New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

PCI SSC CPSA Card Production Security Assessor (CPSA)QualificationExam Exam Practice Test

Page: 1 / 5
Total 50 questions

Card Production Security Assessor (CPSA)QualificationExam Questions and Answers

Question 1

A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder’s mobile device. Which of the following best describes the vendor’s activities?

Options:

A.

Card personalization

B.

Host Card Emulation (HCE) provisioning

C.

Secure Element (SE) provisioning

D.

Over-the-air (OTA) provisioning

Question 2

A vendor is unsure which forms are needed to complete an assessment. Who should they ask?

Options:

A.

Assessor

B.

Issuing banks

C.

Payment brands

D.

PCI SSC

Question 3

For how long must a vendor retain all applicant and employee background information on file?

Options:

A.

For at least 12 months after termination of the contract of employment

B.

For at least 18 months after termination of the contract of employment

C.

For at least 24 months after termination of the contract of employment

D.

It is not a requirement to store this information beyond termination of the contract

Question 4

You are driving to a vendor for their first assessment. The facility is in a rural area, twenty miles away from the nearest large town. What most concerns you about the location?

Options:

A.

The local fire service may not be able to reach the facility within 15 minutes

B.

Law enforcement services may not be able to reach the facility in a timely manner

C.

Power blackouts may affect security systems

D.

There may not be adequate retail outlets, which may cause problems when sourcing lunch items for onsite personnel

Question 5

How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?

Options:

A.

Every day

B.

Every week

C.

Every month

D.

Every 3 months

Question 6

After reviewing their completed ROC and AOC, which state that they are compliant, the vendor wishes to be listed on PCI SSC’s list of Compliant Card Vendors. How should you assist them with the listing process?

Options:

A.

Submit the full ROC to PCI SSC

B.

Submit only the AOC to PCI SSC

C.

Inform the vendor that PCI SSC does not list compliant vendors

D.

Inform the vendor that they must request a listing via the payment brand(s) that received their ROC

Question 7

John works for ACME Inc Personalizers. an organization that personalizes payment cards as well as printing the corresponding PIN mailers for distribution directly to the cardholder. Which of the following statements is true?

Options:

A.

If John is involved in card personalization then he must not be involved in the printing of the corresponding PINs

B.

If John is involved in card personalization, then he must never be involved in the card shipment process

C.

If John is involved in card personalization, then he must never be involved in PIN printing

D.

If John is involved in PIN printing, then he must never be involved in the card shipment process

Page: 1 / 5
Total 50 questions