
CPSA_P_New Practice Test Questions Answers Updated 52 Questions
CPSA_P_New dumps & CPSA Qualification Sure Practice with 52 Questions
NEW QUESTION # 15
A vendor has a list of pre-approved third parties which may be granted access to the facility. Under what circumstances can other third-parties be granted access?
- A. When the third party s liability insurance covers the risk
- B. When no card production activities are taking place
- C. When they are approved by the physical security manager or senior management
- D. None, only people on the pre-approved list may enter
Answer: C
Explanation:
Explanation
According to the PCI Card Production Logical Security Requirements, vendors must have a list of pre-approved third parties that are authorized to access the facility and the systems involved in card production. However, other third parties may be granted access under exceptional circumstances, such as emergency repairs or maintenance, provided that they are approved by the physical security manager or senior management. The vendor must also ensure that the third parties comply with the security policies and procedures, and that their access is logged and monitored. References: PCI Card Production Logical Security Requirements, v2.0, April 2019, page 13
NEW QUESTION # 16
During an assessment you walk the perimeter of the building with a guard you find an emergency exit door from the facility and ask the guard what is on the other side. The guard can't remember, and so uses their assigned, secure key to open the door and show you a corridor within the facility. What most concerns you about the situation?
- A. The guard should have sought permission from their manager before opening the door
- B. The exit door should not lead into the facility
- C. The exit door should not be capable of being opened from the outside
- D. The guard should not have forgotten where the door leads to
Answer: C
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, emergency exit doors must be equipped with devices that prevent unauthorized entry from the outside, such as panic bars, crash bars, or push pads. These devices allow the door to be opened from the inside without a key or a code, but prevent the door from being opened from the outside by unauthorized persons. Therefore, the most concerning aspect of the situation is that the exit door can be opened from the outside with a key, which creates a security risk for the facility. The other options are not as concerning, as they do not directly affect the security of the exit door. The exit door can lead into the facility as long as it provides a safe and unobstructed path to the exit discharge. The guard's memory lapse is not a major issue, as long as they follow the proper proceduresand protocols for opening the door. The guard's permission from their manager is not relevant, as long as they have the authority and the responsibility to open the door for inspection purposes. References:
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
171
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
181
NEW QUESTION # 17
Where can misprinted, partially finished cards be shredded?
- A. Only in the HSA destruction room
- B. Either in the HSA printing room or destruction room
- C. In any HSA room approved by the security manager
- D. Either in the HSA destruction room or a loading bay that meets all requirements of a destruction room
Answer: A
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for card destruction is to ensure that misprinted, partially finished, or rejected cards are shredded only in the HSA destruction room. This is to prevent unauthorized access, theft, or misuse of the cards, which may contain sensitive data or features. The HSA destruction room should have adequate security measures, such as locks, alarms, cameras, etc., to protect the cards until they are shredded. The shredding process should render the cards unusable and unrecognizable, and the shredded material should be disposed of securely. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 5, Requirement 5.1.1, Page 111
NEW QUESTION # 18
Before you go on-site, the vendor's primary contact communicates a legitimate reason for delaying the assessment for several months. Who can approve the change in the report delivery schedule?
- A. Affected issuers
- B. PCI SSC
- C. Payment brands
- D. Vendor senior management
Answer: B
Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, one of the administrative requirements for CPSA Companies is to adhere to the report delivery schedule as defined by the PCI SSC. The report delivery schedule specifies the deadlines for submitting the PCI Card Production Reports on Compliance (ROCs) and Attestations of Compliance (AOCs) to the PCI SSC and the payment brands. The report delivery schedule also defines the circumstances under which a CPSA Company may request an extension or a waiver of the report delivery deadline. The PCI SSC is the only entity that can approve the change in the report delivery schedule, and the CPSA Company must submit a written request to the PCI SSC with a valid reason for the delay and the proposed new delivery date. The PCI SSC will review the request and notify the CPSA Company of its decision. The PCI SSC may also notify the payment brands and the affected issuers of the change in the report delivery schedule. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 6.1.4, Page 121
NEW QUESTION # 19
An assessor is unsure if log review and interview is sufficient testing for a requirement. Who can best answer this question?
