Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, individual lessons, and BMC Cyber Challenge activities.

PCI Security Standards Council · Free, ad-free audio course

PCI QSA

A structured, audio-first learning route for PCI QSA, designed for focused review and practical understanding.

Every Bare Metal Cyber audio course is free and 100% ad-free.

PUT IT INTO PRACTICE

Practice PCI QSA concepts

Try 50 original BMC questions, review every explanation, and return to the lessons behind the answer. No login is required. Earn Challenge achievements and share your progress as you go.

50 original questionsExplanation after every answerAchievements and sharing

Independent BMC learning practice—not official exam items, a full mock exam, or an exam-readiness score.

Certification practice in the BMC Cyber Challenge

Companion Books

Study with the audio course, then reinforce it in print.

The study guide helps you organize and revisit the material. The flashcards book adds active recall and rapid review across the course objectives.

Complete Lesson Directory

Choose the exact subject you want to study.

Search by topic or narrow the directory by exam domain. Courses with multiple editions are organized below so every season remains easy to find. Each lesson includes its own audio player, full description, transcript when available, and previous-or-next navigation.

58 lessons available

S01E29Transcript

PCI DSS Technical and Operational Requirements

Test Security Regularly and Prove It Works

Listen to Test Security Regularly and Prove It Works in the PCI QSA audio course.

Transcript availableFebruary 23, 2026
S01E53Transcript

Shared Responsibility, Evidence and Quality Review

Meet the QSA QA Program With Confidence.

Listen to Meet the QSA QA Program With Confidence. in the PCI QSA audio course.

Transcript availableFebruary 23, 2026

A Practical Study Routine

Listen, read, and review in the order that works for you.

01

Listen

Use the free audio course during a commute, walk, workout, or focused study session.

02

Read

Use the study guide to organize the material, annotate key ideas, and build a reference you can return to.

03

Review

Use the flashcards book to practice active recall and quickly revisit weak areas.

Related Cyber Wiki

Continue with the concepts behind the course.

AI architecture

AI Shared-Responsibility Mapping

AI shared-responsibility mapping assigns control duties across model providers, cloud platforms, application teams, data owners, users, and oversight functions.

Privacy engineering technique

Anonymization and Pseudonymization

Anonymization aims to prevent data from being linked to an identifiable person, while pseudonymization replaces direct identifiers but retains a controlled path to re-link the data.

Service management

Approved Scanning Vendor Scans

Approved Scanning Vendor scans provide externally performed vulnerability scanning for applicable internet-facing systems under PCI scanning rules, with defined scope, evidence, dispute, remediation, and passing criteria.

Vulnerability reference

CVE, CWE, CVSS, and EPSS

CVE identifies publicly disclosed vulnerabilities, CWE describes classes of weakness, CVSS expresses technical severity, and EPSS estimates the probability of near-term exploitation.

Service management

Cardholder Data Environment

The cardholder data environment includes the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, together with connected or security-impacting components in scope.

Service management

Change Enablement Practice

Change enablement maximizes successful changes by assessing risk, authorizing work, coordinating schedules, preserving evidence, and learning from results without imposing unnecessary friction.