
(2024) CPSA_P_New Dumps and Practice Test (52 Questions)
Guide (New 2024) Actual PCI CPSA_P_New Exam Questions
NEW QUESTION # 31
Before you go on-site, the vendor's primary contact communicates a legitimate reason for delaying the assessment for several months. Who can approve the change in the report delivery schedule?
- A. PCI SSC
- B. Vendor senior management
- C. Affected issuers
- D. Payment brands
Answer: A
Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, one of the administrative requirements for CPSA Companies is to adhere to the report delivery schedule as defined by the PCI SSC. The report delivery schedule specifies the deadlines for submitting the PCI Card Production Reports on Compliance (ROCs) and Attestations of Compliance (AOCs) to the PCI SSC and the payment brands. The report delivery schedule also defines the circumstances under which a CPSA Company may request an extension or a waiver of the report delivery deadline. The PCI SSC is the only entity that can approve the change in the report delivery schedule, and the CPSA Company must submit a written request to the PCI SSC with a valid reason for the delay and the proposed new delivery date. The PCI SSC will review the request and notify the CPSA Company of its decision. The PCI SSC may also notify the payment brands and the affected issuers of the change in the report delivery schedule. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 6.1.4, Page 121
NEW QUESTION # 32
Which of the follow best describes a Technical FAQ?
- A. Use of the Technical FAQs is mandatory, they shall be used during an assessment
- B. Technical FAQs only apply to the specific technology as the FAQ defines it
- C. Technical FAQs can be submitted to PCI SSC at any time
- D. Use of the Technical FAQs is optional, they are considered guidance
Answer: D
Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, Technical FAQs are documents that provide guidance on specific technical topics related to the PCI Card Production Security Standards. Technical FAQs are not mandatory, but they are recommended to be used by CPSA Companies and CPSA Employees during the card production assessment process. Technical FAQs are intended to help clarify the intent and applicability of the PCI Card Production Security Requirements, and to provide examples and best practices for achieving compliance. Technical FAQs are published by the PCI SSC on its website, and are updated periodically based on feedback from the card production industry and the payment brands. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 4.2, Page 81
NEW QUESTION # 33
If you have a query about a missing field in the card production reporting template, which organization is best-placed to answer it?
- A. PCI SSC
- B. The payment brands
- C. The vendor
- D. The issuer
Answer: A
Explanation:
Explanation
The PCI SSC is the best-placed organization to answer a query about a missing field in the card production reporting template, as they are the ones who develop and maintain the template and the standards. The card production reporting template is the mandatory template for use in completing a Card Production Report on Compliance (ROC), which provides detail on how to document the findings of a PCI Card Production Assessment. The template is based on the PCI Card Production and Provisioning LogicalSecurity Requirements and the PCI Card Production and Provisioning Physical Security Requirements, which are also developed and maintained by the PCI SSC. Therefore, the PCI SSC has the authority and the expertise to clarify any issues or questions regarding the template and the standards. The other options are not the best sources of information for the query, as they may not have the same level of knowledge or involvement in the template and the standards. References:
PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 31 PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 52 PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 82
NEW QUESTION # 34
How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?
- A. Every month
- B. Every week
- C. Every 3 months
- D. Every day
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must test all alarms on external doors of the card production and provisioning vendor environment at least every month.
The vendor must also document the results of the tests and retain them for at least one year. The vendor must also have procedures to respond to any alarms or incidents, and to report them to the relevant parties. The vendor must not test the alarms less frequently than every month, as this may compromise the security and integrity of the card production and provisioning vendor environment and increase the risk of unauthorized access or theft. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101
NEW QUESTION # 35
The receptionist responsible for the entrance and departure of visitors must have which of the following?
