ANSWERS A+ VERIFIED LATEST VERSION
=
1. Methods identified as being used to remove stolen data from the environ-
ments:: - Use of stolen credentials to access the POS environment
- Outdated patches or poor system patching processes
- The use of default or static vendor credentials / brute force
- POS skimming malware being installed on POS controllers
- POI physical skimming devices
2. 95% of breaches feature: The use of stolen credentials leveraging vendor remote access to hack into
customers POS environments.
3. Skimming: Copying payment card numbers either by tampering with:
- POS Devices
- ATMs
- Kiosks
Or by copying the card's magnetic stripe manually using handheld skimmers.
4. Phishing: Reconnaissance
- Information gathering from various online sources and social networking sites
- Business applications and software
Social Engineering
- Phishing emails or messages coming from a target's social network
- Phone call from an assumed known entity
Break-In
- Delivery through email
- Software vulnerabilities
5. Common methods for monetizing stolen card data:: - Skimmed full track data and
transaction information used to replicate a physical payment card, which can then be used for fraudulent transactions
in face-to-face environments, or ATM transactions
- Captured cardholder data is used where card-not-present transactions are accepted, such as e-commerce or
mail-order / telephone order (MO/TO) transactions
, PCI ISA FUNDAMENTALS EXAM QUESTIONS WITH CORRECT DETAILED
ANSWERS A+ VERIFIED LATEST VERSION
=
- Stolen cardholder data and sensitive authentication data are sold in bulk to other criminals who perform their own
fraud using the stolen data
6. Commonly targeted industries: - Retail - 45% of breaches
- Food and Beverage - 24% of breaches
- Hospitality - 9% of breaches
- Financial Services - 7% of breaches
- Nonprofit - 3%
7. PCI SSC founding payment brands include:: - American Express
- Discover Financial
- JCB International
- MasterCard
- Visa, Inc.
8. PCI DSS:: Covers security of the environments that store, process, or transmit account data
- Environments receive account data from payment applications and other sources (e.g., acquirers)
9. PCI PA-DSS: Covers secure payment applications to support PCI DSS compliance
Payment application receives account data from PIN-entry devices (PEDs) or other devices and begins payment
transaction
10. PCI P2PE: Covers encryption, decryption, and key management requirements for point-to-point encryption
solutions
11. PCI PTS - POI: Covers the protection of sensitive data at point-of-interaction devices and their secure
components, including cardholder PINs and account data, and the cryptographic keys used in connection with the
protection of that cardholder data
12. PCI PTS - PIN Security: Covers secure management, processing and transmission of personal identi-
ficationnumber (PIN) data during online and offline payment card transaction processing
13. PCI PTS - HSM: Covers physical, logical and device security requirements for securing Hardware Security
Modules (HSM)
14. PCI Card Production: Covers physical and logical security requirements for systems and business
processes
15. PA-DSS applies to third party payment applications if?: An application performs
authorization and/or settlement (POS, shopping carts, etc.)
, PCI ISA FUNDAMENTALS EXAM QUESTIONS WITH CORRECT DETAILED
ANSWERS A+ VERIFIED LATEST VERSION
=
16. PA-DSS ensures a payment application can function in a PCI DSS compliant
manner: - To support the PCI DSS compliance of those that use the application
- Use of a PA-DSS application alone does not guarantee PCI DSS compliance
17. Are PA-DSS applications in scope for PCI DSS?: Yes
18. PA DSS assessor must validate that payment application is installed:: - Per
instructions in the PA-DSS Implementation Guide provided by payment application vendor
- In a PCI DSS compliant manner
19. A PCI P2PE solution must include all of the following:: - Secure encryption of payment
card data at the point-of-interaction (POI)
- Validated application(s) at the point-of-interaction
- Secure management of encryption and decryption devices
- Management of the decryption environment and all decrypted account data
- Use of secure encryption methodologies and cryptographic key operations, including key generation, distribution,
loading/injection, administration and usage
20. Merchants may be able to reduce their PCI DSS scope when using Coun-
cil-listed P2PE solutions: - Merchant has no access to account data within encryption device (POI) or
decryption environment (at Solution Provider)
- Merchant has no involvement in encryption or decryption operations, or cryptographic key management
- All cryptographic operations managed by third party Solution Provider
21. PTS requirements apply to:: Point of Interaction (POI) devices; Encrypting PIN Pads (EPP); Point
of Sale devices (POS); Hardware (or host) Security Modules (HSMs); Unattended Payment Terminals, (UPTs) and
non-PIN Entry module
22. The PTS program ensures: Terminals cannot be manipulated or attacked to allow the capture of
Sensitive Authentication data, nor allow access to clear-text PINs or Keys
23. The Secure Read and Exchange Module, (SRED): Allows terminals to be approved for the
secure encryption of cardholder data as part of the Point to Point Encryption program
24. PTS has been extended to allow: Non-PIN entry modules to be evaluated against the SRED
module to allow secure encryption at the point of interaction for non-chip and PIN cards
25. PCI PIN Security Requirements: These requirements provide for secure PIN:
- management
, PCI ISA FUNDAMENTALS EXAM QUESTIONS WITH CORRECT DETAILED
ANSWERS A+ VERIFIED LATEST VERSION
=
- processing
- transmission
Protection of personal identification number (PIN) data during online and offline payment card transaction processing
at:
- ATMs
- attended point-of-sale (POS) terminals
- unattended point-of-sale (POS) terminals
The requirements also provide guidance on key management and key handling associated with the PIN
26. PCI PTS - POI and PCI DSS: - PCI DSS requires that account data be protected both when stored and
when transmitted across open, public networks
- PCI PTS POI validates how POIs protect PIN and account data and manage cryptographic keys
- PCI PTS POI-approved devices may form part of a PCI DSS-compliant environment
27. PCI PTS - PIN Security Standard and PCI DSS: - PCI DSS prohibits storage of encrypted PIN
blocks
- No overlap
28. PCI Card Production and PCI DSS: - No overlap
- Procedures for assessing card production facilities are defined and managed by the payment brands, not by PCI
SSC
29. PCI PTS - HSM and PCI DSS: - PCI DSS requires that stored cardholder data be protected and
cryptographic keys be managed in a secure manner
- Use of a Hardware Security Module is not required by PCI DSS, but may help with handling and managing keys
used to protect stored cardholder data
30. Payment Industry Terminology: Cardholder
- Customer purchasing goods either as a "Card Present" or "Card Not Present" transaction
- Receives the payment card and bills from the issuer
Issuer
- Bank or other organization issuing a payment card on behalf of a Payment Brand (e.g. MasterCard & Visa)
- Payment Brand issuing a payment card directly (e.g. Amex, Discover, JCB)
Merchant
- Organization accepting the payment card for payment during a purchase