- A. Vendor
- B. Issuing banks
- C. PCI SSC
- D. Payment brands
Answer: C
Explanation:
Explanation
The PCI SSC (Payment Card Industry Security Standards Council) is the organization that develops and maintains the PCI Card Production Standards and related validation requirements, programs, and supporting documentation. The PCI SSC also provides training and qualification for CPSA Companies and CPSA Employees to perform PCI Card Production Assessments. The PCI SSC is the best source of guidance and clarification for any questions or issues related to the assessment process, testing methods, reporting requirements, and interpretation of the standards. The assessor can contact the PCI SSC by email, phone, or online form, as specified in the CPSA Program Guide1. The payment brands, issuing banks, and vendors are not responsible for defining or explaining the assessment requirements or testing methods, and may not have the same level of expertise or authority as the PCI SSC. References:
Card Production Security Assessor (CPSA) Program Guide, Section 2.1 and 5.1 Card Production Security Assessor (CPSA) Qualification Requirements, Section 1.1 and 2.1
NEW QUESTION # 20
Who performs regular AQM audits of CPSA companies?
- A. Vendor
- B. Issuing banks
- C. PCI SSC
- D. Payment brands
Answer: C
Explanation:
Explanation
The PCI Security Standards Council (PCI SSC) performs regular Assessor Quality Management (AQM) audits of CPSA companies to ensure that they comply with the PCI CPSA Qualification Requirements and the PCI Card Production Standards. The AQM audits are conducted by PCI SSC staff or authorized third parties, and may include onsite visits, remote reviews, or both. The AQM audits aim to verify the quality and consistency of the CPSA companies' assessment processes, reports, and documentation, as well as their adherence to the PCI SSC Code of Professional Responsibility. The AQM audits may result in corrective actions, sanctions, or revocation of the CPSA company status, depending on the severity and frequency of the non-compliance issues identified. References:
PCI Card Production Security Assessor (CPSA) Qualification Requirements, v1.0, April 2019, page 12, requirement 8.1 PCI Card Production Security Assessor (CPSA) Program Guide, v1.0, April 2019, page 6, section 3.2
NEW QUESTION # 21
The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?
- A. During busy times, the local police may not be able to respond
- B. If the local police have not been issued with an exterior key. they will not be able to investigate the cause of the alarm and reset it
- C. During working hours, the alarm should be managed in the security control room, or by a central monitoring service
- D. If the local police receive too many false-positive alerts, they may not respond within 15 minutes of the alarm
Answer: C
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must have an alarm system that monitors and detects unauthorized access to the card production and provisioning facilities, and that alerts the security control room or a central monitoring service. The alarm system must also be able to identify the location and cause of the alarm, and allow authorized personnel to reset it. The alarm system must be operational 24/7, and must be tested at least annually. The vendor must also have procedures to respond to alarms and incidents, and to report them to the relevant parties. If the alarm system does not send alerts to the security control room, or a central monitoring service, during working hours, the vendor may not be able to comply with these requirements, and may not be able to prevent, detect, or respond to unauthorized access or security breaches. This may cause a problem for their assessment, as they may not meet the PCI Card Production and Provisioning Physical Security Requirements. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101
NEW QUESTION # 22
During an assessment you do a walk-through of bringing card products into the HSA using the goods-tools trap. You act as production staff, using an empty cardboard box as the card products. During the process, the guard escorts you, along with the box, into the pre-press room. What is your conclusion?
- A. Compliant, because the guard ensured that the card product remained under dual control
- B. Not compliant, because an inventory of the card product did not take place prior to entry
- C. Compliant, because the guard escorted you
- D. Not compliant, because the guard escorted you
Answer: D
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the goods-tools trap is a secure area that separates the HSA from the outside world, and is used to control the entry and exit of card products, tools, and other materials. The goods-tools trap must have two doors that are interlocked, meaning that only one door can be opened at a time. The goods-tools trap must also have a CCTV camera and an alarm system. The process of bringing card products into the HSA using the goods-tools trap must follow these steps1:
The card products must be delivered to the goods-tools trap by authorized personnel, who must present their identification to the guard and sign a delivery note.
