser payment pages? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 Our operations team conducts internal vulnerability scans monthly. How frequently must external vulnerability scans be performed by an Approved Scanning Vendor (ASV) to meet PCI DSS Requirement 11? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 Our retail stores deploy PCI P2PE (Point-to-Point Encryption) validated hardware payment terminals connected to our store IP network. A vendor suggests that because the terminals connect via Ethernet, our internal store network switches and POS software must undergo full PCI DSS CDE assessment and quarterly ASV scans. Is full CDE scoping required for internal store network switches when using a validated P2PE solution? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 As part of our security architecture modernization, we need to implement updated payment card security controls across our infrastructure, particularly around access management, monitoring, and data defense. Please create a structured deployment plan detailing necessary technical safeguards, continuous monitoring mechanisms, and frequent implementation mistakes we must avoid. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 When transmitting payment card data across public networks, our gateway supports TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3 to maintain legacy browser compatibility. Which minimum TLS protocol version must be enforced for PCI DSS Requirement 4? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 When setting up remote and internal access controls for PCI DSS 4.0 compliance, our IT team suggested enforcing MFA only for system administrators with root/admin access to save on licensing costs. Is this restricted MFA scope permissible under requirement 8.4.2? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 Our cloud engineering team frequently releases major architectural changes to our CDE network and payment microservices. Under PCI DSS Requirement 11.4, when must penetration testing be performed beyond the standard annual schedule? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 Our customer payment web app processes card transactions online. To meet PCI DSS Requirement 6.4.1 for public-facing web applications, should we rely solely on periodic manual code reviews or deploy an active technical protection control? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 We are building an e-commerce website where payment card fields are rendered directly inside an inline frame (iframe) hosted by our payment processor. Our developer suggests that because the iframe is embedded on our web page, our web server handles cardholder data and must complete the full SAQ D questionnaire. How should our compliance scope be categorized? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 Our engineering team needs to bring our online payment processing platform into full alignment with the latest PCI DSS 4.0 standards. Please build a comprehensive multi-phase implementation roadmap that outlines the execution sequence, key security activities at each stage, and realistic timeframes from initial environment scoping all the way to final audit attestation. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 Our database architecture stores truncated card numbers displaying only the BIN (first 6 digits) and last 4 digits for customer transaction history lookup. No full PAN or sensitive authentication data is ever stored anywhere in our database. Our auditor asks if storing these masked card numbers requires applying full PCI DSS Requirement 3 cryptographic key management controls to this database. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 For audit log review compliance under PCI DSS 4.0, our security operations team plans to have SOC analysts manually sample log files from primary servers once a week. Does manual sampling meet requirement 10.4.1.1? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 Under PCI DSS 4.0 Requirement 8.3.9, our security team is evaluating whether user passwords must still be forced to change every 90 days across all systems. Does PCI DSS 4.0 still require mandatory 90-day password changes for user accounts? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 We are updating our anti-malware and email defenses for PCI DSS 4.0. Our compliance officer asks if employee security awareness emails are sufficient to satisfy requirement 5.4.1 without technical phishing detection mechanisms. What technical control must be deployed? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 Our identity management team is updating password policies for PCI DSS 4.0 compliance for accounts that use passwords without MFA. What minimum password length does PCI DSS 4.0 mandate under Requirement 8.3.6? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 Our architecture team wants to implement an alternative security control that does not strictly match the defined PCI DSS requirement text, but achieves the same security objective. What PCI DSS 4.0 validation framework permits custom control designs based on objective-based validation? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 We are tracking regulatory transition timelines for PCI DSS 4.0. While PCI DSS 3.2.1 retired in April 2024, by what exact date do the 51 new future-dated PCI DSS 4.0 requirements become mandatory for all entities? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 To satisfy file change detection requirements under PCI DSS Requirement 11, what specific continuous security software mechanism must be deployed on critical CDE system files to alert on unauthorized modifications? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |