• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 5 pages
Exam (elaborations)

PCIP Study Guide 2017 Correctly Solved

Document preview thumbnail
Preview 2 out of 5 pages

PA-DSS - ANSWER Payment Application Data Security Standard (POS, shopping carts, etc.) PTS (POI) - ANSWER Pin Transaction Security Point of Interaction Standard (Attended and Unattended Devices) HSM (PIN) - ANSWER Hardware Security Module Pin Standard (not required but may assist in becoming compliant) P2PE - ANSWER Point to Point Encryption Standard (Most helpful standard to reduce scope) SRED - ANSWER Secure Read and Exchange Module allows terminals to be approved for secure encryption of cardholder data. POI Examples - ANSWER Attended : Cash Registers Unattended Encrypted PIN Pads : ATM Unattended Payment Terminals : Gas Pump PCI PIN Security Requirements - ANSWER Management Processing Transmission Payment Card Flow - ANSWER Cardholder presents card - Acquirer asks payment brand to determine issuer - Payment brand network determines issuer and requests approval- Issuer approves purchase- Payment brand network sends approval to the acquirer - Acquirer sends approval to merchant- Cardholder completes purchase and receives receipt. Aquirer (Also Called?) - ANSWER -Merchant Bank -Independent Sale Organization (ISO) -Payment Brand (Amex, Discover, JCB) -Never Visa or Mastercard Payment Card Flow (Clearing) - ANSWER Acquirer sends purchase information to the payment brand network - payment brand network sends purchase information to the issuer - issuer prepares data for cardholder statement - payment brand network provides complete reconciliation to acquirer. Payment Card Flow (Settlement) - ANSWER Issuer determines acquirer via the payment brand network - Issuer sends payment to acquirer - Acquirer pays merchant for cardholders purchase - Issuer bills cardholder Service Provider - ANSWER A business that is not a payment brand, directly involved in the processing, storage or transmission of cardholder data on behalf of another entity. Sometimes a service provider is a merchant. QIR's - ANSWER Qualified Integrators and Resellers -Assure quality and provide feedback What QIR's do? - ANSWER -Implementing applications into a merchant environment -Integrating applications into new software or systems. -Configuring the payment application -Servicing payment applications to provide troubleshooting/remote updates or support. PA-DSS Implementation Guide - ANSWER -What the QIR uses in order to implement a PCI DSS compliant payment application into a CDE environment. -After installation the QIR creates an implementation statement and gives it to the customer for their signature. CID - ANSWER Card Identification Number (American Express) CAV2/CID/CVC2/CW2 - ANSWER Card specific code on back of card (Discover, JCB, Mastercard, Visa) Cardholder Data - ANSWER -PAN -Cardholder Name -Expiration Date -Service Code Sensitive Authentication Data - ANSWER -Full magnetic stripe data or chip data -CAV2/CVC2/CVV2/CID -PINs/PIN blocks -Cannot be stored after authorization Track 1 Data - ANSWER Contains all fields of Both Track 1 and Track 2 -Length up to 79 characters. Track 2 Data - ANSWER Provides shorter processing time for older dial up transmissions. -Length up to 40 characters Inventorying Cardholder Environment - ANSWER -System Name -Cardholder data stored -Reason for storage -Retention period -Protection mechanism. Is storing track data permitted after authorization? - ANSWER No PCI DSS Goals - ANSWER -Build and maintain a secure network and systems -Protect Cardholder Data -Maintain a vulnerability management program -Implement strong access control measures -Regularly monitor and test networks -Maintain an information security policy. Requirement 1 - ANSWER Install and maintain a firewall configuration to protect cardholder data. Requirement 2 - ANSWER Do not use vendor-supplied defaults for system passwords and other security parameters. Requirement 3 - ANSWER Protect stored cardholder data. (Hashing, truncation, tokenization, and encryption) Requirement 4 - ANSWER Encrypt transmission of cardholder data across open, public networks. Requirement 5 - ANSWER Protect all systems against malware and regularly update anti-virus software or programs. Requirement 6 - ANSWER Develop and maintain secure systems and applications. (Coding, patching) Requirement 7 - ANSWER Restrict access to cardholder data by business need to know. Requirement 8 - ANSWER Identify and authenticate access to system components. (Access control) Requirement 9 - ANSWER Restrict physical access to cardholder data. Requirement 10 - ANSWER Track and monitor all access to network resources and cardholder data. (Logs/Changes) Requirement 11 - ANSWER Regularly test security systems and processes. (Vuln. Scans, PenTests, Network Scans) Requirement 12 - ANSWER Maintain a policy that addresses information security for all personnel. Masking - ANSWER The first six and last 4 digits are the only account numbers viewable. Storing track data "long-term" or "persistently" is permitted when ____________? - ANSWER It is being used by issuers. Requirement A1 - ANSWER Shared hosting providers must protect the cardholder data environment. Requirement A2 - ANSWER SSL and Early TLS implementations. Requirement A3 - ANSWER Designated Entities Supplemental Validation (DESV) What has to exist for a compensating control? - ANSWER Legitimate Technical Constraint or Documented Business Constraint


Document information

Uploaded on
March 16, 2023
Number of pages
5
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers
$12.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
shantelleG
4.1
(119)
Sold
658
Followers
369
Items
18427
Last sold
3 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions

Whoops! We can’t load your doc right now. Try again or contact support.