The guard must verify the identification of the personnel and the quantity and quality of the card products, and record the details in a log.
The guard must then escort the personnel to the first door of the goods-tools trap, and open it using a key or a card reader. The personnel must place the card products inside the goods-tools trap and exit the area. The guard must then lock the first door.
The guard must then notify the production staff inside the HSA that the card products are ready to be collected. The production staff must present their identification to the guard and sign a receipt note.
The guard must then escort the production staff to the second door of the goods-tools trap, and open it using a key or a card reader. The production staff must collect the card products from the goods-tools trap and enter the HSA. The guard must then lock the second door.
In this scenario, the guard escorted the production staff, along with the box, into the pre-press room. This is not compliant, because the guard is not authorized to enter the HSA, and the card products must remain under dual control at all times. The guard should have stayed outside the HSA and only opened the second door of the goods-tools trap for the production staff. This would ensure that the card products are securely transferred from the goods-tools trap to the HSA, and that the guard does not compromise the security of the HSA.
References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 15, requirement 2.1.1 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 16, requirement 2.1.2 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 17, requirement 2.1.3 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 18, requirement 2.1.4
NEW QUESTION # 23
During an assessment you ask to see employee records for employees with access to the HSA. The records include information about the screening process, including background information from the employee application process. The oldest background Information that is available is for an employee that left the vendor (terminated their contract) one year previously. You note this as non-compliant, why?
- A. The vendor must only retain background information for all current employees, not for those that have been terminated
- B. The vendor must retain the background information for at least 18 months after termination of contract
- C. Employee information, including background checks, must be stored for at least seven years
- D. Employee information must be securely destroyed (e.g. securely wiped) within 2 years (after termination of contract)
Answer: D
Explanation:
Explanation
According to the PCI Card Production Logical Security Requirements, the vendor must securely destroy all employee information, including background checks, within two years of the employee's termination of contract. This is to prevent unauthorized access to sensitive employee data and to comply with the PCI DSS requirement 3.1, which states that cardholder data must not be stored longer than necessary. The vendor must also have a documented policy and procedure for the secure destruction of employee information, and must maintain a log of all destruction activities. References:
PCI Card Production Logical Security Requirements, v2.0, April 2019, page 19, requirement 6.1.1 PCI DSS, v3.2.1, May 2018, page 25, requirement 3.1
NEW QUESTION # 24
In which of the following locations must the CCTV and access control servers be located?
- A. Within a room in the HSA with security controls equivalent to the SCR applied
- B. Within the SCR or a room with equivalent security
- C. Within the Security Control Room (SCR)
- D. Within the secure server room inside of the HSA
Answer: B
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the CCTV and access control servers must be located within the Security Control Room (SCR) or a room with equivalent security. This means that the room must have the same level of physical protection as the SCR, such as locks, alarms, sensors, cameras, and access control devices. The purpose of this requirement is to prevent unauthorized access, tampering, or theft of the servers that store and process sensitive data related to card production and security. References: PCI Card Production Physical Security Requirements, v2.0, April 2019, page 16
NEW QUESTION # 25
When must HSA motion detectors generate an alarm event?
- A. Each time movement is detected and the access-control system indicates the room is not occupied
- B. Each time movement is detected outside of regular business hours
- C. Each time movement is detected and the access-control system indicates the room is occupied
- D. Each time movement is detected
Answer: A
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for high-security areas (HSAs) is to have motion detectors that generate an alarm event when movement is detected and the access-control system indicates the room is not occupied. This is to prevent unauthorized access or intrusion to the HSAs, where sensitive card production and provisioning activities take place. The motion detectors should be configured to cover all areas within the HSA and should be tested periodically to ensure proper functionality. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 2, Requirement 2.1.1, Page 61
NEW QUESTION # 26
Which of the following statements about unsolicited visitors is true?
- A. They must be turned away
- B. They must be registered, their identities confirmed, and must be allocated an escort before entry
- C. They must be able to prove a legitimate reason for their visit prior to entry
- D. They must complete an NDA before entry is granted
Answer: B
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, unsolicited visitors are defined as "individuals who do not have a pre-arranged appointment or a legitimate reason for visiting the Card Production Entity". The requirement for dealing with unsolicited visitors is that they must be registered, their identities confirmed, and must be allocated an escort before entry. The escort must accompany the unsolicited visitor at all times and ensure that they do not access any restricted areas or sensitive information.
The other options are not true statements about unsolicited visitors, as they may not comply with the PCI Card Production Standards or the best practices for physical security. References:
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
101
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
111
NEW QUESTION # 27
In relation to guards, which of the following must the vendor ensure?
- A. There is always at least one guard in the HSA and one guard in the security control room at all times
- B. A clear segregation of duties is maintained between production staff and guards
- C. A clear segregation of duties is maintained between guard and reception related job functions
- D. There is always at least one guard on-site, including outside of working hours, to monitor security systems and premises
Answer: C
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the vendor must ensure that a clear segregation of duties is maintained between guard and reception related job functions. This is to prevent any conflict of interest or collusion that could compromise the security of the card production and provisioning processes or the cardholder data. The vendor must also ensure that the guards are adequately trained, supervised, and evaluated, and that they follow the security policies and procedures established by the vendor.
The vendor must also have a documented policy and procedure for the selection, hiring, and termination of guards, and must maintain a log of all guard activities. References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 24, requirement 6.1.1 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 25, requirement 6.1.2 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 26, requirement 6.1.3 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 27, requirement 6.1.4
NEW QUESTION # 28
Which of the following must be used by the vendor to protect doors that provide access to buildings containing air conditioning equipment?
- A. Magnetic contacts that are permanently alarmed and that are connected to the security control-room panels
- B. Physical locks with a limited set of keys under constant supervision by a guard in the security control-room
- C. Electrical contacts that log each open and close event to a secure system memory
- D. Security tape that will leave an observable trace each time a door is opened
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must use magnetic contacts that are permanently alarmed and that are connected to the security control-room panels to protect doors that provide access to buildings containing air conditioning equipment. The vendor must also ensure that the air conditioning equipment is located in a secure area that is not accessible to unauthorized personnel, and that the air conditioning system is monitored and maintained to prevent unauthorized access or tampering. The vendor must also have procedures to respond to any alarms or incidents related to the air conditioning system, and to report them to the relevant parties. The vendor must not use security tape, electrical contacts, or physical locks alone, as these may not provide adequate protection or detection of unauthorized access or tampering. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 21-221
NEW QUESTION # 29
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?
- A. Issuing banks
- B. PCI SSC
- C. Payment brands
- D. Assessor
Answer: C
Explanation:
Explanation
The PCI SSC does not enforce compliance, nor does it mandate penalties for non-compliance. Compliance with the PCI Card Production Standards is enforced by the payment brands. The payment brands may have their own compliance programs and may apply penalties or fines to entities that are not compliant or suffer a breach. Therefore, a vendor who wants to know if they will be penalized if their vault is not compliant should ask the payment brands that they work with or are contracted by. References:
Payment Card Industry (PCI) Card Production Security Assessors Program Guide, Version 1.0, April
2019, page 51
PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 62
NEW QUESTION # 30
A vendor discovers that a recent shipment of cards is missing a set. Which of the following responses would you expect in a compliant organization?
- A. An immediate call is made to the issuer and the VPA who, between them, contact law enforcement and put together a joint statement
- B. A report is requested by the issuer, the vendor sends it to them, and the issuer handles the incident with the local police
- C. After an incident review, the VPA, issuer and law enforcement are all notified within 24 hours
- D. The head of security initiates a meeting, and once the VPA approves the messaging, law enforcement is notified in two days
Answer: C
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for card shipment is to ensure that the vendor has an incident response plan in place to handle any card shipment incidents, such as loss, theft, or tampering. The incident response plan should include the following steps1:
The vendor should conduct an incident review to determine the cause and scope of the incident, and document the findings and actions taken.
The vendor should notify the VPA, the issuer, and law enforcement of the incident within 24 hours of discovery, or as soon as possible.
The vendor should cooperate with the VPA, the issuer, and law enforcement in the investigation and resolution of the incident, and provide any evidence or information requested.
The vendor should implement corrective actions to prevent the recurrence of the incident, and report the results to the VPA and the issuer. Therefore, the response that best reflects a compliant organization is option D, which follows the steps of the incident response plan as required by the PCI Card Production Physical Security Requirements. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 6, Requirement 6.2, Page 131
NEW QUESTION # 31
For how long must a vendor retain all applicant and employee background information on file?
- A. For at least 24 months after termination of the contract of employment
- B. For at least 18 months after termination of the contract of employment
- C. It is not a requirement to store this information beyond termination of the contract
- D. For at least 12 months after termination of the contract of employment
Answer: D
Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, one of the administrative requirements for CPSA Companies is to retain all applicant and employee background information on file for at least 12 months after termination of the contract of employment. This is to ensure that the CPSA Company can provide evidence of the background checks performed on the CPSA Employees or other personnel involved in card production and provisioning activities. The background checks should include criminal history, employment history, education verification, and reference checks, and should be conducted at least every two years or upon rehire. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 6.1.2, Page 111
NEW QUESTION # 32
How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?
- A. Every week
- B. Every 3 months
- C. Every day
- D. Every month
Answer: D
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must test all alarms on external doors of the card production and provisioning vendor environment at least every month.
The vendor must also document the results of the tests and retain them for at least one year. The vendor must also have procedures to respond to any alarms or incidents, and to report them to the relevant parties. The vendor must not test the alarms less frequently than every month, as this may compromise the security and integrity of the card production and provisioning vendor environment and increase the risk of unauthorized access or theft. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101
NEW QUESTION # 33
Which of the follow best describes a Technical FAQ?
- A. Use of the Technical FAQs is mandatory, they shall be used during an assessment
- B. Technical FAQs can be submitted to PCI SSC at any time
- C. Technical FAQs only apply to the specific technology as the FAQ defines it
- D. Use of the Technical FAQs is optional, they are considered guidance
Answer: D
Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, Technical FAQs are documents that provide guidance on specific technical topics related to the PCI Card Production Security Standards. Technical FAQs are not mandatory, but they are recommended to be used by CPSA Companies and CPSA Employees during the card production assessment process. Technical FAQs are intended to help clarify the intent and applicability of the PCI Card Production Security Requirements, and to provide examples and best practices for achieving compliance. Technical FAQs are published by the PCI SSC on its website, and are updated periodically based on feedback from the card production industry and the payment brands. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 4.2, Page 81
NEW QUESTION # 34
Which of the following security awareness measures is required for compliance?
- A. Security awareness exams for all personnel
- B. Security posters must be placed in the facility
- C. Annual training on common attack methods
- D. Annual training on use of mantraps
Answer: C
Explanation:
Explanation
According to the PCI Card Production and Provisioning Logical Security Requirements, the vendor must implement a formal security awareness program to make all personnel aware of the importance of card production and provisioning security. The security awareness program must include annual training on common attack methods, such as phishing, social engineering, malware, and ransomware, and how to prevent, detect, and report them. The security awareness program must also include training on the vendor's security policies and procedures, the roles and responsibilities of personnel, the applicable PCI Card Production and Provisioning Security Requirements, and the consequences of non-compliance. The vendor must also require all personnel to acknowledge at least annually that they have read and understood the security policies and procedures. The vendor must not use security posters alone, as they are not sufficient to meet the security awareness program requirements. The vendor may use security awareness exams for all personnel, but they are not mandatory for compliance. The vendor may also train personnel on the use of mantraps, but this is not relevant to the logical security requirements. References: PCI Card Production and Provisioning Logical Security Requirements and Test Procedures v3.0, January 2022, pages 28-291
NEW QUESTION # 35
......
New CPSA_P_New Exam Questions| Real CPSA_P_New Dumps: https://www.exam4labs.com/CPSA_P_New-practice-torrent.html
Get New CPSA_P_New Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1XrV5Kf93lszLJX0gMebR6Za6rqLhizdO