Courseiva
Security Assessment and TestingmediumMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

A company is preparing for an external audit to comply with PCI DSS. Which type of auditor is typically required to perform this assessment?

⚠ Common exam trap

Many exam-takers confuse 'external auditor' with any certified accountant or general IT auditor, overlooking that PCI DSS mandates a specifically certified QSA for compliance validation, not just any third-party assessor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Qualified Security Assessor (QSA)

PCI DSS requires assessments to be conducted by a Qualified Security Assessor (QSA) because QSAs are certified by the PCI Security Standards Council to validate compliance with the standard's technical and procedural controls. Unlike internal or general external auditors, QSAs have specific training in PCI DSS requirements, including network segmentation, encryption protocols (e.g., TLS 1.2+), and logging mechanisms (e.g., audit trails per Requirement 10).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • System administrator

    Why it's wrong here

    A system administrator is an internal operational role responsible for managing and maintaining an organization's IT infrastructure and systems. They inherently lack the required independence and specialized auditing qualifications necessary to perform an external PCI DSS compliance assessment. Their direct involvement in the system's day-to-day operations creates a significant conflict of interest, making them unsuitable for the objective, third-party audit mandated for official PCI DSS certification.

  • Internal auditor

    Why it's wrong here

    An internal auditor, while possessing valuable skills in assessing organizational controls and processes, operates within the company's reporting structure and is not considered an independent third party. Although they can conduct internal assessments to help prepare for compliance, PCI DSS specifically mandates that a formal Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ) validation for external certification must be performed by an independent, third-party Qualified Security Assessor (QSA). Their internal position inherently lacks the external objectivity required for official PCI DSS validation.

  • Certified Public Accountant (CPA)

    Why it's wrong here

    A Certified Public Accountant (CPA) is a professional expert in financial auditing, accounting principles, and financial reporting compliance. While their role involves assessing financial controls and accuracy, their specific training and certification do not encompass the technical and procedural requirements of information security standards like PCI DSS. PCI DSS compliance requires specialized knowledge of data security, network architecture, and cardholder data environments, which falls outside the typical scope of a CPA's professional expertise and certification.

  • Qualified Security Assessor (QSA)

    Why this is correct

    A Qualified Security Assessor (QSA) is an individual certified by the PCI Security Standards Council (PCI SSC) to conduct formal PCI DSS compliance assessments. QSAs possess specialized expertise in the technical and procedural requirements of the standard, ensuring an independent and objective evaluation of an entity's cardholder data environment. Their external validation is mandatory for organizations required to submit a Report on Compliance (ROC) or validate their Self-Assessment Questionnaire (SAQ) with a QSA attestation, providing the necessary assurance to payment brands.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.