PCI SSC QSA_New_V4 試験概要:
| 認定ベンダー: | PCI SSC |
| 試験名: | Qualified Security Assessor V4 Exam |
| 試験番号: | QSA_New_V4 |
| 受験料: | $3,600 USD |
| 認定の有効期間: | 12か月 |
| 対応言語: | 英語 |
| 試験時間: | 90 minutes |
| 合格点: | 75% |
| 出題数: | 60 |
| 試験形式: | 多肢選択式 |
| 関連資格: | Qualified Security Assessor (QSA) Internal Security Assessor (ISA) |
| サンプル問題: | PCI SSC QSA_New_V4 サンプル問題 |
| 受験方法: | 対面(Instructor-Led Training)または eLearning(Pearson VUE 経由で提供) |
| 前提条件: | 認定済み QSA Company の正社員であること。前提資格(例:CISSP、CISA、CISM、または IRCA ISMS Auditor)を保有していること。アプリケーションセキュリティ、情報システムセキュリティ、ネットワークセキュリティ、IT セキュリティ監査、ならびに情報セキュリティのリスク評価/管理において、最低 1 年の経験が必要です。PCI Fundamentals の前提コースを修了していること。 |
| 公式シラバスのURL: | https://www.pcisecuritystandards.org/program_training_and_qualification/qsa_certification |
PCI SSC QSA_New_V4 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|
| トピック 1 | - Real-World Case Studies: This section of the exam measures the skills of Cybersecurity Consultants and involves analyzing real-world breaches, compliance failures, and best practices in PCI DSS implementation. Candidates must review case studies to understand practical applications of security standards and identify lessons learned. One key skill evaluated is applying PCI DSS principles to prevent security breaches.
|
| トピック 2 | - Payment Brand Specific Requirements: This section of the exam measures the skills of Payment Security Specialists and focuses on the unique security and compliance requirements set by different payment brands, such as Visa, Mastercard, and American Express. Candidates must be familiar with the specific mandates and expectations of each brand when handling cardholder data. One skill assessed is identifying brand-specific compliance variations.
|
| トピック 3 | - PCI Validation Requirements: This section of the exam measures the skills of Compliance Analysts and evaluates the processes involved in validating PCI DSS compliance. Candidates must understand the different levels of merchant and service provider validation, including self-assessment questionnaires and external audits. One essential skill tested is determining the appropriate validation method based on business type.
|
| トピック 4 | - PCI DSS Testing Procedures: This section of the exam measures the skills of PCI Compliance Auditors and covers the testing procedures required to assess compliance with the Payment Card Industry Data Security Standard (PCI DSS). Candidates must understand how to evaluate security controls, identify vulnerabilities, and ensure that organizations meet compliance requirements. One key skill evaluated is assessing security measures against PCI DSS standards.
|
| トピック 5 | - PCI Reporting Requirements: This section of the exam measures the skills of Risk Management Professionals and covers the reporting obligations associated with PCI DSS compliance. Candidates must be able to prepare and submit necessary documentation, such as Reports on Compliance (ROCs) and Self-Assessment Questionnaires (SAQs). One critical skill assessed is compiling and submitting accurate PCI compliance reports.
|
参照:https://www.pcisecuritystandards.org/wp-content/uploads/2022/05/PCI_QSA_Training_Course_Description.pdf