• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 3 fuera de 17 páginas
Examen

PCIP QUESTIONS AND ANSWERS CORRECT 100%

Document preview thumbnail
Vista previa 3 fuera de 17 páginas

PCI DSS Requirement 8 - ANSWER Assign a unique ID to each person with computer access PCI DSS Requirement 9 - ANSWER Restrict physical access to cardholder data PCI DSS Requirement 10 - ANSWER Track and monitor all access to network resources and cardholder data PCI DSS Requirement 11 - ANSWER Regularly test secuirty systems and processes with wireless scans, vulnerability scnas, log audits, ASV (Approved Scanning Vendor) PCI DSS Requirement 12 - ANSWER Maintain a policy that addresses information security for all personnel ASV (Approved Scanning Vendor) - ANSWER Company approved by the PCI SSC to conduct external vulnerability scanning services. PCI Data Security Standards (PCI DSS) - ANSWER Covers the security of the environments that store, process or transmit account data. Environments receive account data from payment applications and other sources (e.g. acquirers) PCI Payment Application Data Security Standards (PCI PA-DSS) - ANSWER Covers secure payment applications to support PCI DSS compliance. Applies to Third Party payment applications if the application performs authorization and/or settlement (POS, shopping carts, etc.) Ensures a payment application can function in a PCI DSS compliant manner PA-DSS applications are in scope for PCI DSS Payment application receives account data from PIN Entry Devices (PED) or other devices and begins payment transaction PCI PIN Transaction Security (PCI PTS) - ANSWER Covers device tamper detection, cryptographic processes and other mechanisms to protect the Personal Identification Number (PIN). Encrypted PIN is passed to payment application or hardware terminal. PCI-PTS - PIN Security - ANSWER Covers secure management, processing and transmission of personal identification number data during online and offline payment card transaction processing PCI-PTS - HSM (Hardware Security Module or Host Security Module) - ANSWER A physically and logically protected hardware device that provides a secure set of cryptographic services, used for cryptographic key-management functions and/or the decryption of account data. Not required by DSS, but may help with the management of keys. PCI Point to Point Encryption (PCI P2PE) - ANSWER Covers encryption, decryption and key management within secure cryptographic devices (SCD). Not a requirement but may result in reduction of scope. Secure Cryptographic Device (SCD) - ANSWER A set of hardware, software and firmware that implements cryptographic processes (including cryptographic algorithms and key generation) and is contained within a defined cryptographic boundary. Examples of secure cryptographic devices include host/hardware security modules (HSMs) and point-of-interaction devices (POIs) that have been validated to PCI PTS. POI - Point of Interaction - ANSWER The initial point where data is read from a card. An electronic transaction-acceptance product, a POI consists of hardware and software and is hosted in acceptance equipment to enable a cardholder to perform a card transaction. The POI may be attended or unattended. POI transactions are typically integrated circuit (chip) and/or magnetic-stripe card-based payment transactions. PCI Card Production - ANSWER Covers physical and logical security requirements for systems and business processes associated with card personalization, PIN generation, PIN mailers, and card carriers and distribution. CDE - Cardholder Data Environment - ANSWER The people, processes and technology that store, process, or transmit cardholder data or sensitive authentication data. Relationship between PTS and PCI DSS - ANSWER DSS prevents the storage of encrypted PIN blocks. PTS supports the PIN encryption so there's no overlap. Relationship between PCI DSS and PA-DSS - ANSWER Payment applications must support and not hinder PCI DSS compliance PCI DSS requirements mirrored in many payment application requirements in PA-DSS Relationship between PCI DSS and P2PE - ANSWER Incorporates requirements from Pin Transaction Security, PCI DSS, PA-DSS and PCI PIN to protect CHD from the point of capture until it reaches the payment processor. Properly implemented, validated P2PE solutions may help reduce the scope of a merchant's PCI DSS assessment. Payment Processor - ANSWER Entity engaged by a merchant or other entity to handle payment card transactions on their behalf. While they typically provide acquiring services, payment processors are not considered acquirers unless defined as such by a payment card brand. CHD - Card Holder Data - ANSWER At a minimum, cardholder data consists of the full PAN. Cardholder data may also appear in the form of the full PAN plus any of the following: cardholder name, expiration date and/or service code See Sensitive Authentication Data for additional data elements that may be transmitted or processed (but not stored) as part of a payment transaction. PA-DSS applies to third party payment applications - ANSWER if application performs authorization and/or settlement (POS, shopping carts, etc.) in a PCI DSS compliant manner by supporting the compliance of those that use the application. - ANSWER PA-DSS ensure a payment application functions True - ANSWER True or False: Use of a PA-DSS application alone does not guarantee PCI DSS compliance. Assessor must validate that payment application is installed - ANSWER per instructions in the PA-DSS implementation Guide provided by payment application vendor and in a PCI DSS compliant manner. PTS - ANSWER Acronym for "PIN Transaction Security," PTS is a set of modular evaluation requirements managed by PCI Security Standards Council, for PIN acceptance POI terminals PTS requirements apply to: - ANSWER Point of Interaction (POI) devices Encrypting PIN Pads (EPP) Point of Sale devices (POS) Hardware/host Security Modules (HSM) Unattended Payment Terminals (UPT) non-PIN entry modules PTS ensures terminals cannot be - ANSWER manipulated or attacked to allow the capture of sensitive authentication data nor allow access to clear-text PINS or keys SRED - ANSWER Secure Read and Exchange Module The SRED allows terminals to be - ANSWER approved for the secure encryption of cardholder data as part of the P2PE program. PTS has been extended to allow non-PIN entry modules - ANSWER to be evaluated against the SRED module to allow secure encryption at the point of interaction for non-chip and PIN cards. per PA-DSS implementation guide and in a PCI DSS compliant manner - ANSWER A PCI DSS assessor must validate that the payment application is installed Point of Interaction (POI) Hardware Security Modules (HSM) - ANSWER There are two types of devices addressed by PTS... 1. Attended POS devices such as cash registers 2. Encrypting PIN pads for use in unattended environments such as ATM's 3. Unattended payment terminals such as automated fuel dispensers and kiosks. - ANSWER Points of Interaction are broken into 3 device types.... PIN (Personal Identification Number) security is comprised of - ANSWER secure management, processing and transmission of PIN data during online and offline payment card transaction processing - such as POS terminals (attended or unattended)


Información del documento

Subido en
15 de marzo de 2023
Número de páginas
17
Escrito en
2022/2023
Tipo
Examen
Contiene
Preguntas y respuestas
$13.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
shantelleG
4.1
(119)
Vendido
658
Seguidores
369
Artículos
18427
Última venta
3 horas hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes

Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.