Pass the PCI SSC CPSA Qualification CPSA_P_New Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder’s mobile device. Which of the following best describes the vendor’s activities?

Options:

A.

Card personalization


B.

Host Card Emulation (HCE) provisioning


C.

Secure Element (SE) provisioning


D.

Over-the-air (OTA) provisioning


Questions # 2:

Which of the following statements is true in relation to visitor access badges?

Options:

A.

Each visitor entering the facility must be issued and must visibly wear a disposable ID badge that identifies them as a non-employee


B.

Each visitor entering the facility must wear their issued access badge above waist height


C.

Badges with access-controls must not be issued to visitors


D.

Unissued visitor access badges must be securely stored


Questions # 3:

During an assessment you do a walk-through of bringing card products into the HSA using the goods-tools trap. You act as production staff, using an empty cardboard box as the card products. During the process, the guard escorts you, along with the box, into the pre-press room. What is your conclusion?

Options:

A.

Compliant, because the guard escorted you


B.

Compliant, because the guard ensured that the card product remained under dual control


C.

Not compliant, because an inventory of the card product did not take place prior to entry


D.

Not compliant, because the guard escorted you


Questions # 4:

A vendor is unsure which forms are needed to complete an assessment. Who should they ask?

Options:

A.

Assessor


B.

Issuing banks


C.

Payment brands


D.

PCI SSC


Questions # 5:

Where can misprinted, partially finished cards be shredded?

Options:

A.

In any HSA room approved by the security manager


B.

Either in the HSA printing room or destruction room


C.

Only in the HSA destruction room


D.

Either in the HSA destruction room or a loading bay that meets all requirements of a destruction room


Questions # 6:

If a vendor plans to terminate an employee, which of these must be done?

Options:

A.

The employee must be escorted from the premises immediately


B.

The employee's locker and desk must be searched prior to termination


C.

The Human Resources department must be notified prior to termination


D.

The security manager must be notified in writing prior to termination


Questions # 7:

For how long must a vendor retain all applicant and employee background information on file?

Options:

A.

For at least 12 months after termination of the contract of employment


B.

For at least 18 months after termination of the contract of employment


C.

For at least 24 months after termination of the contract of employment


D.

It is not a requirement to store this information beyond termination of the contract


Questions # 8:

Which of the following personnel changes must result in the vendor notifying the Vendor Program Administration (VPA)?

Options:

A.

Adding additional rights to someone’s role to give them access to the mam production vault


B.

Any change to a role that directly affects the security of card products and related components


C.

Hiring someone that will directly interact with the card issuers


D.

Promoting someone to senior management level


Questions # 9:

A vendor’s HSA access is enforced by a security turnstile they have a logical access-control system that ensures anti pass-back. The device is functioning correctly. When must the status of the access change?

Options:

A.

Only when an unauthorised badge is presented


B.

Only when the person has successfully completed the access cycle


C.

Upon initial entry of the person into the device, prior to completion of the access cycle


D.

Upon initial presentation of an authorised badge, prior to completion of the access cycle


Questions # 10:

The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?

Options:

A.

If the local police have not been issued with an exterior key. they will not be able to investigate the cause of the alarm and reset it


B.

During working hours, the alarm should be managed in the security control room, or by a central monitoring service


C.

If the local police receive too many false-positive alerts, they may not respond within 15 minutes of the alarm


D.

During busy times, the local police may not be able to respond


Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions