
Printable & Easy to Use CPSA_P_New Dumps 100% Same Q&A In Your Real Exam
CPSA_P_New Practice Test Give You First Time Success with 100% Money Back Guarantee!
NEW QUESTION # 11
For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?
- A. 3 years
- B. 1 year
- C. Until each applicable payment brand has accepted (and signed off) the ROC and AOC
- D. As long as the entity under assessment is a client of the CPSA Company
Answer: A
Explanation:
Explanation
According to the PCI CPSA Program Guide, a CPSA Company must maintain workpapers and technical information obtained during an assessment for a minimum of three years from the date of the assessment. The workpapers and technical information must be stored securely and made available to PCI SSC upon request.
The workpapers and technical information must include, but are not limited to, the following:
The Card Production Report on Compliance (ROC) and the Card Production Attestation of Compliance (AOC) The Card Production Entity's policies and procedures The Card Production Entity's network diagrams and data flow diagrams The results of any testing performed by the CPSA Company or the Card Production Entity The evidence of any remediation actions taken by the Card Production Entity The correspondence between the CPSA Company and the Card Production Entity The correspondence between the CPSA Company and the payment brands The feedback form completed by the Card Production Entity References:
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 111
NEW QUESTION # 12
The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?
- A. If the local police receive too many false-positive alerts, they may not respond within 15 minutes of the alarm
- B. If the local police have not been issued with an exterior key. they will not be able to investigate the cause of the alarm and reset it
- C. During busy times, the local police may not be able to respond
- D. During working hours, the alarm should be managed in the security control room, or by a central monitoring service
Answer: D
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must have an alarm system that monitors and detects unauthorized access to the card production and provisioning facilities, and that alerts the security control room or a central monitoring service. The alarm system must also be able to identify the location and cause of the alarm, and allow authorized personnel to reset it. The alarm system must be operational 24/7, and must be tested at least annually. The vendor must also have procedures to respond to alarms and incidents, and to report them to the relevant parties. If the alarm system does not send alerts to the security control room, or a central monitoring service, during working hours, the vendor may not be able to comply with these requirements, and may not be able to prevent, detect, or respond to unauthorized access or security breaches. This may cause a problem for their assessment, as they may not meet the PCI Card Production and Provisioning Physical Security Requirements. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101
NEW QUESTION # 13
Where can misprinted, partially finished cards be shredded?
- A. Either in the HSA destruction room or a loading bay that meets all requirements of a destruction room
- B. Either in the HSA printing room or destruction room
- C. In any HSA room approved by the security manager
- D. Only in the HSA destruction room
Answer: D
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for card destruction is to ensure that misprinted, partially finished, or rejected cards are shredded only in the HSA destruction room. This is to prevent unauthorized access, theft, or misuse of the cards, which may contain sensitive data or features. The HSA destruction room should have adequate security measures, such as locks, alarms, cameras, etc., to protect the cards until they are shredded. The shredding process should render the cards unusable and unrecognizable, and the shredded material should be disposed of securely. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 5, Requirement 5.1.1, Page 111
NEW QUESTION # 14
In relation to guards, which of the following must the vendor ensure?
- A. A clear segregation of duties is maintained between guard and reception related job functions
- B. There is always at least one guard in the HSA and one guard in the security control room at all times
- C. There is always at least one guard on-site, including outside of working hours, to monitor security systems and premises
- D. A clear segregation of duties is maintained between production staff and guards
Answer: A
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the vendor must ensure that a clear segregation of duties is maintained between guard and reception related job functions. This is to prevent any conflict of interest or collusion that could compromise the security of the card production and provisioning processes or the cardholder data. The vendor must also ensure that the guards are adequately trained, supervised, and evaluated, and that they follow the security policies and procedures established by the vendor.
The vendor must also have a documented policy and procedure for the selection, hiring, and termination of guards, and must maintain a log of all guard activities. References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 24, requirement 6.1.1 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 25, requirement 6.1.2 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 26, requirement 6.1.3 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 27, requirement 6.1.4
NEW QUESTION # 15
A cardholder wants to make purchases using their phone, so they have their cardholder information programmed into their SIM card using their mobile phone provider. Which of the following best describes this system?
- A. Host Card Emulation (HCE) provisioning
- B. Over-the-air (OTA) provisioning
- C. Secure Element (SE) provisioning
- D. Card personalization
Answer: C
Explanation:
Explanation
According to the PCI Card Production and Provisioning Logical Security Requirements, Secure Element (SE) provisioning is the process of adding cardholder account information to a secure element on a mobile device via an over-the-air or over-the-internet communication channel. A secure element is a tamper-resistant platform that can securely host applications and their confidential and cryptographic data. A SIM card is an example of a secure element that can be used for mobile payments. SE provisioning is different from Host Card Emulation (HCE) provisioning, which is the process of adding cardholder account information to a cloud-based server that emulates a secure element on a mobile device. SE provisioning is also different from card personalization, which is the process of adding cardholder account information to a physical card.
Over-the-air (OTA) provisioning is a generic term that can refer to either SE or HCE provisioning, depending on the type of mobile payment system used. References: PCI Card Production and Provisioning Logical Security Requirements and Test Procedures v3.0, January 2022, pages 6-71
NEW QUESTION # 16
Which of the following statements is true about the facility's non-emergency exits?
- A. They may be left unlocked when a guard is present
- B. They must be contact-alarm monitored only when card production activities are taking place
- C. They must be configured to prevent staff tailgating
- D. They must be fitted with biometric access-control devices
Answer: C
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must ensure that all non-emergency exits are configured to prevent staff tailgating. Tailgating is the act of following someone closely through a door or other entry point without proper authorization. The vendor must use access-control devices, such as turnstiles, mantraps, or biometric readers, to prevent tailgating and unauthorized access or exit. The vendor must also monitor and alarm all non-emergency exits 24/7, and have procedures to respond to any alarms or incidents. The vendor must not leave any non-emergency exits unlocked, even when a guard is present, as this may compromise the security of the facility and the card production andprovisioning materials. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 8-91
NEW QUESTION # 17
Who is required to approve visitor entry to the HSA or cloud-based provisioning environment?
- A. The Security Manager
- B. The Security Manager, Production Manager, and the head of the vendor facility
- C. Both the Security Manager and the Production Manager
- D. The head of the vendor facility
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning - Physical Security Requirements, the Security Manager is the person who is responsible for approving visitor entry to the High Security Area (HSA) or cloud-based provisioning environment. The HSA is the area where card production and provisioning activities take place, such as card manufacturing, personalization, PIN generation and printing, and fulfillment. The cloud-based provisioning environment is the logical equivalent of the HSA for entities that provide over-the-air (OTA) provisioning or host card emulation (HCE) provisioning services. The Security Manager must ensure that visitors have a legitimate business need toenter the HSA or cloud-based provisioning environment, and must authorize their access in advance. The Security Manager must also maintain a visitor log that records the visitor's name, company, date, time, and purpose of visit, as well as the escort's name and signature. The Security Manager must also ensure that visitors are escorted by authorized personnel at all times, and that they wear a distinctive visitor badge. The head of the vendor facility, the Production Manager, or any other person is not required to approve visitor entry to the HSA or cloud-based provisioning environment, unless they are also designated as the Security Manager by the vendor. References:
Payment Card Industry (PCI) Card Production and Provisioning - Physical Security Requirements, Section 3.1.1 and 3.1.2 Payment Card Industry (PCI) Card Production and Provisioning - Glossary of Terms, Abbreviations, and Acronyms, Definitions of Security Manager, High Security Area, Cloud-Based Provisioning Environment, OTA Provisioning, and HCE Provisioning
NEW QUESTION # 18
You wish to check that you are using the most current version of the Card Production requirements. What should you do?
- A. Have the CPSA Company's point of contact request the document
- B. View it directly via PCI SSC Assessor Portal
- C. Download it from PCI SSC's Document Library
- D. Email a request for the document to PCI SSC
Answer: C
Explanation:
Explanation
The best way to check that you are using the most current version of the Card Production requirements is to download it from PCI SSC's Document Library. The PCI SSC's Document Library is a repository of all the PCI standards, guidelines, and supporting documents that are developed and maintained by the PCI SSC. The Document Library is accessible to the public and provides the latest versions of the documents, as well as the summary of changes and the effective dates. The Document Library also allows you to search, filter, and sort the documents by category, type, date, and keyword. Therefore, by downloading the Card Production requirements from the Document Library, you can ensure that you have the most up-to-date and authoritative version of the requirements. The other options are not the best ways to check the version of the Card Production requirements, as they may not be reliable, efficient, or available. Having the CPSA Company's point of contact request the document may not be feasible, as the point of contact may not have the authority, the access, or the time to do so. Emailing a request for the document to PCI SSC may not be effective, as the PCI SSC may not respond promptly or provide the document in the format that you need. Viewing the document directly via PCI SSC Assessor Portal may not be possible, as the Assessor Portal may not have the latest version of the document or may require a login credential that you do not have. References:
PCI SSC Document Library1
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 52
NEW QUESTION # 19
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?
- A. Assessor
- B. PCI SSC
- C. Issuing banks
- D. Payment brands
Answer: D
Explanation:
Explanation
The PCI SSC does not enforce compliance, nor does it mandate penalties for non-compliance. Compliance with the PCI Card Production Standards is enforced by the payment brands. The payment brands may have their own compliance programs and may apply penalties or fines to entities that are not compliant or suffer a breach. Therefore, a vendor who wants to know if they will be penalized if their vault is not compliant should ask the payment brands that they work with or are contracted by. References:
Payment Card Industry (PCI) Card Production Security Assessors Program Guide, Version 1.0, April
2019, page 51
PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 62
NEW QUESTION # 20
A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder's mobile device. Which of the following best describes the vendor's activities?
- A. Host Card Emulation (HCE) provisioning
- B. Over-the-air (OTA) provisioning
- C. Secure Element (SE) provisioning
- D. Card personalization
Answer: A
Explanation:
Explanation
Host Card Emulation (HCE) provisioning is the process of creating and storing cardholder data in a virtual secure element hosted in a remote server, and generating a payment token that can be used by a mobile device to perform a contactless transaction. HCE provisioning is one of the methods of cloud-based provisioning, which does not require the use of a physical secure element on the mobile device. HCE provisioning is different from Secure Element (SE) provisioning, which involves loading cardholder data into a physical secure element embedded or attached to the mobile device. HCE provisioning is also different from Over-the-air (OTA) provisioning, which involves transmitting cardholder data from a remote server to a physical secure element on the mobiledevice using a wireless communication channel. In this scenario, the vendor hosts virtual secure elements holding cardholder information in their data center, and creates a payment token that is sent to the cardholder's mobile device. This best describes the vendor's activities as HCE provisioning. References:
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 8, section
1.3
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 9, section
1.4
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 10, section 1.5 PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 43, Appendix A: Applicability of Requirements
NEW QUESTION # 21
For each requirement listed in a ROC, which types of findings must have a full narrative response?
- A. All types of findings
- B. Non-compliant findings only
- C. New or Closed findings only
- D. All types except Not Applicable findings
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Template for Report on Compliance, for each requirement listed in a ROC, all types of findings must have a full narrative response. A finding is the result of the assessor's evaluation of the entity's compliance status for each requirement. The types of findings are:
Compliant: The entity meets the requirement as stated in the PCI Card Production Standards.
Non-Compliant: The entity does not meet the requirement as stated in the PCI Card Production Standards.
Not Applicable: The requirement does not apply to the entity's environment or operations.
Not Tested: The requirement was not tested by the assessor for a valid reason.
New: The entity has implemented a new process, system, or control that affects the requirement since the last assessment.
Closed: The entity has remediated a previous non-compliant finding and has provided sufficient evidence to the assessor.
A full narrative response is a detailed explanation of the finding, including the following elements:
The scope of testing performed by the assessor to evaluate the requirement The testing procedures and tools used by the assessor The sampling methodology and rationale used by the assessor The evidence collected and reviewed by the assessor The observations and conclusions made by the assessor The recommendations and remediation actions (if any) suggested by the assessor A full narrative response is required for all types of findings to provide a clear and comprehensive documentation of the entity's compliance status and to support the assessor's professional judgment and opinion. A full narrative response also helps the payment brands, the PCI SSC, and the entity itself to understand the entity's environment, risks, and controls, and to verify the accuracy and validity of the assessment. References:
PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 4 PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 5 PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 6
NEW QUESTION # 22
Under which circumstances may boxes containing card stock remain unsealed within the vault?
- A. Where the stock from those boxes will be pulled once at the beginning of production
- B. This is never permitted
- C. Where stock from those boxes will be pulled multiple times per day
- D. Always, as long as an accurate inventory is being maintained
Answer: B
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must ensure that all boxes containing card stock are sealed with tamper-evident tape or labels when stored in the vault. The vendor must also maintain a log of all card stock movements in and out of the vault, and reconcile the card stock inventory at least daily. The vendor must not leave any boxes containing card stock unsealed within the vault, regardless of the frequency of stock pulling, as this may compromise the security and integrity of the card stock and increase the risk of unauthorized access or theft. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages
12-131
NEW QUESTION # 23
John works for ACME Inc Personalizers. an organization that personalizes payment cards as well as printing the corresponding PIN mailers for distribution directly to the cardholder. Which of the following statements is true?
- A. If John is involved in card personalization then he must not be involved in the printing of the corresponding PINs
- B. If John is involved in card personalization, then he must never be involved in PIN printing
- C. If John is involved in card personalization, then he must never be involved in the card shipment process
- D. If John is involved in PIN printing, then he must never be involved in the card shipment process
Answer: B
Explanation:
Explanation
According to the PCI Card Production and Provisioning - Logical Security Requirements, there must be a clear segregation of duties between the staff involved in different card production and provisioning activities, such as card personalization, PIN generation and printing, and card fulfillment. This is to prevent any unauthorized access, modification, or disclosure of sensitive cardholder data and to ensure the integrity and confidentiality of the card production process. Therefore, if John is involved in card personalization, which is the process of transferring cardholder information to a payment card, then he must never be involved in PIN printing, which is the process of printing the personal identification number associated with the cardholder account on a mailer. This way, John cannot link the cardholder data on the card with the PIN on the mailer, and cannot compromise the security of the cardholder authentication. The other statements are not true, as there is no requirement that prohibits John from being involved in the card shipment process, as long as he does not have access to both the card and the PIN mailer at the same time. References:
Payment Card Industry (PCI) Card Production and Provisioning - Logical Security Requirements, Section 2.1.1 and 2.1.2 Payment Card Industry (PCI) Card Production and Provisioning - Glossary of Terms, Abbreviations, and Acronyms, Definitions of Card Personalization and PIN Printing
NEW QUESTION # 24
The receptionist responsible for the entrance and departure of visitors must have which of the following?
- A. A constant, open communication channel with a guard
- B. A means of communicating directly with the visitor while on the premises
- C. An unobstructed view of the reception area at all times
- D. A shredder for the destruction of disposable visitor badges
Answer: C
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the receptionist responsible for the entrance and departure of visitors must have an unobstructed view of the reception area at all times. This is to ensure that the receptionist can monitor and control the access of visitors, and to prevent any unauthorized entry or exit of personnel or materials. The receptionist must also have a means of verifying the identity of visitors, such as a photo ID or a visitor log, and a means of issuing and collecting visitor badges, such as a badge printer or a badge holder. The receptionist must also have a means of communicating with the security personnel or the security control room, such as a phone or an intercom, in case of any emergency or suspicious activity. References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 21, requirement 5.3.1 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 22, requirement 5.3.2 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 23, requirement 5.3.3
NEW QUESTION # 25
How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?
- A. Every 3 months
- B. Every month
- C. Every week
- D. Every day
Answer: B
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must test all alarms on external doors of the card production and provisioning vendor environment at least every month.
The vendor must also document the results of the tests and retain them for at least one year. The vendor must also have procedures to respond to any alarms or incidents, and to report them to the relevant parties. The vendor must not test the alarms less frequently than every month, as this may compromise the security and integrity of the card production and provisioning vendor environment and increase the risk of unauthorized access or theft. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101
NEW QUESTION # 26
......
Fully Updated Free Actual PCI CPSA_P_New Exam Questions: https://www.exams4collection.com/CPSA_P_New-latest-braindumps.html
All Obstacles During CPSA_P_New Exam Preparation with CPSA_P_New Real Test Questions: https://drive.google.com/open?id=1-O2p-dCRFiCo0jrDLObOOrxa1tgcbs1V
