• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 9 pages
Exam (elaborations)

PCIP Certificates Correct Questions & Answers

Document preview thumbnail
Preview 2 out of 9 pages

P2PE - ANSWER Merchants who have implemented a validated Point-to-Point Encryption Solution that is listed on the PCI SSC website, with no electronic cardholder data storage. Not applicable to e-commerce channels Prioritize Approach Goal #1 - ANSWER Remove sensitive authentication data and limit data retention Intent: Remove SAD & limit data retention Prioritize Approach Goal #2 - ANSWER Protect systems and networks, and be prepared to respond to a system breach Intent: Controls for point of access and processes for responding Prioritize Approach Goal #3 - ANSWER Secure payment card applications Intent: Controls for applications, application processes, and application servers. Prioritize Approach Goal #4 - ANSWER Monitor and control access to your systems Intent: Detect the who, what, when, and how Prioritize Approach Goal #5 - ANSWER Protect stored cardholder data Intent: Key protections mechanisms for stored PAN Prioritize Approach Goal #6 - ANSWER Finalize remaining compliance efforts, and ensure all controls are in place Intent: Complete PCS DSS requirements, and finalize all remaining related policies, procedures, and processes needed to protect the CDE Goal 1 Req 1-2 - ANSWER Build and Maintain a Secure Network and Systems Goal 2 Req 3-4 - ANSWER Protect Cardholder Data Goal 3 Req 5-6 - ANSWER Maintain a Vulnerability Management Program Goal 4 Req 7-9 - ANSWER Implement Strong Access Control Measures Goal 5 Req 10-11 - ANSWER Regularly Monitor and Test Networks Goal 6 Req 12 - ANSWER Maintain an Information Security Policy PA-DSS and PCI DSS - ANSWER Payment applications must facilitate and not prevent PCI DSS compliance Many payment application requirements in PA-DSS address equivalent PCI DSS requirements P2PE and PCI DSS - ANSWER Incorporates requirements from PTS, PCI DSS, PA-DSS, and PCI PIN to protect account data from the point of capture until it reaches the payment processor When properly implemented and maintained, Council-listed P2PE solutions may help reduce work involved during a merchant's PCI DSS assessment PCI PTS - ANSWER PTS requirements apply to: Point of Interaction (POI) devices; Encrypting PIN Pads (EPP); Point of Sale devices (POS); Hardware (or host) Security Modules (HSMs); Unattended Payment Terminals, (UPTs) Non-PIN Entry module PCI PTS - ANSWER The PTS program ensures terminals cannot be manipulated or attacked to allow the capture of Sensitive Authentication data, nor allow access to clear-text PINs or Keys PCI PTS - ANSWER The Secure Read and Exchange Module, (SRED) allows terminals to be approved for the secure encryption of cardholder data as part of the Point to Point Encryption program PCI PTS - ANSWER PTS has been extended to allow non-PIN entry modules to be evaluated against the SRED module to allow secure encryption at the point of interaction for non-chip and PIN cards PCI PTS - ANSWER Currently addresses two types of devices—point of interaction and hardware security modules. POI is further broken down into three device types: - ANSWER Attended POS devices, which would be a device used at cash registers Encrypting PIN pads, which are intended for use in unattended environments, such as ATMs, and Unattended payment terminals for example, Automated Fuel Dispensers and Kiosks. PCI PIN Security Requirements - ANSWER These requirements provide for secure PIN: Management Processing Transmission PCI PIN Security Requirements - ANSWER The requirements also provide guidance on key management and key handling associated with the PIN PCI PTS - POI and PCI DSS - ANSWER PCI DSS requires that account data be protected both when stored and when transmitted across open, public networks PCI PTS POI validates how POIs protect PIN and account data and manage cryptographic keys PCI PTS POI-approved devices may form part of a PCI DSS-compliant environment PCI PTS - PIN Security Standard and PCI DSS - ANSWER PCI DSS prohibits storage of encrypted PIN blocks No overlap PCI Card Production and PCI DSS - ANSWER No overlap Procedures for assessing card production facilities are defined and managed by the payment brands, not by PCI SSC


Document information

Uploaded on
March 15, 2023
Number of pages
9
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
shantelleG
4.1
(119)
Sold
658
Followers
369
Items
18427
Last sold
4 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions

Whoops! We can’t load your doc right now. Try again or contact support.