Winter Special Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

PCI SSC CPSA_P_New Card Production Security AssessorCPSA Physical NewExam Exam Practice Test

Page: 1 / 5
Total 50 questions

Card Production Security AssessorCPSA Physical NewExam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$42  $119.99

PDF Study Guide

  • Product Type: PDF Study Guide
$36.75  $104.99
Question 1

Which of the following statements is true about the facility’s non-emergency exits?

Options:

A.

They must be contact-alarm monitored only when card production activities are taking place

B.

They must be configured to prevent staff tailgating

C.

They may be left unlocked when a guard is present

D.

They must be fitted with biometric access-control devices

Question 2

During an assessment you ask to see employee records for employees with access to the HSA. The records include information about the screening process, including background information from the employee application process. The oldest background Information that is available is for an employee that left the vendor (terminated their contract) one year previously. You note this as non-compliant, why?

Options:

A.

Employee information, including background checks, must be stored for at least seven years

B.

Employee information must be securely destroyed (e.g. securely wiped) within 2 years (after termination of contract)

C.

The vendor must retain the background information for at least 18 months after termination of contract

D.

The vendor must only retain background information for all current employees, not for those that have been terminated

Question 3

Which document describes the results of an assessment, and is signed by both the assessor and the vendor executive officer?

Options:

A.

Security Assessment Questionnaire (SAQ)

B.

Attestation of Compliance (AOC)

C.

Report on Compliance (ROC)

D.

Letter of Approval (LOA)

Question 4

Which of the following principles must be enforce by the HSA Access Control system?

Options:

A.

Dual control

B.

Dual presence

C.

Dual control and dual presence

D.

Dual guard entry when required

Question 5

Which of the following statements about unsolicited visitors is true?

Options:

A.

They must be turned away

B.

They must complete an NDA before entry is granted

C.

They must be able to prove a legitimate reason for their visit prior to entry

D.

They must be registered, their identities confirmed, and must be allocated an escort before entry

Question 6

The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?

Options:

A.

If the local police have not been issued with an exterior key. they will not be able to investigate the cause of the alarm and reset it

B.

During working hours, the alarm should be managed in the security control room, or by a central monitoring service

C.

If the local police receive too many false-positive alerts, they may not respond within 15 minutes of the alarm

D.

During busy times, the local police may not be able to respond

Question 7

Which of the following security awareness measures is required for compliance?

Options:

A.

Annual training on common attack methods

B.

Annual training on use of mantraps

C.

Security awareness exams for all personnel

D.

Security posters must be placed in the facility

Question 8

For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?

Options:

A.

Until each applicable payment brand has accepted (and signed off) the ROC and AOC

B.

As long as the entity under assessment is a client of the CPSA Company

C.

3 years

D.

1 year

Question 9

The receptionist responsible for the entrance and departure of visitors must have which of the following?

Options:

A.

A shredder for the destruction of disposable visitor badges

B.

A constant, open communication channel with a guard

C.

An unobstructed view of the reception area at all times

D.

A means of communicating directly with the visitor while on the premises

Question 10

When must HSA motion detectors generate an alarm event?

Options:

A.

Each time movement is detected

B.

Each time movement is detected outside of regular business hours

C.

Each time movement is detected and the access-control system indicates the room is occupied

D.

Each time movement is detected and the access-control system indicates the room is not occupied

Question 11

Which of the following statements is true in relation to visitor access badges?

Options:

A.

Each visitor entering the facility must be issued and must visibly wear a disposable ID badge that identifies them as a non-employee

B.

Each visitor entering the facility must wear their issued access badge above waist height

C.

Badges with access-controls must not be issued to visitors

D.

Unissued visitor access badges must be securely stored

Question 12

A vendor receives cardholder information and keys from a bank. The vendor then performs the following:

* Uses its HSM to create keys

* Creates cardholder information specific to each cardholder, including name and PAN

* Formats the data for the hardware that will put it on a card

* Writes it to an encrypted file

Which of the following best describes this process?

Options:

A.

Data creation

B.

Data preparation

C.

Manufacture

D.

Pre-personalization

Question 13

If you have a query about a missing field in the card production reporting template, which organization is best-placed to answer it?

Options:

A.

The payment brands

B.

The vendor

C.

The issuer

D.

PCI SSC

Question 14

Who is required to approve visitor entry to the HSA or cloud-based provisioning environment?

Options:

A.

The head of the vendor facility

B.

The Security Manager

C.

Both the Security Manager and the Production Manager

D.

The Security Manager, Production Manager, and the head of the vendor facility

Question 15

A card production vendor employs a contracted guard service from an outside source. What is one of the responsibilities of the contracted service?

Options:

A.

Provide only certified guards

B.

Register their service with the VPA

C.

Maintain their own liability insurance in case of losses to card material

D.

Undergo their own Card Production assessment and provide evidence of a passing result

Page: 1 / 5
Total 50 questions