PCIP EXAM CORRECT 100% 2023
PA-DSS applies to third party payment applications - ANSWER if application performs authorization and/or settlement (POS, shopping carts, etc.) in a PCI DSS compliant manner by supporting the compliance of those that use the application. - ANSWER PA-DSS ensure a payment application functions True - ANSWER True or False: Use of a PA-DSS application alone does not guarantee PCI DSS compliance. Assessor must validate that payment application is installed - ANSWER per instructions in the PA-DSS implementation Guide provided by payment application vendor and in a PCI DSS compliant manner. PTS - ANSWER Acronym for "PIN Transaction Security," PTS is a set of modular evaluation requirements managed by PCI Security Standards Council, for PIN acceptance POI terminals PTS requirements apply to: - ANSWER Point of Interaction (POI) devices Encrypting PIN Pads (EPP) Point of Sale devices (POS) Hardware/host Security Modules (HSM) Unattended Payment Terminals (UPT) non-PIN entry modules PTS ensures terminals cannot be - ANSWER manipulated or attacked to allow the capture of sensitive authentication data nor allow access to clear-text PINS or keys SRED - ANSWER Secure Read and Exchange Module The SRED allows terminals to be - ANSWER approved for the secure encryption of cardholder data as part of the P2PE program. PTS has been extended to allow non-PIN entry modules - ANSWER to be evaluated against the SRED module to allow secure encryption at the point of interaction for non-chip and PIN cards. per PA-DSS implementation guide and in a PCI DSS compliant manner - ANSWER A PCI DSS assessor must validate that the payment application is installed Point of Interaction (POI) Hardware Security Modules (HSM) - ANSWER There are two types of devices addressed by PTS... 1. Attended POS devices such as cash registers 2. Encrypting PIN pads for use in unattended environments such as ATM's 3. Unattended payment terminals such as automated fuel dispensers and kiosks. - ANSWER Points of Interaction are broken into 3 device types.... PIN (Personal Identification Number) security is comprised of - ANSWER secure management, processing and transmission of PIN data during online and offline payment card transaction processing - such as POS terminals (attended or unattended) and ATMs P2PE - ANSWER Point to Point Encryption the scope of the cardholder data environment - ANSWER Using a P2PE hardware to hardware solution may reduce P2PE addresses merchants who - ANSWER ..do not store or decrypt encrypted data within their environment and who use validated solutions consisting of hardware-based encryption and third-party hardware-based encryption P2PE solutions typically consist of - ANSWER a secure encryption device at the merchant premises (PTS validated POI device), all applications on the Point of Interaction device and secure decryption and key management in the service provider's environment. Service Provider - ANSWER Is a business that is not a payment brand and is directly involved in the processing, storage or transmission of cardholder data on behalf of another entity. Sometimes is a merchant. Can control or impact the security of the cardholder. Could be a managed security(firewall, ids, ips), managed network or hosting providers. PCI DSS scope can be reduced on the merchant side because - ANSWER merchants have no access to account data within POI or decryption environment merchants have no involvement in crypto key management all crypto operations managed by solution provider Cardholder - ANSWER the person actually owns the payment card Card present or card not present transaction - ANSWER Cardholder purchases goods either as a the issuer. - ANSWER The cardholder receives the card and bills from The issuer is - ANSWER the bank or other organization issuing a payment card on behalf of a payment brand (i.e. Visa, MC) Yes - ANSWER Can the issuer be a payment brand directly? The merchant is - ANSWER the organization accepting the payment card for payment during a purchase PAN - ANSWER Primary Account Number cardholder data. - ANSWER PAN, Cardholder name, expiration date, service code are all examples of SAD - ANSWER Sensitive Authentication Data SAD (sensitive authentication data) - ANSWER full magnetic stripe data or equivalent on a chip, CAV2/CVC2/CVV2/CID, PINs/PIN blocks...are all examples of Yes - ANSWER If the PAN or SAD is stored processed or transmitted, are the PCI DSS requirements applicable? Cannot - ANSWER Sensitive Authentication Data ________________ be stored after authorization. No, not necessarily - ANSWER Does encrypting Cardholder data or SAD remove it from scope? Track data or track equivalent data - ANSWER Data stored on a magnetic strip or equivalent data encoded on a chip Cloning - ANSWER Chip track data contains a unique chip CVV/CVC code which prevents ___________ the magnetic stripe. True - ANSWER The PAN and expiration data in the chip can be used for fraudulent card-not-present transactions...true or false? Track 1 on the magnetic stripe - ANSWER Contains all fields of both Track 1 and Track 2 and is up to 79 characters Track 2 on magnetic stripe - ANSWER Provides shorter processing time for older dial up transmissions and is up to 40 characters True - ANSWER Issuers and issuing processors may be permitted to retain sensitive authentications data after authorization if needed for business purposes - T or F? True - ANSWER Businesses may have a need to store track data temporarily for troubleshooting purposes - tracks mis-reads, network errors, encryption issues, etc. TorF? True - ANSWER Requirements for a firewall at each internet connection and between any demilitarized zone and the internal network zone - t or f? 6 - ANSWER Requirment to review firewall and router rule sets at least every _____ months False - ANSWER Firewalls do not have to be installed between all wireless networks and the CDE - regardless of the purpose of the environment to which the wireless network is connected - t or f? Yes - ANSWER Is the implementation of a DMZ recommended? True - ANSWER Firewalls should be stateful - true or false? True - ANSWER Segregate system components that store cardholder data (such as a database) in an internal network zone, separate from the DMZ and other untrusted networks t or F? Easier - ANSWER Cardholder data within the DMZ makes it easier or harder for the external attacker to access? False - ANSWER The implementation of multiple functions on one server is encouraged - t or f? Yes - Appendix A1 states shared hosting providers must protect each entity's cardholder data environment - ANSWER Are there additional requirements for shared hosting providers? True - ANSWER Use a one way hash of entire PAN as a way or rendering PAN unreadable - t or f? True - ANSWER A cryptoperiod is a time span during which a particular cryptographic key can be used for its defined purpose - true or false? 800-57 - ANSWER Which NIST SP is used for guidance on cryptographic measures for PCI? Split - ANSWER ______-knowledge and dual control of keys is used to eliminate one person's access to the whole key. True - ANSWER The use of WEP as a security control was prohibited as of June 30, 2010 - true or false? False - answer is one month - ANSWER Keep your **** patched - always within two months of patch release - true or false? PCI DSS Requirement 6 - ANSWER The intention of this requirement is that organizations keep up to date with new vulnerabilities that may impact their environment True - ANSWER The ranking of vulnerabilities is a requirement enacted June 30, 2012 - t or f? True - ANSWER Security must be at the table during requirements definition, design, etc. - t or false? False - ANSWER Production data (live PANs) are used for testing and development - true or false? encryption, decryption and key management within Secure Cryptographic Devices (SCD) - ANSWER The P2PE standard covers... stores, processes, transmits - ANSWER The PCI DSS applies to any entity that ________, _________, or ____________ cardholder data. 36 month - ANSWER The PCI DSS follows a defined ______________ lifecycle. Acquirer - ANSWER Providing: -authorization services to a merchant -clearing services to a merchant -settlement services to a merchant are functions associated with an _____________? Acquirer - Also referred to as "merchant bank," "acquiring bank," or "acquiring financial institution". - ANSWER Entity, typically a financial institution, that processes payment card transactions for merchants and is defined by a payment brand as an acquirer.
Document information
- Uploaded on
- March 16, 2023
- Number of pages
- 16
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers