
Latest PCI CPSA_P_New Dumps for success in Actual Exam May-2024]
Realistic CPSA_P_New 100% Pass Guaranteed Download Exam Q&A
NEW QUESTION # 26
During an assessment you ask to see employee records for employees with access to the HSA. The records include information about the screening process, including background information from the employee application process. The oldest background Information that is available is for an employee that left the vendor (terminated their contract) one year previously. You note this as non-compliant, why?
- A. Employee information, including background checks, must be stored for at least seven years
- B. Employee information must be securely destroyed (e.g. securely wiped) within 2 years (after termination of contract)
- C. The vendor must retain the background information for at least 18 months after termination of contract
- D. The vendor must only retain background information for all current employees, not for those that have been terminated
Answer: B
Explanation:
Explanation
According to the PCI Card Production Logical Security Requirements, the vendor must securely destroy all employee information, including background checks, within two years of the employee's termination of contract. This is to prevent unauthorized access to sensitive employee data and to comply with the PCI DSS requirement 3.1, which states that cardholder data must not be stored longer than necessary. The vendor must also have a documented policy and procedure for the secure destruction of employee information, and must maintain a log of all destruction activities. References:
PCI Card Production Logical Security Requirements, v2.0, April 2019, page 19, requirement 6.1.1 PCI DSS, v3.2.1, May 2018, page 25, requirement 3.1
NEW QUESTION # 27
To liberate a person detected inside of the inner shipping delivery room and stop the alarm, the software monitoring the access-control system must only allow the opening of which door?
- A. The last activated door
- B. The internal facing door
- C. The external facing door
- D. The least secure door
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must have a secure inner shipping delivery room that is equipped with an alarm system and an access-control system. The alarm system must be triggered when any door of the inner shipping delivery room is opened without proper authorization. The access-control system must only allow the opening of the last activated door to liberate a person detected inside of the inner shipping delivery room and stop the alarm. This is to prevent unauthorized access or exit from the inner shipping delivery room, and to ensure that only one door can be opened at a time. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 18-191
NEW QUESTION # 28
A vendor is unsure which forms are needed to complete an assessment. Who should they ask?
- A. PCI SSC
- B. Payment brands
- C. Issuing banks
- D. Assessor
Answer: D
Explanation:
Explanation
The assessor is the person who conducts the PCI Card Production Security Assessment and prepares the Card Production Report on Compliance (ROC) and the Card Production Attestation of Compliance (AOC). The assessor should be familiar with the forms that are needed to complete an assessment and provide guidance to the vendor on how to fill them out. The assessor should also ensure that the forms are consistent with the PCI Card Production Standards and the PCI CPSA Qualification Requirements. The other options are not the best sources of information for the vendor, as they may not be directly involved in the assessment process or have the expertise to advise on the forms. References:
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 81 PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 10 PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 3 PCI Card Production and Provisioning Attestation of Compliance, Version 1.0, April 2019, page 22
NEW QUESTION # 29
For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?
- A. As long as the entity under assessment is a client of the CPSA Company
- B. 3 years
- C. 1 year
- D. Until each applicable payment brand has accepted (and signed off) the ROC and AOC
Answer: B
Explanation:
Explanation
According to the PCI CPSA Program Guide, a CPSA Company must maintain workpapers and technical information obtained during an assessment for a minimum of three years from the date of the assessment. The workpapers and technical information must be stored securely and made available to PCI SSC upon request.
The workpapers and technical information must include, but are not limited to, the following:
The Card Production Report on Compliance (ROC) and the Card Production Attestation of Compliance (AOC) The Card Production Entity's policies and procedures The Card Production Entity's network diagrams and data flow diagrams The results of any testing performed by the CPSA Company or the Card Production Entity The evidence of any remediation actions taken by the Card Production Entity The correspondence between the CPSA Company and the Card Production Entity The correspondence between the CPSA Company and the payment brands The feedback form completed by the Card Production Entity References:
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 111
NEW QUESTION # 30
Who performs regular AQM audits of CPSA companies?
- A. PCI SSC
- B. Vendor
- C. Payment brands
- D. Issuing banks
Answer: A
Explanation:
Explanation
The PCI Security Standards Council (PCI SSC) performs regular Assessor Quality Management (AQM) audits of CPSA companies to ensure that they comply with the PCI CPSA Qualification Requirements and the PCI Card Production Standards. The AQM audits are conducted by PCI SSC staff or authorized third parties, and may include onsite visits, remote reviews, or both. The AQM audits aim to verify the quality and consistency of the CPSA companies' assessment processes, reports, and documentation, as well as their adherence to the PCI SSC Code of Professional Responsibility. The AQM audits may result in corrective actions, sanctions, or revocation of the CPSA company status, depending on the severity and frequency of the non-compliance issues identified. References:
PCI Card Production Security Assessor (CPSA) Qualification Requirements, v1.0, April 2019, page 12, requirement 8.1 PCI Card Production Security Assessor (CPSA) Program Guide, v1.0, April 2019, page 6, section 3.2
NEW QUESTION # 31
For how long must a vendor retain all applicant and employee background information on file?
- A. For at least 12 months after termination of the contract of employment
- B. For at least 18 months after termination of the contract of employment
- C. For at least 24 months after termination of the contract of employment
- D. It is not a requirement to store this information beyond termination of the contract
Answer: A
Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, one of the administrative requirements for CPSA Companies is to retain all applicant and employee background information on file for at least 12 months after termination of the contract of employment. This is to ensure that the CPSA Company can provide evidence of the background checks performed on the CPSA Employees or other personnel involved in card production and provisioning activities. The background checks should include criminal history, employment history, education verification, and reference checks, and should be conducted at least every two years or upon rehire. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 6.1.2, Page 111
NEW QUESTION # 32
Who is required to approve visitor entry to the HSA or cloud-based provisioning environment?
- A. The Security Manager
- B. The Security Manager, Production Manager, and the head of the vendor facility
- C. The head of the vendor facility
- D. Both the Security Manager and the Production Manager
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning - Physical Security Requirements, the Security Manager is the person who is responsible for approving visitor entry to the High Security Area (HSA) or cloud-based provisioning environment. The HSA is the area where card production and provisioning activities take place, such as card manufacturing, personalization, PIN generation and printing, and fulfillment. The cloud-based provisioning environment is the logical equivalent of the HSA for entities that provide over-the-air (OTA) provisioning or host card emulation (HCE) provisioning services. The Security Manager must ensure that visitors have a legitimate business need toenter the HSA or cloud-based provisioning environment, and must authorize their access in advance. The Security Manager must also maintain a visitor log that records the visitor's name, company, date, time, and purpose of visit, as well as the escort's name and signature. The Security Manager must also ensure that visitors are escorted by authorized personnel at all times, and that they wear a distinctive visitor badge. The head of the vendor facility, the Production Manager, or any other person is not required to approve visitor entry to the HSA or cloud-based provisioning environment, unless they are also designated as the Security Manager by the vendor. References:
Payment Card Industry (PCI) Card Production and Provisioning - Physical Security Requirements, Section 3.1.1 and 3.1.2 Payment Card Industry (PCI) Card Production and Provisioning - Glossary of Terms, Abbreviations, and Acronyms, Definitions of Security Manager, High Security Area, Cloud-Based Provisioning Environment, OTA Provisioning, and HCE Provisioning
NEW QUESTION # 33
A vendor receives cardholder information and keys from a bank. The vendor then performs the following:
* Uses its HSM to create keys
* Creates cardholder information specific to each cardholder, including name and PAN
* Formats the data for the hardware that will put it on a card
* Writes it to an encrypted file
Which of the following best describes this process?
- A. Data creation
- B. Manufacture
- C. Data preparation
- D. Pre-personalization
Answer: C
Explanation:
Explanation
Data preparation is the process of creating cardholder data and keys for each card, and formatting them for the hardware that will put them on a card. Data preparation involves the use of an HSM to generate keys and encrypt data, and the creation of an encrypted file that contains the cardholder data and keys. Data preparation is one of the steps in the card production lifecycle, and it precedes the manufacture and personalization of the cards. References:
Card Production Security Assessor (CPSA) Qualification Requirements, v1.0, April 2019, page 10 PCI Card Production Logical Security Requirements, v2.0, April 2019, page 9 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 9
NEW QUESTION # 34
Which of the following principles must be enforce by the HSA Access Control system?
- A. Dual control and dual presence
- B. Dual presence
- C. Dual control
- D. Dual guard entry when required
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the HSA Access Control system must enforce both dual control and dual presence principles. Dual control means that at least two authorized individuals must act together to perform a critical function or access a sensitive area. Dual presence means that at least two authorized individuals must be physically present in the same area at all times. These principles are intended to prevent unauthorized or fraudulent activities by requiring mutual supervision and accountability. Therefore, the HSA Access Control system must ensure that no single individual can enter, exit, or operate within the HSA without the cooperation and the presence of another authorized individual. References:
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
121
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
131
NEW QUESTION # 35
Which of the following statements is true about the facility's non-emergency exits?
- A. They may be left unlocked when a guard is present
- B. They must be configured to prevent staff tailgating
- C. They must be fitted with biometric access-control devices
- D. They must be contact-alarm monitored only when card production activities are taking place
Answer: B
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must ensure that all non-emergency exits are configured to prevent staff tailgating. Tailgating is the act of following someone closely through a door or other entry point without proper authorization. The vendor must use access-control devices, such as turnstiles, mantraps, or biometric readers, to prevent tailgating and unauthorized access or exit. The vendor must also monitor and alarm all non-emergency exits 24/7, and have procedures to respond to any alarms or incidents. The vendor must not leave any non-emergency exits unlocked, even when a guard is present, as this may compromise the security of the facility and the card production andprovisioning materials. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 8-91
NEW QUESTION # 36
Which of these are guards allowed access to?
- A. Loading bays
- B. Audit logs
- C. Physical master keys that provide access to card production or provisioning areas
- D. HSAs
Answer: A
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for contracted guard services is to ensure that they have limited access to card production or provisioning areas, and that they do not have access to HSAs, audit logs, or physical master keys that provide access to card production or provisioning areas. This is to prevent unauthorized access, theft, or misuse of card material or data by the contracted guard service. However, the contracted guard service may have access to loading bays, as long as they are escorted by authorized personnel and do not handle or interfere with card shipments. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section
1.1, Objective 2, Requirement 2.2.1, Page 71
NEW QUESTION # 37
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?
- A. PCI SSC
- B. Assessor
- C. Issuing banks
- D. Payment brands
Answer: D
Explanation:
Explanation
The PCI SSC does not enforce compliance, nor does it mandate penalties for non-compliance. Compliance with the PCI Card Production Standards is enforced by the payment brands. The payment brands may have their own compliance programs and may apply penalties or fines to entities that are not compliant or suffer a breach. Therefore, a vendor who wants to know if they will be penalized if their vault is not compliant should ask the payment brands that they work with or are contracted by. References:
Payment Card Industry (PCI) Card Production Security Assessors Program Guide, Version 1.0, April
2019, page 51
PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 62
NEW QUESTION # 38
In which of the following locations must the CCTV and access control servers be located?
- A. Within the secure server room inside of the HSA
- B. Within a room in the HSA with security controls equivalent to the SCR applied
- C. Within the Security Control Room (SCR)
- D. Within the SCR or a room with equivalent security
Answer: D
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the CCTV and access control servers must be located within the Security Control Room (SCR) or a room with equivalent security. This means that the room must have the same level of physical protection as the SCR, such as locks, alarms, sensors, cameras, and access control devices. The purpose of this requirement is to prevent unauthorized access, tampering, or theft of the servers that store and process sensitive data related to card production and security. References: PCI Card Production Physical Security Requirements, v2.0, April 2019, page 16
NEW QUESTION # 39
The receptionist responsible for the entrance and departure of visitors must have which of the following?
- A. A means of communicating directly with the visitor while on the premises
- B. An unobstructed view of the reception area at all times
- C. A shredder for the destruction of disposable visitor badges
- D. A constant, open communication channel with a guard
Answer: B
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the receptionist responsible for the entrance and departure of visitors must have an unobstructed view of the reception area at all times. This is to ensure that the receptionist can monitor and control the access of visitors, and to prevent any unauthorized entry or exit of personnel or materials. The receptionist must also have a means of verifying the identity of visitors, such as a photo ID or a visitor log, and a means of issuing and collecting visitor badges, such as a badge printer or a badge holder. The receptionist must also have a means of communicating with the security personnel or the security control room, such as a phone or an intercom, in case of any emergency or suspicious activity. References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 21, requirement 5.3.1 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 22, requirement 5.3.2 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 23, requirement 5.3.3
NEW QUESTION # 40
A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder's mobile device. Which of the following best describes the vendor's activities?
- A. Over-the-air (OTA) provisioning
- B. Card personalization
- C. Secure Element (SE) provisioning
- D. Host Card Emulation (HCE) provisioning
Answer: D
Explanation:
Explanation
Host Card Emulation (HCE) provisioning is the process of creating and storing cardholder data in a virtual secure element hosted in a remote server, and generating a payment token that can be used by a mobile device to perform a contactless transaction. HCE provisioning is one of the methods of cloud-based provisioning, which does not require the use of a physical secure element on the mobile device. HCE provisioning is different from Secure Element (SE) provisioning, which involves loading cardholder data into a physical secure element embedded or attached to the mobile device. HCE provisioning is also different from Over-the-air (OTA) provisioning, which involves transmitting cardholder data from a remote server to a physical secure element on the mobiledevice using a wireless communication channel. In this scenario, the vendor hosts virtual secure elements holding cardholder information in their data center, and creates a payment token that is sent to the cardholder's mobile device. This best describes the vendor's activities as HCE provisioning. References:
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 8, section
1.3
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 9, section
1.4
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 10, section 1.5 PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 43, Appendix A: Applicability of Requirements
NEW QUESTION # 41
Where can misprinted, partially finished cards be shredded?
- A. Only in the HSA destruction room
- B. Either in the HSA destruction room or a loading bay that meets all requirements of a destruction room
- C. In any HSA room approved by the security manager
- D. Either in the HSA printing room or destruction room
Answer: A
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for card destruction is to ensure that misprinted, partially finished, or rejected cards are shredded only in the HSA destruction room. This is to prevent unauthorized access, theft, or misuse of the cards, which may contain sensitive data or features. The HSA destruction room should have adequate security measures, such as locks, alarms, cameras, etc., to protect the cards until they are shredded. The shredding process should render the cards unusable and unrecognizable, and the shredded material should be disposed of securely. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 5, Requirement 5.1.1, Page 111
NEW QUESTION # 42
A vendor has a list of pre-approved third parties which may be granted access to the facility. Under what circumstances can other third-parties be granted access?
- A. When no card production activities are taking place
- B. When they are approved by the physical security manager or senior management
- C. None, only people on the pre-approved list may enter
- D. When the third party s liability insurance covers the risk
Answer: B
Explanation:
Explanation
According to the PCI Card Production Logical Security Requirements, vendors must have a list of pre-approved third parties that are authorized to access the facility and the systems involved in card production. However, other third parties may be granted access under exceptional circumstances, such as emergency repairs or maintenance, provided that they are approved by the physical security manager or senior management. The vendor must also ensure that the third parties comply with the security policies and procedures, and that their access is logged and monitored. References: PCI Card Production Logical Security Requirements, v2.0, April 2019, page 13
NEW QUESTION # 43
......
Accurate CPSA_P_New Answers 365 Days Free Updates: https://www.passexamdumps.com/CPSA_P_New-valid-exam-dumps.html
CPSA_P_New DUMPS Q&As with Explanations Verified & Correct Answers: https://drive.google.com/open?id=1Ef5V3geklf-QXyu8de9xCuzFCeqHH08f
