PCIP Certificates Correct Questions & Answers
P2PE - ANSWER Merchants who have implemented a validated Point-to-Point Encryption Solution that is listed on the PCI SSC website, with no electronic cardholder data storage. Not applicable to e-commerce channels Prioritize Approach Goal #1 - ANSWER Remove sensitive authentication data and limit data retention Intent: Remove SAD & limit data retention Prioritize Approach Goal #2 - ANSWER Protect systems and networks, and be prepared to respond to a system breach Intent: Controls for point of access and processes for responding Prioritize Approach Goal #3 - ANSWER Secure payment card applications Intent: Controls for applications, application processes, and application servers. Prioritize Approach Goal #4 - ANSWER Monitor and control access to your systems Intent: Detect the who, what, when, and how Prioritize Approach Goal #5 - ANSWER Protect stored cardholder data Intent: Key protections mechanisms for stored PAN Prioritize Approach Goal #6 - ANSWER Finalize remaining compliance efforts, and ensure all controls are in place Intent: Complete PCS DSS requirements, and finalize all remaining related policies, procedures, and processes needed to protect the CDE Goal 1 Req 1-2 - ANSWER Build and Maintain a Secure Network and Systems Goal 2 Req 3-4 - ANSWER Protect Cardholder Data Goal 3 Req 5-6 - ANSWER Maintain a Vulnerability Management Program Goal 4 Req 7-9 - ANSWER Implement Strong Access Control Measures Goal 5 Req 10-11 - ANSWER Regularly Monitor and Test Networks Goal 6 Req 12 - ANSWER Maintain an Information Security Policy PA-DSS and PCI DSS - ANSWER Payment applications must facilitate and not prevent PCI DSS compliance Many payment application requirements in PA-DSS address equivalent PCI DSS requirements P2PE and PCI DSS - ANSWER Incorporates requirements from PTS, PCI DSS, PA-DSS, and PCI PIN to protect account data from the point of capture until it reaches the payment processor When properly implemented and maintained, Council-listed P2PE solutions may help reduce work involved during a merchant's PCI DSS assessment PCI PTS - ANSWER PTS requirements apply to: Point of Interaction (POI) devices; Encrypting PIN Pads (EPP); Point of Sale devices (POS); Hardware (or host) Security Modules (HSMs); Unattended Payment Terminals, (UPTs) Non-PIN Entry module PCI PTS - ANSWER The PTS program ensures terminals cannot be manipulated or attacked to allow the capture of Sensitive Authentication data, nor allow access to clear-text PINs or Keys PCI PTS - ANSWER The Secure Read and Exchange Module, (SRED) allows terminals to be approved for the secure encryption of cardholder data as part of the Point to Point Encryption program PCI PTS - ANSWER PTS has been extended to allow non-PIN entry modules to be evaluated against the SRED module to allow secure encryption at the point of interaction for non-chip and PIN cards PCI PTS - ANSWER Currently addresses two types of devices—point of interaction and hardware security modules. POI is further broken down into three device types: - ANSWER Attended POS devices, which would be a device used at cash registers Encrypting PIN pads, which are intended for use in unattended environments, such as ATMs, and Unattended payment terminals for example, Automated Fuel Dispensers and Kiosks. PCI PIN Security Requirements - ANSWER These requirements provide for secure PIN: Management Processing Transmission PCI PIN Security Requirements - ANSWER The requirements also provide guidance on key management and key handling associated with the PIN PCI PTS - POI and PCI DSS - ANSWER PCI DSS requires that account data be protected both when stored and when transmitted across open, public networks PCI PTS POI validates how POIs protect PIN and account data and manage cryptographic keys PCI PTS POI-approved devices may form part of a PCI DSS-compliant environment PCI PTS - PIN Security Standard and PCI DSS - ANSWER PCI DSS prohibits storage of encrypted PIN blocks No overlap PCI Card Production and PCI DSS - ANSWER No overlap Procedures for assessing card production facilities are defined and managed by the payment brands, not by PCI SSC
Información del documento
- Subido en
- 15 de marzo de 2023
- Número de páginas
- 9
- Escrito en
- 2022/2023
- Tipo
- Examen
- Contiene
- Preguntas y respuestas