Winter Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Free and Premium PCI SSC CPSA_P_New Dumps Questions Answers

Page: 1 / 4
Total 50 questions

Card Production Security AssessorCPSA Physical NewExam Questions and Answers

Question 1

Which of the following principles must be enforce by the HSA Access Control system?

Options:

A.

Dual control

B.

Dual presence

C.

Dual control and dual presence

D.

Dual guard entry when required

Buy Now
Question 2

In relation to guards, which of the following must the vendor ensure?

Options:

A.

A clear segregation of duties is maintained between production staff and guards

B.

A clear segregation of duties is maintained between guard and reception related job functions

C.

There is always at least one guard on-site, including outside of working hours, to monitor security systems and premises

D.

There is always at least one guard in the HSA and one guard in the security control room at all times

Question 3

A cardholder wants to make purchases using their phone, so they have their cardholder information programmed into their SIM card using their mobile phone provider. Which of the following best describes this system?

Options:

A.

Card personalization

B.

Host Card Emulation (HCE) provisioning

C.

Secure Element (SE) provisioning

D.

Over-the-air (OTA) provisioning

Question 4

In which of the following locations must the CCTV and access control servers be located?

Options:

A.

Within the Security Control Room (SCR)

B.

Within a room in the HSA with security controls equivalent to the SCR applied

C.

Within the SCR or a room with equivalent security

D.

Within the secure server room inside of the HSA

Question 5

Which of the following must every assessor do to maintain their CPSA certification?

Options:

A.

Complete annual requalification training or complete 3 assessments for different facilities each year

B.

Earn and document at least 20 hours of Continuing Professional Education (CPE) over 3 years

C.

Earn an additional professional certification from List A or B of the Qualification Requirements (QRs)

D.

Submit evidence of internal training in a relevant area (as per the QRs)

Question 6

A vendor puts cardholder information into a chip by sliding a payment card through a machine that programs it and verifies the data. The chip can make contactless transactions. Which of the following best describes the vendor’s activity?

Options:

A.

Card personalization

B.

Host Card Emulation (HCE) provisioning

C.

Secure Element (SE) provisioning

D.

Fulfillment

Question 7

The receptionist responsible for the entrance and departure of visitors must have which of the following?

Options:

A.

A shredder for the destruction of disposable visitor badges

B.

A constant, open communication channel with a guard

C.

An unobstructed view of the reception area at all times

D.

A means of communicating directly with the visitor while on the premises

Question 8

During an assessment you do a walk-through of bringing card products into the HSA using the goods-tools trap. You act as production staff, using an empty cardboard box as the card products. During the process, the guard escorts you, along with the box, into the pre-press room. What is your conclusion?

Options:

A.

Compliant, because the guard escorted you

B.

Compliant, because the guard ensured that the card product remained under dual control

C.

Not compliant, because an inventory of the card product did not take place prior to entry

D.

Not compliant, because the guard escorted you

Question 9

When must HSA motion detectors generate an alarm event?

Options:

A.

Each time movement is detected

B.

Each time movement is detected outside of regular business hours

C.

Each time movement is detected and the access-control system indicates the room is occupied

D.

Each time movement is detected and the access-control system indicates the room is not occupied

Question 10

For how long must a vendor retain all applicant and employee background information on file?

Options:

A.

For at least 12 months after termination of the contract of employment

B.

For at least 18 months after termination of the contract of employment

C.

For at least 24 months after termination of the contract of employment

D.

It is not a requirement to store this information beyond termination of the contract

Question 11

For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?

Options:

A.

Until each applicable payment brand has accepted (and signed off) the ROC and AOC

B.

As long as the entity under assessment is a client of the CPSA Company

C.

3 years

D.

1 year

Question 12

During an assessment you walk the perimeter of the building with a guard you find an emergency exit door from the facility and ask the guard what is on the other side. The guard can’t remember, and so uses their assigned, secure key to open the door and show you a corridor within the facility. What most concerns you about the situation?

Options:

A.

The exit door should not lead into the facility

B.

The exit door should not be capable of being opened from the outside

C.

The guard should not have forgotten where the door leads to

D.

The guard should have sought permission from their manager before opening the door

Question 13

A card production vendor employs a contracted guard service from an outside source. What is one of the responsibilities of the contracted service?

Options:

A.

Provide only certified guards

B.

Register their service with the VPA

C.

Maintain their own liability insurance in case of losses to card material

D.

Undergo their own Card Production assessment and provide evidence of a passing result

Question 14

If you have a query about a missing field in the card production reporting template, which organization is best-placed to answer it?

Options:

A.

The payment brands

B.

The vendor

C.

The issuer

D.

PCI SSC

Question 15

A vendor is unsure which forms are needed to complete an assessment. Who should they ask?

Options:

A.

Assessor

B.

Issuing banks

C.

Payment brands

D.

PCI SSC

Page: 1 / 4
Total 50 questions