New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

PCI SSC CPSA_P_New Card Production Security AssessorCPSA Physical NewExam Exam Practice Test

Page: 1 / 5
Total 50 questions

Card Production Security AssessorCPSA Physical NewExam Questions and Answers

Question 1

How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?

Options:

A.

Every day

B.

Every week

C.

Every month

D.

Every 3 months

Question 2

In relation to guards, which of the following must the vendor ensure?

Options:

A.

A clear segregation of duties is maintained between production staff and guards

B.

A clear segregation of duties is maintained between guard and reception related job functions

C.

There is always at least one guard on-site, including outside of working hours, to monitor security systems and premises

D.

There is always at least one guard in the HSA and one guard in the security control room at all times

Question 3

An assessor must provide which of the following to their client at the start of every assessment?

Options:

A.

CPSA Feedback Form

B.

Quality Assurance Manual

C.

Attestation of Compliance

D.

Vendor Release Agreement

Question 4

Which of the follow best describes a Technical FAQ?

Options:

A.

Technical FAQs only apply to the specific technology as the FAQ defines it

B.

Technical FAQs can be submitted to PCI SSC at any time

C.

Use of the Technical FAQs is mandatory, they shall be used during an assessment

D.

Use of the Technical FAQs is optional, they are considered guidance

Question 5

During an assessment you do a walk-through of bringing card products into the HSA using the goods-tools trap. You act as production staff, using an empty cardboard box as the card products. During the process, the guard escorts you, along with the box, into the pre-press room. What is your conclusion?

Options:

A.

Compliant, because the guard escorted you

B.

Compliant, because the guard ensured that the card product remained under dual control

C.

Not compliant, because an inventory of the card product did not take place prior to entry

D.

Not compliant, because the guard escorted you

Question 6

Which of the following principles must be enforce by the HSA Access Control system?

Options:

A.

Dual control

B.

Dual presence

C.

Dual control and dual presence

D.

Dual guard entry when required

Question 7

For how long must a vendor retain all applicant and employee background information on file?

Options:

A.

For at least 12 months after termination of the contract of employment

B.

For at least 18 months after termination of the contract of employment

C.

For at least 24 months after termination of the contract of employment

D.

It is not a requirement to store this information beyond termination of the contract

Question 8

To liberate a person detected inside of the inner shipping delivery room and stop the alarm, the software monitoring the access-control system must only allow the opening of which door?

Options:

A.

The external facing door

B.

The internal facing door

C.

The last activated door

D.

The least secure door

Question 9

When must HSA motion detectors generate an alarm event?

Options:

A.

Each time movement is detected

B.

Each time movement is detected outside of regular business hours

C.

Each time movement is detected and the access-control system indicates the room is occupied

D.

Each time movement is detected and the access-control system indicates the room is not occupied

Question 10

A cardholder wants to make purchases using their phone, so they have their cardholder information programmed into their SIM card using their mobile phone provider. Which of the following best describes this system?

Options:

A.

Card personalization

B.

Host Card Emulation (HCE) provisioning

C.

Secure Element (SE) provisioning

D.

Over-the-air (OTA) provisioning

Question 11

A vendor receives cardholder information and keys from a bank. The vendor then performs the following:

* Uses its HSM to create keys

* Creates cardholder information specific to each cardholder, including name and PAN

* Formats the data for the hardware that will put it on a card

* Writes it to an encrypted file

Which of the following best describes this process?

Options:

A.

Data creation

B.

Data preparation

C.

Manufacture

D.

Pre-personalization

Question 12

Which of the following must be used by the vendor to protect doors that provide access to buildings containing air conditioning equipment?

Options:

A.

Security tape that will leave an observable trace each time a door is opened

B.

Electrical contacts that log each open and close event to a secure system memory

C.

Magnetic contacts that are permanently alarmed and that are connected to the security control-room panels

D.

Physical locks with a limited set of keys under constant supervision by a guard in the security control-room

Question 13

Which of the following personnel changes must result in the vendor notifying the Vendor Program Administration (VPA)?

Options:

A.

Adding additional rights to someone’s role to give them access to the mam production vault

B.

Any change to a role that directly affects the security of card products and related components

C.

Hiring someone that will directly interact with the card issuers

D.

Promoting someone to senior management level

Question 14

A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder’s mobile device. Which of the following best describes the vendor’s activities?

Options:

A.

Card personalization

B.

Host Card Emulation (HCE) provisioning

C.

Secure Element (SE) provisioning

D.

Over-the-air (OTA) provisioning

Question 15

A CPSA Company has submitted multiple reports that are incomplete and do not contain the information described in the reporting instructions. Which of the following are possible outcomes?

Options:

A.

They may be put into remediation or revoked by the applicable payment brands

B.

They may be put into remediation or revoked by PCI SSC

C.

They may be fined by the applicable payment brands

D.

They may be fined by PCI SSC

Page: 1 / 5
Total 50 questions