Certified Payment Industry Security Implementer Exam Prep
Free practice questions

Free CPISI Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The CPISI exam has 50 questions and runs 1 hours.

These 10 free CPISI questions are organized by exam domain, so you can see how each part of the Certified Payment Industry Security Implementer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Background of Payment Security

Question 1

During a cloud-provider review, the merchant verifies that the provider's current Attestation of Compliance covers the infrastructure service it uses. The responsibility matrix assigns operating-system patching and application-log review to the merchant. The infrastructure team proposes closing those two controls using the provider's attestation. What evidence is still needed?

Show answer & explanation

Correct answer: A - Records showing that the merchant performs the patching and log reviews assigned to it.

Domain 2: Building and Maintaining a Secure Network and Systems

Question 2

The proposed PCI DSS scope excludes a software-deployment server on the corporate network. It never handles account data, but its service account can replace the application running on payment servers in the cardholder data environment (CDE). Those payment servers reject all other corporate-network connections. How should the deployment server be classified?

Show answer & explanation

Correct answer: D - In scope, because its deployment privileges can affect the security of the CDE.

Question 3

Only one Internet-bound flow is approved for payment server PAY-01: TCP port 443 to two specified processor IP addresses. Their hosting subnet also contains unrelated hosts. Name resolution and time synchronization use internal services. The firewall is stateful and already permits return traffic for authorized connections. Select the egress policy that preserves this flow without granting unnecessary access.

Show answer & explanation

Correct answer: A - Permit PAY-01 to the two processor addresses on TCP 443; deny other Internet-bound traffic.

Domain 3: Protecting Account Data

Question 4

At a subscription retailer, authorization completes when the processor returns an approval or decline. An encrypted retry queue nevertheless retains the card verification code until the settlement batch closes that evening. The retailer does not perform issuing services. Which redesign addresses the PCI DSS violation without abandoning recurring billing?

Show answer & explanation

Correct answer: B - Remove the verification code from persistent storage when authorization completes, rather than retaining it for settlement.

Question 5

A retailer has a documented business need to retain full primary account numbers (PANs). Its database sits on non-removable server disks protected by full-disk encryption. PANs have no additional unreadability protection, although support screens display only the last four digits. The design is being assessed against PCI DSS v4.0.1. What is the missing storage control?

Show answer & explanation

Correct answer: B - Render stored PAN unreadable through another permitted method, such as properly managed field-level encryption.

Domain 4: Maintaining a Vulnerability Management Program

Question 6

A remediation ticket records a CVSS v4.0 Base score of 8.2. The organization's documented risk assessment treats the vulnerability as noncritical and sets a 45-day patch deadline. The applicable patch was released 10 days ago, and installation is scheduled for day 35. There is no evidence of exploitation or a stricter applicable deadline. Under the PCI DSS v4.0.1 defined approach, which assessment is correct?

Show answer & explanation

Correct answer: C - The score is High; the planned installation meets the documented risk-based deadline for this noncritical finding.

Question 7

In an authorized test of a merchant's customer portal, a tester signs in normally and changes an invoice identifier in a request. The application returns another customer's invoice. The request contains no script or SQL syntax, and the response comes from the genuine application. Which diagnosis and repair fit this result?

Show answer & explanation

Correct answer: D - Broken object-level authorization; check the signed-in user's permission for each requested invoice.

Domain 5: Implementing a Strong Access Control Measures

Question 8

A reconciliation clerk uses an office workstation to access a CDE application containing multiple customers' payment records. The clerk is not an administrator. Entry requires a password followed by a separate memorized PIN; no other authentication occurs. The team proposes keeping this arrangement because the connection starts inside the corporate network. Which change supplies the missing authentication factor?

Show answer & explanation

Correct answer: A - Replace the PIN challenge with proof of possession of an individually assigned security token.

Question 9

Opening checks at a shop reveal an unfamiliar overlay on one payment terminal and a serial number that does not match the device inventory. No replacement was authorized. The supervisor has access to the incident-response contact and a separate, verified terminal. What should happen before another customer uses the suspect device?

Show answer & explanation

Correct answer: C - Take it out of service, preserve it as evidence, and activate the incident-response process.

Domain 6: Regularly Monitoring and Testing Networks

Question 10

Six weeks after a passing periodic external scan by an Approved Scanning Vendor (ASV), a merchant makes a significant change to its Internet-facing payment infrastructure. A separate external vulnerability scan is now required for the change. Which statement accurately describes the personnel requirement for this additional scan?

Show answer & explanation

Correct answer: C - Qualified internal testers are eligible when their organizational independence is established.

That's 10 of 1,030

The full bank has 1,020 more CPISI questions with explanations.

Continue in the free practice test →

View plans