• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 2 fuera de 5 páginas
Examen

PCIP Study Guide Correct 100%

Document preview thumbnail
Vista previa 2 fuera de 5 páginas

PA-DSS - ANSWER Payment Application Data Security Standard (POS, shopping carts, etc.) PTS (POI) - ANSWER Pin Transaction Security Point of Interaction Standard (Attended and Unattended Devices) HSM (PIN) - ANSWER Hardware Security Module Pin Standard (not required but may assist in becoming compliant) P2PE - ANSWER Point to Point Encryption Standard (Most helpful standard to reduce scope) SRED - ANSWER Secure Read and Exchange Module allows terminals to be approved for secure encryption of cardholder data. POI Examples - ANSWER Attended : Cash Registers Unattended Encrypted PIN Pads : ATM Unattended Payment Terminals : Gas Pump PCI PIN Security Requirements - ANSWER Management Processing Transmission Payment Card Flow - ANSWER Cardholder presents card - Acquirer asks payment brand to determine issuer - Payment brand network determines issuer and requests approval- Issuer approves purchase- Payment brand network sends approval to the acquirer - Acquirer sends approval to merchant- Cardholder completes purchase and receives receipt. Aquirer (Also Called?) - ANSWER -Merchant Bank -Independent Sale Organization (ISO) -Payment Brand (Amex, Discover, JCB) -Never Visa or Mastercard Payment Card Flow (Clearing) - ANSWER Acquirer sends purchase information to the payment brand network - payment brand network sends purchase information to the issuer - issuer prepares data for cardholder statement - payment brand network provides complete reconciliation to acquirer. Payment Card Flow (Settlement) - ANSWER Issuer determines acquirer via the payment brand network - Issuer sends payment to acquirer - Acquirer pays merchant for cardholders purchase - Issuer bills cardholder Service Provider - ANSWER A business that is not a payment brand, directly involved in the processing, storage or transmission of cardholder data on behalf of another entity. Sometimes a service provider is a merchant. QIR's - ANSWER Qualified Integrators and Resellers -Assure quality and provide feedback What QIR's do? - ANSWER -Implementing applications into a merchant environment -Integrating applications into new software or systems. -Configuring the payment application -Servicing payment applications to provide troubleshooting/remote updates or support. PA-DSS Implementation Guide - ANSWER -What the QIR uses in order to implement a PCI DSS compliant payment application into a CDE environment. -After installation the QIR creates an implementation statement and gives it to the customer for their signature. CID - ANSWER Card Identification Number (American Express) CAV2/CID/CVC2/CW2 - ANSWER Card specific code on back of card (Discover, JCB, Mastercard, Visa) Cardholder Data - ANSWER -PAN -Cardholder Name -Expiration Date -Service Code Sensitive Authentication Data - ANSWER -Full magnetic stripe data or chip data -CAV2/CVC2/CVV2/CID -PINs/PIN blocks -Cannot be stored after authorization Track 1 Data - ANSWER Contains all fields of Both Track 1 and Track 2 -Length up to 79 characters. Track 2 Data - ANSWER Provides shorter processing time for older dial up transmissions. -Length up to 40 characters Inventorying Cardholder Environment - ANSWER -System Name -Cardholder data stored -Reason for storage -Retention period -Protection mechanism. Is storing track data permitted after authorization? - ANSWER No PCI DSS Goals - ANSWER -Build and maintain a secure network and systems -Protect Cardholder Data -Maintain a vulnerability management program -Implement strong access control measures -Regularly monitor and test networks -Maintain an information security policy. Requirement 1 - ANSWER Install and maintain a firewall configuration to protect cardholder data. Requirement 2 - ANSWER Do not use vendor-supplied defaults for system passwords and other security parameters. Requirement 3 - ANSWER Protect stored cardholder data. (Hashing, truncation, tokenization, and encryption) Requirement 4 - ANSWER Encrypt transmission of cardholder data across open, public networks. Requirement 5 - ANSWER Protect all systems against malware and regularly update anti-virus software or programs. Requirement 6 - ANSWER Develop and maintain secure systems and applications. (Coding, patching) Requirement 7 - ANSWER Restrict access to cardholder data by business need to know. Requirement 8 - ANSWER Identify and authenticate access to system components. (Access control) Requirement 9 - ANSWER Restrict physical access to cardholder data. Requirement 10 - ANSWER Track and monitor all access to network resources and cardholder data. (Logs/Changes) Requirement 11 - ANSWER Regularly test security systems and processes. (Vuln. Scans, PenTests, Network Scans) Requirement 12 - ANSWER Maintain a policy that addresses information security for all personnel. Masking - ANSWER The first six and last 4 digits are the only account numbers viewable. Storing track data "long-term" or "persistently" is permitted when ____________? - ANSWER It is being used by issuers. Requirement A1 - ANSWER Shared hosting providers must protect the cardholder data environment. Requirement A2 - ANSWER SSL and Early TLS implementations. Requirement A3 - ANSWER Designated Entities Supplemental Validation (DESV) What has to exist for a compensating control? - ANSWER Legitimate Technical Constraint or Documented Business Constraint SAQ A - ANSWER Card not present (E-Commerce, Mail Order/Telephone Order) w/outsourced storage to PCI compliant 3rd party. SAQ A-EP - ANSWER E-Commerce merchants with a website that does not take cardholder data. SAQ B - ANSWER Imprint-only merchants with no electronic cardholder data storage. SAQ B-IP - ANSWER Merchants using only stand-alone, PTS-approved payment terminals with an IP connection to a payment processor. SAQ C - ANSWER Merchants with segmented payment application systems, and no electronic cardholder data storage. SAQ C-VT - ANSWER Merchants using only web-based virtual payment terminals, with no electronic cardholder data storage. SAQ D - ANSWER All merchants not included in the description for all other SAQ types. SAQ P2PE - ANSWER Merchants who have implemented a validated Point-to-Point Encryption Solution that is listed on the PCI SSC website, with no electronic cardholder data storage. Prioritized Approach 1 - ANSWER Remove sensitive data and limit data retention. Prioritized Approach 2 - ANSWER Protect systems and networks, and be prepared to respond to a system breach. Prioritized Approach 3 - ANSWER Secure payment card applications. Prioritized Approach 4 - ANSWER Monitor and control access to your systems.


Información del documento

Subido en
15 de marzo de 2023
Número de páginas
5
Escrito en
2022/2023
Tipo
Examen
Contiene
Preguntas y respuestas
$11.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
shantelleG
4.1
(119)
Vendido
658
Seguidores
369
Artículos
18427
Última venta
3 horas hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes

Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.