PCIP Study questions from PCI Training manual Questions with
Correct Answers (Grade A+)
Question 1: How is skimming used to target PCI data?
Answer: Copying payment card numbers by tampering with POS devices, ATMs, Kiosks or copying the
magnetic stripe using handheld skimmers.
Question 2: How is phishing used to target PCI data?
Answer: By doing reconnaissance work through social engineering and or breaking in using software
vulnerabilities or e-mails.
Question 3: How can Payment Data be Monetized?
Answer: By skimming the card to get the full track of data, and then making another like card. Using the
card information in a "Card-not-present transactions such as e-commerce or mail order, Telephone order.
Card data is also sold in bulk to other criminals who perform their own fraud using the stolen data.
Question 4: Who all are targeted ?
Answer: Retail, Food and Beaverage, Hospitality, Financial Services, non-profit. EVERYONE!
Question 5: What is the PCI SSC ?
Answer: Payment Card Industry Security Service Counsel is an independent industry standards body
providing oversight of the development and management of Payment Card Industry Data Security Standards
on a global basis.
Question 6: What are some of the PCI SSC founding payment brands.
Answer: American Express, Discover Financial, JCB International, Master Card, Visa inc.
Question 7: What are the Resources provided by the PCI SSC?
Answer: PCI DSS, PA-DSS, P2PE, PTS (POI, HSM and PIN) Card Production, and supporting documents.
Roster of QSAs, PA-QSAs, PCIPs, ASVs, validated payment applications, PTS Devices, and P2PE
solutions PCI Security Standards Counsil FAQs Education and Outreach programs Participating
Organization Membership, Community Meetings, feedback.
Question 8: What is the overview of PCI DSS?
Answer: Covers security of the environments that store, process or transmit account data. Environments
receive account data from payment applications and other sources (e.g.., acquirers).
Page 1
, Question 9: what is the overview of PCI PA-DSS
Answer: Covers secure payment applications to support PCI DSS compliance Payment application recieves
account data from PIN-entry devices (PEDs) or other devices and begins payment transaction.
Question 10: What is the overview of PCI P2PE
Answer: Covers encryption, decryption, and Key management requirements for point to point encryption
solutions.
Question 11: What is the overview of PCI PTS-POI?
Answer: Covers the protection of sensitive data at the point of interaction devices and their secure
components, including cardholder PINs and account data, and the cryptographic keys used in connection
with the protection of that cardholder data.
Question 12: What is the overview of PCI PTS-PIN Security?
Answer: Covers secure management, processing and transmission of personal identification number (PIN)
data during online and offline payment card transaction processing.
Question 13: What is the overview of PCI PTS-HSM
Answer: Covers physical, logical and device security requirements for securing hardware security modules.
Question 14: What is the overview of PCI Card Production
Answer: Covers physical and logical security requirements for systems and business processes.
Question 15: What PCI DSS compliance program does American Express develop and maintain?
Answer: Data Security Operating Policy (DSOP)
Question 16: What PCI DSS compliance program does Discover develop and maintain?
Answer: Discover Information Security Compliance (DISC)
Question 17: What PCI does DSS compliance program does JCB develop and maintain?
Answer: Data Security Program
Question 18: What PCI does DSS compliance program does MasterCard develop and maintain?
Answer: Site Data Protection
Page 2
Correct Answers (Grade A+)
Question 1: How is skimming used to target PCI data?
Answer: Copying payment card numbers by tampering with POS devices, ATMs, Kiosks or copying the
magnetic stripe using handheld skimmers.
Question 2: How is phishing used to target PCI data?
Answer: By doing reconnaissance work through social engineering and or breaking in using software
vulnerabilities or e-mails.
Question 3: How can Payment Data be Monetized?
Answer: By skimming the card to get the full track of data, and then making another like card. Using the
card information in a "Card-not-present transactions such as e-commerce or mail order, Telephone order.
Card data is also sold in bulk to other criminals who perform their own fraud using the stolen data.
Question 4: Who all are targeted ?
Answer: Retail, Food and Beaverage, Hospitality, Financial Services, non-profit. EVERYONE!
Question 5: What is the PCI SSC ?
Answer: Payment Card Industry Security Service Counsel is an independent industry standards body
providing oversight of the development and management of Payment Card Industry Data Security Standards
on a global basis.
Question 6: What are some of the PCI SSC founding payment brands.
Answer: American Express, Discover Financial, JCB International, Master Card, Visa inc.
Question 7: What are the Resources provided by the PCI SSC?
Answer: PCI DSS, PA-DSS, P2PE, PTS (POI, HSM and PIN) Card Production, and supporting documents.
Roster of QSAs, PA-QSAs, PCIPs, ASVs, validated payment applications, PTS Devices, and P2PE
solutions PCI Security Standards Counsil FAQs Education and Outreach programs Participating
Organization Membership, Community Meetings, feedback.
Question 8: What is the overview of PCI DSS?
Answer: Covers security of the environments that store, process or transmit account data. Environments
receive account data from payment applications and other sources (e.g.., acquirers).
Page 1
, Question 9: what is the overview of PCI PA-DSS
Answer: Covers secure payment applications to support PCI DSS compliance Payment application recieves
account data from PIN-entry devices (PEDs) or other devices and begins payment transaction.
Question 10: What is the overview of PCI P2PE
Answer: Covers encryption, decryption, and Key management requirements for point to point encryption
solutions.
Question 11: What is the overview of PCI PTS-POI?
Answer: Covers the protection of sensitive data at the point of interaction devices and their secure
components, including cardholder PINs and account data, and the cryptographic keys used in connection
with the protection of that cardholder data.
Question 12: What is the overview of PCI PTS-PIN Security?
Answer: Covers secure management, processing and transmission of personal identification number (PIN)
data during online and offline payment card transaction processing.
Question 13: What is the overview of PCI PTS-HSM
Answer: Covers physical, logical and device security requirements for securing hardware security modules.
Question 14: What is the overview of PCI Card Production
Answer: Covers physical and logical security requirements for systems and business processes.
Question 15: What PCI DSS compliance program does American Express develop and maintain?
Answer: Data Security Operating Policy (DSOP)
Question 16: What PCI DSS compliance program does Discover develop and maintain?
Answer: Discover Information Security Compliance (DISC)
Question 17: What PCI does DSS compliance program does JCB develop and maintain?
Answer: Data Security Program
Question 18: What PCI does DSS compliance program does MasterCard develop and maintain?
Answer: Site Data Protection
Page 2