- A. A shredder for the destruction of disposable visitor badges
- B. A means of communicating directly with the visitor while on the premises
- C. An unobstructed view of the reception area at all times
- D. A constant, open communication channel with a guard
Answer: C
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, the receptionist responsible for the entrance and departure of visitors must have an unobstructed view of the reception area at all times. This is to ensure that the receptionist can monitor and control the access of visitors, and to prevent any unauthorized entry or exit of personnel or materials. The receptionist must also have a means of verifying the identity of visitors, such as a photo ID or a visitor log, and a means of issuing and collecting visitor badges, such as a badge printer or a badge holder. The receptionist must also have a means of communicating with the security personnel or the security control room, such as a phone or an intercom, in case of any emergency or suspicious activity. References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 21, requirement 5.3.1 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 22, requirement 5.3.2 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 23, requirement 5.3.3
NEW QUESTION # 36
For how long must a vendor retain all applicant and employee background information on file?
- A. For at least 24 months after termination of the contract of employment
- B. It is not a requirement to store this information beyond termination of the contract
- C. For at least 18 months after termination of the contract of employment
- D. For at least 12 months after termination of the contract of employment
Answer: D
Explanation:
Explanation
According to the PCI CPSA Qualification Requirements, one of the administrative requirements for CPSA Companies is to retain all applicant and employee background information on file for at least 12 months after termination of the contract of employment. This is to ensure that the CPSA Company can provide evidence of the background checks performed on the CPSA Employees or other personnel involved in card production and provisioning activities. The background checks should include criminal history, employment history, education verification, and reference checks, and should be conducted at least every two years or upon rehire. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 6.1.2, Page 111
NEW QUESTION # 37
For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?
- A. 3 years
- B. As long as the entity under assessment is a client of the CPSA Company
- C. 1 year
- D. Until each applicable payment brand has accepted (and signed off) the ROC and AOC
Answer: A
Explanation:
Explanation
According to the PCI CPSA Program Guide, a CPSA Company must maintain workpapers and technical information obtained during an assessment for a minimum of three years from the date of the assessment. The workpapers and technical information must be stored securely and made available to PCI SSC upon request.
The workpapers and technical information must include, but are not limited to, the following:
The Card Production Report on Compliance (ROC) and the Card Production Attestation of Compliance (AOC) The Card Production Entity's policies and procedures The Card Production Entity's network diagrams and data flow diagrams The results of any testing performed by the CPSA Company or the Card Production Entity The evidence of any remediation actions taken by the Card Production Entity The correspondence between the CPSA Company and the Card Production Entity The correspondence between the CPSA Company and the payment brands The feedback form completed by the Card Production Entity References:
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 111
NEW QUESTION # 38
Who performs regular AQM audits of CPSA companies?
- A. PCI SSC
- B. Issuing banks
- C. Payment brands
- D. Vendor
Answer: A
Explanation:
Explanation
The PCI Security Standards Council (PCI SSC) performs regular Assessor Quality Management (AQM) audits of CPSA companies to ensure that they comply with the PCI CPSA Qualification Requirements and the PCI Card Production Standards. The AQM audits are conducted by PCI SSC staff or authorized third parties, and may include onsite visits, remote reviews, or both. The AQM audits aim to verify the quality and consistency of the CPSA companies' assessment processes, reports, and documentation, as well as their adherence to the PCI SSC Code of Professional Responsibility. The AQM audits may result in corrective actions, sanctions, or revocation of the CPSA company status, depending on the severity and frequency of the non-compliance issues identified. References:
PCI Card Production Security Assessor (CPSA) Qualification Requirements, v1.0, April 2019, page 12, requirement 8.1 PCI Card Production Security Assessor (CPSA) Program Guide, v1.0, April 2019, page 6, section 3.2
NEW QUESTION # 39
For each requirement listed in a ROC, which types of findings must have a full narrative response?
- A. All types of findings
- B. New or Closed findings only
- C. All types except Not Applicable findings
- D. Non-compliant findings only
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Template for Report on Compliance, for each requirement listed in a ROC, all types of findings must have a full narrative response. A finding is the result of the assessor's evaluation of the entity's compliance status for each requirement. The types of findings are:
Compliant: The entity meets the requirement as stated in the PCI Card Production Standards.
Non-Compliant: The entity does not meet the requirement as stated in the PCI Card Production Standards.
Not Applicable: The requirement does not apply to the entity's environment or operations.
Not Tested: The requirement was not tested by the assessor for a valid reason.
New: The entity has implemented a new process, system, or control that affects the requirement since the last assessment.
Closed: The entity has remediated a previous non-compliant finding and has provided sufficient evidence to the assessor.
A full narrative response is a detailed explanation of the finding, including the following elements:
The scope of testing performed by the assessor to evaluate the requirement The testing procedures and tools used by the assessor The sampling methodology and rationale used by the assessor The evidence collected and reviewed by the assessor The observations and conclusions made by the assessor The recommendations and remediation actions (if any) suggested by the assessor A full narrative response is required for all types of findings to provide a clear and comprehensive documentation of the entity's compliance status and to support the assessor's professional judgment and opinion. A full narrative response also helps the payment brands, the PCI SSC, and the entity itself to understand the entity's environment, risks, and controls, and to verify the accuracy and validity of the assessment. References:
PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 4 PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 5 PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 6
NEW QUESTION # 40
To liberate a person detected inside of the inner shipping delivery room and stop the alarm, the software monitoring the access-control system must only allow the opening of which door?
- A. The external facing door
- B. The last activated door
- C. The internal facing door
- D. The least secure door
Answer: B
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must have a secure inner shipping delivery room that is equipped with an alarm system and an access-control system. The alarm system must be triggered when any door of the inner shipping delivery room is opened without proper authorization. The access-control system must only allow the opening of the last activated door to liberate a person detected inside of the inner shipping delivery room and stop the alarm. This is to prevent unauthorized access or exit from the inner shipping delivery room, and to ensure that only one door can be opened at a time. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 18-191
NEW QUESTION # 41
Which of the following statements about unsolicited visitors is true?
- A. They must be registered, their identities confirmed, and must be allocated an escort before entry
- B. They must be able to prove a legitimate reason for their visit prior to entry
- C. They must complete an NDA before entry is granted
- D. They must be turned away
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, unsolicited visitors are defined as "individuals who do not have a pre-arranged appointment or a legitimate reason for visiting the Card Production Entity". The requirement for dealing with unsolicited visitors is that they must be registered, their identities confirmed, and must be allocated an escort before entry. The escort must accompany the unsolicited visitor at all times and ensure that they do not access any restricted areas or sensitive information.
The other options are not true statements about unsolicited visitors, as they may not comply with the PCI Card Production Standards or the best practices for physical security. References:
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
101
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
111
NEW QUESTION # 42
A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder's mobile device. Which of the following best describes the vendor's activities?
- A. Secure Element (SE) provisioning
- B. Host Card Emulation (HCE) provisioning
- C. Over-the-air (OTA) provisioning
- D. Card personalization
Answer: B
Explanation:
Explanation
Host Card Emulation (HCE) provisioning is the process of creating and storing cardholder data in a virtual secure element hosted in a remote server, and generating a payment token that can be used by a mobile device to perform a contactless transaction. HCE provisioning is one of the methods of cloud-based provisioning, which does not require the use of a physical secure element on the mobile device. HCE provisioning is different from Secure Element (SE) provisioning, which involves loading cardholder data into a physical secure element embedded or attached to the mobile device. HCE provisioning is also different from Over-the-air (OTA) provisioning, which involves transmitting cardholder data from a remote server to a physical secure element on the mobiledevice using a wireless communication channel. In this scenario, the vendor hosts virtual secure elements holding cardholder information in their data center, and creates a payment token that is sent to the cardholder's mobile device. This best describes the vendor's activities as HCE provisioning. References:
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 8, section
1.3
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 9, section
1.4
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 10, section 1.5 PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 43, Appendix A: Applicability of Requirements
NEW QUESTION # 43
An assessor must provide which of the following to their client at the start of every assessment?
- A. Vendor Release Agreement
- B. CPSA Feedback Form
- C. Attestation of Compliance
- D. Quality Assurance Manual
Answer: D
Explanation:
Explanation
According to the Card Production Security Assessor (CPSA) Qualification Requirements, an assessor must provide their client with a Quality Assurance Manual at the start of every assessment. The Quality Assurance Manual is a document that describes the assessor's methodology, procedures, and quality control measures for conducting assessments. The manual must be consistent with the CPSA Program Guide and the PCI Card Production and Provisioning Security Requirements. The manual must also include a description of the assessor's roles and responsibilities, the assessment scope and objectives, the assessment plan and timeline, the assessment report format and content, and the assessor's conflict of interestpolicy. References: Card Production Security Assessor (CPSA) Qualification Requirements, v1.0, April 2019, page 111
NEW QUESTION # 44
You wish to check that you are using the most current version of the Card Production requirements. What should you do?
- A. View it directly via PCI SSC Assessor Portal
- B. Have the CPSA Company's point of contact request the document
- C. Download it from PCI SSC's Document Library
- D. Email a request for the document to PCI SSC
Answer: C
Explanation:
Explanation
The best way to check that you are using the most current version of the Card Production requirements is to download it from PCI SSC's Document Library. The PCI SSC's Document Library is a repository of all the PCI standards, guidelines, and supporting documents that are developed and maintained by the PCI SSC. The Document Library is accessible to the public and provides the latest versions of the documents, as well as the summary of changes and the effective dates. The Document Library also allows you to search, filter, and sort the documents by category, type, date, and keyword. Therefore, by downloading the Card Production requirements from the Document Library, you can ensure that you have the most up-to-date and authoritative version of the requirements. The other options are not the best ways to check the version of the Card Production requirements, as they may not be reliable, efficient, or available. Having the CPSA Company's point of contact request the document may not be feasible, as the point of contact may not have the authority, the access, or the time to do so. Emailing a request for the document to PCI SSC may not be effective, as the PCI SSC may not respond promptly or provide the document in the format that you need. Viewing the document directly via PCI SSC Assessor Portal may not be possible, as the Assessor Portal may not have the latest version of the document or may require a login credential that you do not have. References:
PCI SSC Document Library1
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 52
NEW QUESTION # 45
A cardholder wants to make purchases using their phone, so they have their cardholder information programmed into their SIM card using their mobile phone provider. Which of the following best describes this system?
- A. Secure Element (SE) provisioning
- B. Over-the-air (OTA) provisioning
- C. Card personalization
- D. Host Card Emulation (HCE) provisioning
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Logical Security Requirements, Secure Element (SE) provisioning is the process of adding cardholder account information to a secure element on a mobile device via an over-the-air or over-the-internet communication channel. A secure element is a tamper-resistant platform that can securely host applications and their confidential and cryptographic data. A SIM card is an example of a secure element that can be used for mobile payments. SE provisioning is different from Host Card Emulation (HCE) provisioning, which is the process of adding cardholder account information to a cloud-based server that emulates a secure element on a mobile device. SE provisioning is also different from card personalization, which is the process of adding cardholder account information to a physical card.
Over-the-air (OTA) provisioning is a generic term that can refer to either SE or HCE provisioning, depending on the type of mobile payment system used. References: PCI Card Production and Provisioning Logical Security Requirements and Test Procedures v3.0, January 2022, pages 6-71
NEW QUESTION # 46
The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?
- A. During working hours, the alarm should be managed in the security control room, or by a central monitoring service
- B. If the local police receive too many false-positive alerts, they may not respond within 15 minutes of the alarm
- C. During busy times, the local police may not be able to respond
- D. If the local police have not been issued with an exterior key. they will not be able to investigate the cause of the alarm and reset it
Answer: A
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must have an alarm system that monitors and detects unauthorized access to the card production and provisioning facilities, and that alerts the security control room or a central monitoring service. The alarm system must also be able to identify the location and cause of the alarm, and allow authorized personnel to reset it. The alarm system must be operational 24/7, and must be tested at least annually. The vendor must also have procedures to respond to alarms and incidents, and to report them to the relevant parties. If the alarm system does not send alerts to the security control room, or a central monitoring service, during working hours, the vendor may not be able to comply with these requirements, and may not be able to prevent, detect, or respond to unauthorized access or security breaches. This may cause a problem for their assessment, as they may not meet the PCI Card Production and Provisioning Physical Security Requirements. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101
NEW QUESTION # 47
Which document describes the results of an assessment, and is signed by both the assessor and the vendor executive officer?
- A. Attestation of Compliance (AOC)
- B. Report on Compliance (ROC)
- C. Letter of Approval (LOA)
- D. Security Assessment Questionnaire (SAQ)
Answer: A
Explanation:
Explanation
The Attestation of Compliance (AOC) is the document that describes the results of a PCI Card Production Assessment, and is signed by both the CPSA and the vendor executive officer. The AOC is a summary of the findings and conclusions of the assessment, and indicates whether the vendor meets the PCI Card Production Logical Security Requirements and/or the PCI Card Production Physical Security Requirements. The AOC must be completed using the template provided by PCI SSC, and must be submitted to PCI SSC along with the Report on Compliance (ROC) and other supporting documents. The AOC must also be provided to the vendor's clients upon request. References:
PCI Card Production Security Assessor (CPSA) Qualification Requirements, v1.0, April 2019, page 11, requirement 7.1.1 PCI Card Production and Provisioning Attestation of Compliance, v2.0, April 2019, page 1, section 1
NEW QUESTION # 48
A vendor discovers that a recent shipment of cards is missing a set. Which of the following responses would you expect in a compliant organization?
- A. The head of security initiates a meeting, and once the VPA approves the messaging, law enforcement is notified in two days
- B. An immediate call is made to the issuer and the VPA who, between them, contact law enforcement and put together a joint statement
- C. A report is requested by the issuer, the vendor sends it to them, and the issuer handles the incident with the local police
- D. After an incident review, the VPA, issuer and law enforcement are all notified within 24 hours
Answer: D
Explanation:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for card shipment is to ensure that the vendor has an incident response plan in place to handle any card shipment incidents, such as loss, theft, or tampering. The incident response plan should include the following steps1:
The vendor should conduct an incident review to determine the cause and scope of the incident, and document the findings and actions taken.
The vendor should notify the VPA, the issuer, and law enforcement of the incident within 24 hours of discovery, or as soon as possible.
The vendor should cooperate with the VPA, the issuer, and law enforcement in the investigation and resolution of the incident, and provide any evidence or information requested.
The vendor should implement corrective actions to prevent the recurrence of the incident, and report the results to the VPA and the issuer. Therefore, the response that best reflects a compliant organization is option D, which follows the steps of the incident response plan as required by the PCI Card Production Physical Security Requirements. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 6, Requirement 6.2, Page 131
NEW QUESTION # 49
During an assessment you walk the perimeter of the building with a guard you find an emergency exit door from the facility and ask the guard what is on the other side. The guard can't remember, and so uses their assigned, secure key to open the door and show you a corridor within the facility. What most concerns you about the situation?
- A. The guard should not have forgotten where the door leads to
- B. The guard should have sought permission from their manager before opening the door
- C. The exit door should not be capable of being opened from the outside
- D. The exit door should not lead into the facility
Answer: C
Explanation:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, emergency exit doors must be equipped with devices that prevent unauthorized entry from the outside, such as panic bars, crash bars, or push pads. These devices allow the door to be opened from the inside without a key or a code, but prevent the door from being opened from the outside by unauthorized persons. Therefore, the most concerning aspect of the situation is that the exit door can be opened from the outside with a key, which creates a security risk for the facility. The other options are not as concerning, as they do not directly affect the security of the exit door. The exit door can lead into the facility as long as it provides a safe and unobstructed path to the exit discharge. The guard's memory lapse is not a major issue, as long as they follow the proper proceduresand protocols for opening the door. The guard's permission from their manager is not relevant, as long as they have the authority and the responsibility to open the door for inspection purposes. References:
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
171
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
181
NEW QUESTION # 50
A vendor is unsure which forms are needed to complete an assessment. Who should they ask?
- A. PCI SSC
- B. Assessor
- C. Issuing banks
- D. Payment brands
Answer: B
NEW QUESTION # 51
......
CPSA_P_New Exam Dumps Pass with Updated 2024 Certified Exam Questions: https://examcollection.dumpsactual.com/CPSA_P_New-actualtests-dumps.html
