& Verified Correct Answers
Methods identified as being used to remove stolen data from the environments: - correct
answer ✔✔- Use of stolen credentials to access the POS environment
- Outdated patches or poor system patching processes
- The use of default or static vendor credentials / brute force
- POS skimming malware being installed on POS controllers
- POI physical skimming devices
95% of breaches feature - correct answer ✔✔The use of stolen credentials leveraging vendor
remote access to hack into customers POS environments.
Skimming - correct answer ✔✔Copying payment card numbers either by tampering with:
- POS Devices
- ATMs
- Kiosks
Or by copying the card's magnetic stripe manually using handheld skimmers.
Phishing - correct answer ✔✔Reconnaissance
- Information gathering from various online sources and social networking sites
- Business applications and software
,Social Engineering
- Phishing emails or messages coming from a target's social network
- Phone call from an assumed known entity
Break-In
- Delivery through email
- Software vulnerabilities
Common methods for monetizing stolen card data: - correct answer ✔✔- Skimmed full track
data and transaction information used to replicate a physical payment card, which can then be
used for fraudulent transactions in face-to-face environments, or ATM transactions
- Captured cardholder data is used where card-not-present transactions are accepted, such as e-
commerce or mail-order / telephone order (MO/TO) transactions
- Stolen cardholder data and sensitive authentication data are sold in bulk to other criminals
who perform their own fraud using the stolen data
Commonly targeted industries - correct answer ✔✔- Retail - 45% of breaches
- Food and Beverage - 24% of breaches
- Hospitality - 9% of breaches
- Financial Services - 7% of breaches
- Nonprofit - 3%
PCI SSC founding payment brands include: - correct answer ✔✔- American Express
- Discover Financial
- JCB International
,- MasterCard
- Visa, Inc.
PCI DSS: - correct answer ✔✔Covers security of the environments that store, process, or
transmit account data
- Environments receive account data from payment applications and other sources (e.g.,
acquirers)
PCI PA-DSS - correct answer ✔✔Covers secure payment applications to support PCI DSS
compliance
Payment application receives account data from PIN-entry devices (PEDs) or other devices and
begins payment transaction
PCI P2PE - correct answer ✔✔Covers encryption, decryption, and key management
requirements for point-to-point encryption solutions
PCI PTS - POI - correct answer ✔✔Covers the protection of sensitive data at point-of-interaction
devices and their secure components, including cardholder PINs and account data, and the
cryptographic keys used in connection with the protection of that cardholder data
PCI PTS - PIN Security - correct answer ✔✔Covers secure management, processing and
transmission of personal identificationnumber (PIN) data during online and offline payment card
transaction processing
PCI PTS - HSM - correct answer ✔✔Covers physical, logical and device security requirements for
securing Hardware Security
Modules (HSM)
, PCI Card Production - correct answer ✔✔Covers physical and logical security requirements for
systems and business processes
PA-DSS applies to third party payment applications if? - correct answer ✔✔An application
performs authorization and/or settlement (POS, shopping carts, etc.)
PA-DSS ensures a payment application can function in a PCI DSS compliant manner - correct
answer ✔✔- To support the PCI DSS compliance of those that use the application
- Use of a PA-DSS application alone does not guarantee PCI DSS compliance
Are PA-DSS applications in scope for PCI DSS? - correct answer ✔✔Yes
PA DSS assessor must validate that payment application is installed: - correct answer ✔✔- Per
instructions in the PA-DSS Implementation Guide provided by payment application vendor
- In a PCI DSS compliant manner
A PCI P2PE solution must include all of the following: - correct answer ✔✔- Secure encryption
of payment card data at the point-of-interaction (POI)
- Validated application(s) at the point-of-interaction
- Secure management of encryption and decryption devices
- Management of the decryption environment and all decrypted account data
- Use of secure encryption methodologies and cryptographic key operations, including key
generation, distribution, loading/injection, administration and usage
Merchants may be able to reduce their PCI DSS scope when using Council-listed P2PE solutions -
correct answer ✔✔- Merchant has no access to account data within encryption device (POI) or
decryption environment (at Solution Provider)