Which statement about the Attestation of Compliance (AOC) is correct?
A.
There are different AOC templates for service providers and merchants.
B.
The AOC must be signed by both the merchant/service provider and by PCI SSC.
C.
The same AOC template is used W ROCs and SAQs.
D.
The AOC must be signed by either the merchant/service provider or the QSA/ISA.
The Answer Is:
A
This question includes an explanation.
Explanation:
Attestation of Compliance (AOC):
The AOC is a document that confirms an entity’s compliance with PCI DSS requirements. It is signed by the entity (merchant or service provider) and the Qualified Security Assessor (QSA) if a QSA is involved.
Different AOC Templates:
PCI DSS provides distinct templates for service providers and merchants, tailored to their respective roles and responsibilities within the cardholder data environment (CDE).
Invalid Options:
B:PCI SSC does not sign AOCs; they are signed by the merchant/service provider and the QSA.
C:AOCs differ between ROCs and SAQs, so the same template is not universally used.
D:Both the merchant/service provider and the QSA/ISA (Internal Security Assessor) must sign the AOC when applicable.
QSA_New_V4 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"