Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

CPSA_P_New Card Production Security AssessorCPSA Physical NewExam Questions and Answers

Questions 4

You are driving to a vendor for their first assessment. The facility is in a rural area, twenty miles away from the nearest large town. What most concerns you about the location?

Options:

A.

The local fire service may not be able to reach the facility within 15 minutes

B.

Law enforcement services may not be able to reach the facility in a timely manner

C.

Power blackouts may affect security systems

D.

There may not be adequate retail outlets, which may cause problems when sourcing lunch items for onsite personnel

Buy Now
Questions 5

A vendor discovers that a recent shipment of cards is missing a set. Which of the following responses would you expect in a compliant organization?

Options:

A.

An immediate call is made to the issuer and the VPA who, between them, contact law enforcement and put together a joint statement

B.

The head of security initiates a meeting, and once the VPA approves the messaging, law enforcement is notified in two days

C.

A report is requested by the issuer, the vendor sends it to them, and the issuer handles the incident with the local police

D.

After an incident review, the VPA, issuer and law enforcement are all notified within 24 hours

Buy Now
Questions 6

Which of the following personnel changes must result in the vendor notifying the Vendor Program Administration (VPA)?

Options:

A.

Adding additional rights to someone’s role to give them access to the mam production vault

B.

Any change to a role that directly affects the security of card products and related components

C.

Hiring someone that will directly interact with the card issuers

D.

Promoting someone to senior management level

Buy Now
Questions 7

Which of the follow best describes a Technical FAQ?

Options:

A.

Technical FAQs only apply to the specific technology as the FAQ defines it

B.

Technical FAQs can be submitted to PCI SSC at any time

C.

Use of the Technical FAQs is mandatory, they shall be used during an assessment

D.

Use of the Technical FAQs is optional, they are considered guidance

Buy Now
Questions 8

During an assessment you do a walk-through of bringing card products into the HSA using the goods-tools trap. You act as production staff, using an empty cardboard box as the card products. During the process, the guard escorts you, along with the box, into the pre-press room. What is your conclusion?

Options:

A.

Compliant, because the guard escorted you

B.

Compliant, because the guard ensured that the card product remained under dual control

C.

Not compliant, because an inventory of the card product did not take place prior to entry

D.

Not compliant, because the guard escorted you

Buy Now
Questions 9

A cardholder wants to make purchases using their phone, so they have their cardholder information programmed into their SIM card using their mobile phone provider. Which of the following best describes this system?

Options:

A.

Card personalization

B.

Host Card Emulation (HCE) provisioning

C.

Secure Element (SE) provisioning

D.

Over-the-air (OTA) provisioning

Buy Now
Questions 10

A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder’s mobile device. Which of the following best describes the vendor’s activities?

Options:

A.

Card personalization

B.

Host Card Emulation (HCE) provisioning

C.

Secure Element (SE) provisioning

D.

Over-the-air (OTA) provisioning

Buy Now
Questions 11

A vendor uses codes from a chip manufacturer to ‘unlock’ chips and prepare them for use by adding applications and keys. Which of the following best describes this process?

Options:

A.

Data creation

B.

Data preparation

C.

Manufacture

D.

Pre-personalization

Buy Now
Questions 12

In which of the following locations must the CCTV and access control servers be located?

Options:

A.

Within the Security Control Room (SCR)

B.

Within a room in the HSA with security controls equivalent to the SCR applied

C.

Within the SCR or a room with equivalent security

D.

Within the secure server room inside of the HSA

Buy Now
Questions 13

For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?

Options:

A.

Until each applicable payment brand has accepted (and signed off) the ROC and AOC

B.

As long as the entity under assessment is a client of the CPSA Company

C.

3 years

D.

1 year

Buy Now
Questions 14

A vendor’s HSA access is enforced by a security turnstile they have a logical access-control system that ensures anti pass-back. The device is functioning correctly. When must the status of the access change?

Options:

A.

Only when an unauthorised badge is presented

B.

Only when the person has successfully completed the access cycle

C.

Upon initial entry of the person into the device, prior to completion of the access cycle

D.

Upon initial presentation of an authorised badge, prior to completion of the access cycle

Buy Now
Questions 15

Which of the following statements is true in relation to visitor access badges?

Options:

A.

Each visitor entering the facility must be issued and must visibly wear a disposable ID badge that identifies them as a non-employee

B.

Each visitor entering the facility must wear their issued access badge above waist height

C.

Badges with access-controls must not be issued to visitors

D.

Unissued visitor access badges must be securely stored

Buy Now
Exam Code: CPSA_P_New
Exam Name: Card Production Security AssessorCPSA Physical NewExam
Last Update: Nov 24, 2024
Questions: 50
CPSA_P_New pdf

CPSA_P_New PDF

$25.5  $84.99
CPSA_P_New Engine

CPSA_P_New Testing Engine

$30  $99.99
CPSA_P_New PDF + Engine

CPSA_P_New PDF + Testing Engine

$40.5  $134.99