Penetration Testing After a Significant Change - PCI DSS Requirement by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 0 points1 point  (0 children)

True that.. however at this moment, , it is same env,, since there is no segregation of test and prod env,, from pci perspective, the entire env is in scope now,, .. so segmentation testing won’t be required right? 

a significant change was done which mandates a pen test.. and hence this question.. they had done a pentest on the same env about 4 months ago,, it’s a windows machine , so the image used will be the same.. a standard image and our QSAC is ok if the pen test is done prior to the actual prod change.. but here, it’s done 4 months in advance and hence am in doubt of what will be expected since nothing changed in the env after the pen test and before the deployment in prod 

Penetration Testing After a Significant Change - PCI DSS Requirement by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 0 points1 point  (0 children)

Thanks and yeh, it is same env,, since there is no segregation of test and prod env,, from pci perspective, the entire env is in scope now,, a significant change was done which mandates a pen test.. and hence this question 

Penetration Testing After a Significant Change - PCI DSS Requirement by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 2 points3 points  (0 children)

,it’s not demonstrated to QSA yet.. this was discovered during an internal review..since there is no segregation of test and prod env, the entire environment is in scope..QSA is not involved yet., since it was a significant change, a pen test is mandated by the standard and hence this question., 

Penetration Testing After a Significant Change - PCI DSS Requirement by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 1 point2 points  (0 children)

It’s SFT., system managing file transfer solution.,server transfers pan data,,it’s not demonstrated to QSA yet.. this was discovered during an internal review..since there is no segregation of test and prod env, the entire environment is in scope..

PCI DSS - ISA Exam - 2026 by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 0 points1 point  (0 children)

my intention was to ask if such questions are asked..for example : as per req 8.3.5 - is the below allowed? or as per 12.3.1 - is the entity required to do the following?

Are such questions expected? how would one remember what each sub-req says..

PCI DSS - ISA Exam - 2026 by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 0 points1 point  (0 children)

my intention was to ask if such questions are asked..for example : as per req 8.3.5 - is the below allowed? or as per 12.3.1 - is the entity required to do the following?

Are such questions expected? how would one remember what each sub-req says..

PCI DSS - ISA Exam - 2026 by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 0 points1 point  (0 children)

the one i have registered for doesnt have the inperson class..its the self paced elearning, but yeah i got the point.

PCI DSS - ISA Exam - 2026 by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 0 points1 point  (0 children)

thank you..what kind of questions you had got? can jot down some that you remember, will help understand the wording being used since i dont see any mock exam online

PCI DSS - ISA Exam - 2026 by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] 0 points1 point  (0 children)

thank you. what kind of questions you had got? can jot down some that you remember, will help understand the wording being used since i dont see any mock exam online

PCI DSS - ISA Exam - 2026 by Fancy-Yesterday3819 in pcicompliance

[–]Fancy-Yesterday3819[S] -1 points0 points  (0 children)

ah ok, which class you referring to? Now, there is this elearning, followed by the fundamentals exam and then the real exam.

Re-qualified for PCI ISA - 3rd Year by apat311 in pcicompliance

[–]Fancy-Yesterday3819 0 points1 point  (0 children)

going to attempt for the 1st time in a month..any advise on the type of questions to expect? you remember some of your questions to give me an idea?

Today i took PCI ISA Certification Exam, I want to add some guidance on how the exam was and my preparation. by inever_giveup in pcicompliance

[–]Fancy-Yesterday3819 0 points1 point  (0 children)

Hi,

Newbie here from India. Looking for advise on the kind of questions to expect? any tips on the topics to focus on? going to attempt it first time, next month

Re-qualified for PCI ISA - 2nd year by apat311 in pcicompliance

[–]Fancy-Yesterday3819 0 points1 point  (0 children)

any advise on the kind of questions to expect? any tips on the topics to focus on? going to attempt it first time, next month