Best PCI CPSA_P_New Exam Practice Material Updated on Apr 02, 2024 [Q14-Q32]

Share

Best PCI CPSA_P_New Exam Practice Material Updated on Apr 02, 2024

New CPSA_P_New Actual Exam Dumps,  PCI Practice Test

NEW QUESTION # 14
To liberate a person detected inside of the inner shipping delivery room and stop the alarm, the software monitoring the access-control system must only allow the opening of which door?

  • A. The last activated door
  • B. The least secure door
  • C. The external facing door
  • D. The internal facing door

Answer: A

Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must have a secure inner shipping delivery room that is equipped with an alarm system and an access-control system. The alarm system must be triggered when any door of the inner shipping delivery room is opened without proper authorization. The access-control system must only allow the opening of the last activated door to liberate a person detected inside of the inner shipping delivery room and stop the alarm. This is to prevent unauthorized access or exit from the inner shipping delivery room, and to ensure that only one door can be opened at a time. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 18-191


NEW QUESTION # 15
Which of the following security awareness measures is required for compliance?

  • A. Annual training on use of mantraps
  • B. Annual training on common attack methods
  • C. Security posters must be placed in the facility
  • D. Security awareness exams for all personnel

Answer: B

Explanation:
Explanation
According to the PCI Card Production and Provisioning Logical Security Requirements, the vendor must implement a formal security awareness program to make all personnel aware of the importance of card production and provisioning security. The security awareness program must include annual training on common attack methods, such as phishing, social engineering, malware, and ransomware, and how to prevent, detect, and report them. The security awareness program must also include training on the vendor's security policies and procedures, the roles and responsibilities of personnel, the applicable PCI Card Production and Provisioning Security Requirements, and the consequences of non-compliance. The vendor must also require all personnel to acknowledge at least annually that they have read and understood the security policies and procedures. The vendor must not use security posters alone, as they are not sufficient to meet the security awareness program requirements. The vendor may use security awareness exams for all personnel, but they are not mandatory for compliance. The vendor may also train personnel on the use of mantraps, but this is not relevant to the logical security requirements. References: PCI Card Production and Provisioning Logical Security Requirements and Test Procedures v3.0, January 2022, pages 28-291


NEW QUESTION # 16
A vendor is unsure which forms are needed to complete an assessment. Who should they ask?

  • A. Payment brands
  • B. PCI SSC
  • C. Issuing banks
  • D. Assessor

Answer: D


NEW QUESTION # 17
How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?

  • A. Every week
  • B. Every day
  • C. Every 3 months
  • D. Every month

Answer: D

Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must test all alarms on external doors of the card production and provisioning vendor environment at least every month.
The vendor must also document the results of the tests and retain them for at least one year. The vendor must also have procedures to respond to any alarms or incidents, and to report them to the relevant parties. The vendor must not test the alarms less frequently than every month, as this may compromise the security and integrity of the card production and provisioning vendor environment and increase the risk of unauthorized access or theft. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101


NEW QUESTION # 18
You wish to check that you are using the most current version of the Card Production requirements. What should you do?

  • A. Have the CPSA Company's point of contact request the document
  • B. Download it from PCI SSC's Document Library
  • C. View it directly via PCI SSC Assessor Portal
  • D. Email a request for the document to PCI SSC

Answer: B

Explanation:
Explanation
The best way to check that you are using the most current version of the Card Production requirements is to download it from PCI SSC's Document Library. The PCI SSC's Document Library is a repository of all the PCI standards, guidelines, and supporting documents that are developed and maintained by the PCI SSC. The Document Library is accessible to the public and provides the latest versions of the documents, as well as the summary of changes and the effective dates. The Document Library also allows you to search, filter, and sort the documents by category, type, date, and keyword. Therefore, by downloading the Card Production requirements from the Document Library, you can ensure that you have the most up-to-date and authoritative version of the requirements. The other options are not the best ways to check the version of the Card Production requirements, as they may not be reliable, efficient, or available. Having the CPSA Company's point of contact request the document may not be feasible, as the point of contact may not have the authority, the access, or the time to do so. Emailing a request for the document to PCI SSC may not be effective, as the PCI SSC may not respond promptly or provide the document in the format that you need. Viewing the document directly via PCI SSC Assessor Portal may not be possible, as the Assessor Portal may not have the latest version of the document or may require a login credential that you do not have. References:
PCI SSC Document Library1
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 52


NEW QUESTION # 19
The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?

  • A. If the local police have not been issued with an exterior key. they will not be able to investigate the cause of the alarm and reset it
  • B. During busy times, the local police may not be able to respond
  • C. If the local police receive too many false-positive alerts, they may not respond within 15 minutes of the alarm
  • D. During working hours, the alarm should be managed in the security control room, or by a central monitoring service

Answer: D

Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must have an alarm system that monitors and detects unauthorized access to the card production and provisioning facilities, and that alerts the security control room or a central monitoring service. The alarm system must also be able to identify the location and cause of the alarm, and allow authorized personnel to reset it. The alarm system must be operational 24/7, and must be tested at least annually. The vendor must also have procedures to respond to alarms and incidents, and to report them to the relevant parties. If the alarm system does not send alerts to the security control room, or a central monitoring service, during working hours, the vendor may not be able to comply with these requirements, and may not be able to prevent, detect, or respond to unauthorized access or security breaches. This may cause a problem for their assessment, as they may not meet the PCI Card Production and Provisioning Physical Security Requirements. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101


NEW QUESTION # 20
A vendor is unsure which forms are needed to complete an assessment. Who should they ask?

  • A. Payment brands
  • B. PCI SSC
  • C. Issuing banks
  • D. Assessor

Answer: D

Explanation:
Explanation
The assessor is the person who conducts the PCI Card Production Security Assessment and prepares the Card Production Report on Compliance (ROC) and the Card Production Attestation of Compliance (AOC). The assessor should be familiar with the forms that are needed to complete an assessment and provide guidance to the vendor on how to fill them out. The assessor should also ensure that the forms are consistent with the PCI Card Production Standards and the PCI CPSA Qualification Requirements. The other options are not the best sources of information for the vendor, as they may not be directly involved in the assessment process or have the expertise to advise on the forms. References:
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 81 PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 10 PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 3 PCI Card Production and Provisioning Attestation of Compliance, Version 1.0, April 2019, page 22


NEW QUESTION # 21
Which of the following must every assessor do to maintain their CPSA certification?

  • A. Earn and document at least 20 hours of Continuing Professional Education (CPE) over 3 years
  • B. Complete annual requalification training or complete 3 assessments for different facilities each year
  • C. Earn an additional professional certification from List A or B of the Qualification Requirements (QRs)
  • D. Submit evidence of internal training in a relevant area (as per the QRs)

Answer: B

Explanation:
Explanation
According to the Card Production Security Assessor (CPSA) Qualification Requirements, CPSAs must maintain their qualification status by either completing the annual requalification training provided by PCI SSC or performing at least three (3) PCI Card Production Assessments for different facilities over the previous one-year period. This ensures that CPSAs remain current with technical and industry changes and demonstrate professionalism. References: Card Production Security Assessor (CPSA) Qualification Requirements, v1.1, March 2022, page 10


NEW QUESTION # 22
A vendor discovers that a recent shipment of cards is missing a set. Which of the following responses would you expect in a compliant organization?

  • A. After an incident review, the VPA, issuer and law enforcement are all notified within 24 hours
  • B. A report is requested by the issuer, the vendor sends it to them, and the issuer handles the incident with the local police
  • C. An immediate call is made to the issuer and the VPA who, between them, contact law enforcement and put together a joint statement
  • D. The head of security initiates a meeting, and once the VPA approves the messaging, law enforcement is notified in two days

Answer: A

Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for card shipment is to ensure that the vendor has an incident response plan in place to handle any card shipment incidents, such as loss, theft, or tampering. The incident response plan should include the following steps1:
The vendor should conduct an incident review to determine the cause and scope of the incident, and document the findings and actions taken.
The vendor should notify the VPA, the issuer, and law enforcement of the incident within 24 hours of discovery, or as soon as possible.
The vendor should cooperate with the VPA, the issuer, and law enforcement in the investigation and resolution of the incident, and provide any evidence or information requested.
The vendor should implement corrective actions to prevent the recurrence of the incident, and report the results to the VPA and the issuer. Therefore, the response that best reflects a compliant organization is option D, which follows the steps of the incident response plan as required by the PCI Card Production Physical Security Requirements. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 6, Requirement 6.2, Page 131


NEW QUESTION # 23
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?

  • A. Assessor
  • B. PCI SSC
  • C. Payment brands
  • D. Issuing banks

Answer: C

Explanation:
Explanation
The PCI SSC does not enforce compliance, nor does it mandate penalties for non-compliance. Compliance with the PCI Card Production Standards is enforced by the payment brands. The payment brands may have their own compliance programs and may apply penalties or fines to entities that are not compliant or suffer a breach. Therefore, a vendor who wants to know if they will be penalized if their vault is not compliant should ask the payment brands that they work with or are contracted by. References:
Payment Card Industry (PCI) Card Production Security Assessors Program Guide, Version 1.0, April
2019, page 51
PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 62


NEW QUESTION # 24
Which of these are guards allowed access to?

  • A. Audit logs
  • B. HSAs
  • C. Loading bays
  • D. Physical master keys that provide access to card production or provisioning areas

Answer: C

Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for contracted guard services is to ensure that they have limited access to card production or provisioning areas, and that they do not have access to HSAs, audit logs, or physical master keys that provide access to card production or provisioning areas. This is to prevent unauthorized access, theft, or misuse of card material or data by the contracted guard service. However, the contracted guard service may have access to loading bays, as long as they are escorted by authorized personnel and do not handle or interfere with card shipments. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section
1.1, Objective 2, Requirement 2.2.1, Page 71


NEW QUESTION # 25
A card production vendor employs a contracted guard service from an outside source. What is one of the responsibilities of the contracted service?

  • A. Register their service with the VPA
  • B. Provide only certified guards
  • C. Undergo their own Card Production assessment and provide evidence of a passing result
  • D. Maintain their own liability insurance in case of losses to card material

Answer: D

Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for contracted guard services is to ensure that they maintain their own liability insurance in case of losses to card material. This is to protect the card production vendor from any financial losses or damages caused by the contracted guard service, such as negligence,theft, or misuse of card material. The contracted guard service should also comply with the vendor's security policies and procedures, and undergo background checks and security training. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 2, Requirement 2.2.1, Page 71


NEW QUESTION # 26
For how long must a vendor retain all applicant and employee background information on file?

  • A. For at least 12 months after termination of the contract of employment
  • B. For at least 18 months after termination of the contract of employment
  • C. It is not a requirement to store this information beyond termination of the contract
  • D. For at least 24 months after termination of the contract of employment

Answer: A

Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, one of the administrative requirements for CPSA Companies is to retain all applicant and employee background information on file for at least 12 months after termination of the contract of employment. This is to ensure that the CPSA Company can provide evidence of the background checks performed on the CPSA Employees or other personnel involved in card production and provisioning activities. The background checks should include criminal history, employment history, education verification, and reference checks, and should be conducted at least every two years or upon rehire. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 6.1.2, Page 111


NEW QUESTION # 27
Which of these is a requirement of the security control room?

  • A. Access must be monitored in real-time
  • B. Access must be controlled by a physical key (in case of power-failure)
  • C. Dual-control must be used to grant entry
  • D. At least one guard must be present at all times

Answer: A

Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the security control room is the area where the security systems are monitored and controlled. The requirement for the security control room is that access must be monitoredin real-time by a guard or an automated system that alerts the guard of any unauthorized access attempts. The security control room must also be protected by physical barriers and access control devices that prevent unauthorized entry. The other options are not requirements of the security control room, although they may be implemented as additional security measures. References:
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
151
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
161


NEW QUESTION # 28
Which document describes the results of an assessment, and is signed by both the assessor and the vendor executive officer?

  • A. Letter of Approval (LOA)
  • B. Security Assessment Questionnaire (SAQ)
  • C. Attestation of Compliance (AOC)
  • D. Report on Compliance (ROC)

Answer: C

Explanation:
Explanation
The Attestation of Compliance (AOC) is the document that describes the results of a PCI Card Production Assessment, and is signed by both the CPSA and the vendor executive officer. The AOC is a summary of the findings and conclusions of the assessment, and indicates whether the vendor meets the PCI Card Production Logical Security Requirements and/or the PCI Card Production Physical Security Requirements. The AOC must be completed using the template provided by PCI SSC, and must be submitted to PCI SSC along with the Report on Compliance (ROC) and other supporting documents. The AOC must also be provided to the vendor's clients upon request. References:
PCI Card Production Security Assessor (CPSA) Qualification Requirements, v1.0, April 2019, page 11, requirement 7.1.1 PCI Card Production and Provisioning Attestation of Compliance, v2.0, April 2019, page 1, section 1


NEW QUESTION # 29
For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?

  • A. 3 years
  • B. As long as the entity under assessment is a client of the CPSA Company
  • C. Until each applicable payment brand has accepted (and signed off) the ROC and AOC
  • D. 1 year

Answer: A

Explanation:
Explanation
According to the PCI CPSA Program Guide, a CPSA Company must maintain workpapers and technical information obtained during an assessment for a minimum of three years from the date of the assessment. The workpapers and technical information must be stored securely and made available to PCI SSC upon request.
The workpapers and technical information must include, but are not limited to, the following:
The Card Production Report on Compliance (ROC) and the Card Production Attestation of Compliance (AOC) The Card Production Entity's policies and procedures The Card Production Entity's network diagrams and data flow diagrams The results of any testing performed by the CPSA Company or the Card Production Entity The evidence of any remediation actions taken by the Card Production Entity The correspondence between the CPSA Company and the Card Production Entity The correspondence between the CPSA Company and the payment brands The feedback form completed by the Card Production Entity References:
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 111


NEW QUESTION # 30
The receptionist responsible for the entrance and departure of visitors must have which of the following?

  • A. A constant, open communication channel with a guard
  • B. An unobstructed view of the reception area at all times
  • C. A means of communicating directly with the visitor while on the premises
  • D. A shredder for the destruction of disposable visitor badges

Answer: B

Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the receptionist responsible for the entrance and departure of visitors must have an unobstructed view of the reception area at all times. This is to ensure that the receptionist can monitor and control the access of visitors, and to prevent any unauthorized entry or exit of personnel or materials. The receptionist must also have a means of verifying the identity of visitors, such as a photo ID or a visitor log, and a means of issuing and collecting visitor badges, such as a badge printer or a badge holder. The receptionist must also have a means of communicating with the security personnel or the security control room, such as a phone or an intercom, in case of any emergency or suspicious activity. References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 21, requirement 5.3.1 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 22, requirement 5.3.2 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 23, requirement 5.3.3


NEW QUESTION # 31
Which of the follow best describes a Technical FAQ?

  • A. Technical FAQs only apply to the specific technology as the FAQ defines it
  • B. Use of the Technical FAQs is optional, they are considered guidance
  • C. Use of the Technical FAQs is mandatory, they shall be used during an assessment
  • D. Technical FAQs can be submitted to PCI SSC at any time

Answer: B

Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, Technical FAQs are documents that provide guidance on specific technical topics related to the PCI Card Production Security Standards. Technical FAQs are not mandatory, but they are recommended to be used by CPSA Companies and CPSA Employees during the card production assessment process. Technical FAQs are intended to help clarify the intent and applicability of the PCI Card Production Security Requirements, and to provide examples and best practices for achieving compliance. Technical FAQs are published by the PCI SSC on its website, and are updated periodically based on feedback from the card production industry and the payment brands. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 4.2, Page 81


NEW QUESTION # 32
......

Study HIGH Quality CPSA_P_New Free Study Guides and Exams Tutorials: https://www.pass4surequiz.com/CPSA_P_New-exam-quiz.html

Download PCI CPSA_P_New Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=1ue_iX10A7Bmqfwx2fD3ad8T2p-luDQyZ