
オンラインCPSA_P_Newテストブレーン問題集とテストエンジン
リアルPCI CPSA_P_New試験問題集には正解52問題と解答があります
質問 # 23
How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?
- A. Every 3 months
- B. Every day
- C. Every month
- D. Every week
正解:C
解説:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must test all alarms on external doors of the card production and provisioning vendor environment at least every month.
The vendor must also document the results of the tests and retain them for at least one year. The vendor must also have procedures to respond to any alarms or incidents, and to report them to the relevant parties. The vendor must not test the alarms less frequently than every month, as this may compromise the security and integrity of the card production and provisioning vendor environment and increase the risk of unauthorized access or theft. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 9-101
質問 # 24
A vendor uses codes from a chip manufacturer to 'unlock' chips and prepare them for use by adding applications and keys. Which of the following best describes this process?
- A. Data preparation
- B. Data creation
- C. Pre-personalization
- D. Manufacture
正解:C
解説:
Explanation
According to the PCI Card Production and Provisioning Logical Security Requirements, pre-personalization is the process of unlocking the chip and loading the applications and keys onto the chip. This process is performed by the vendor using codes provided by the chip manufacturer. The codes are used to authenticate the vendor and enable the chip to accept the applications and keys. The pre-personalization process prepares the chip for the subsequent personalization process, where the chip is associated with a specific cardholder account andactivated. The pre-personalization process is different from data creation, data preparation, and manufacture, which are other processes involved in card production and provisioning. References: PCI Card Production and Provisioning Logical Security Requirements and Test Procedures v3.0, January 2022, pages
6-71
質問 # 25
When must HSA motion detectors generate an alarm event?
- A. Each time movement is detected outside of regular business hours
- B. Each time movement is detected
- C. Each time movement is detected and the access-control system indicates the room is occupied
- D. Each time movement is detected and the access-control system indicates the room is not occupied
正解:D
解説:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for high-security areas (HSAs) is to have motion detectors that generate an alarm event when movement is detected and the access-control system indicates the room is not occupied. This is to prevent unauthorized access or intrusion to the HSAs, where sensitive card production and provisioning activities take place. The motion detectors should be configured to cover all areas within the HSA and should be tested periodically to ensure proper functionality. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 2, Requirement 2.1.1, Page 61
質問 # 26
A vendor is unsure which forms are needed to complete an assessment. Who should they ask?
- A. PCI SSC
- B. Issuing banks
- C. Assessor
- D. Payment brands
正解:C
質問 # 27
A vendor has a list of pre-approved third parties which may be granted access to the facility. Under what circumstances can other third-parties be granted access?
- A. None, only people on the pre-approved list may enter
- B. When no card production activities are taking place
- C. When they are approved by the physical security manager or senior management
- D. When the third party s liability insurance covers the risk
正解:C
解説:
Explanation
According to the PCI Card Production Logical Security Requirements, vendors must have a list of pre-approved third parties that are authorized to access the facility and the systems involved in card production. However, other third parties may be granted access under exceptional circumstances, such as emergency repairs or maintenance, provided that they are approved by the physical security manager or senior management. The vendor must also ensure that the third parties comply with the security policies and procedures, and that their access is logged and monitored. References: PCI Card Production Logical Security Requirements, v2.0, April 2019, page 13
質問 # 28
Who is required to approve visitor entry to the HSA or cloud-based provisioning environment?
- A. The head of the vendor facility
- B. The Security Manager
- C. Both the Security Manager and the Production Manager
- D. The Security Manager, Production Manager, and the head of the vendor facility
正解:B
解説:
Explanation
According to the PCI Card Production and Provisioning - Physical Security Requirements, the Security Manager is the person who is responsible for approving visitor entry to the High Security Area (HSA) or cloud-based provisioning environment. The HSA is the area where card production and provisioning activities take place, such as card manufacturing, personalization, PIN generation and printing, and fulfillment. The cloud-based provisioning environment is the logical equivalent of the HSA for entities that provide over-the-air (OTA) provisioning or host card emulation (HCE) provisioning services. The Security Manager must ensure that visitors have a legitimate business need toenter the HSA or cloud-based provisioning environment, and must authorize their access in advance. The Security Manager must also maintain a visitor log that records the visitor's name, company, date, time, and purpose of visit, as well as the escort's name and signature. The Security Manager must also ensure that visitors are escorted by authorized personnel at all times, and that they wear a distinctive visitor badge. The head of the vendor facility, the Production Manager, or any other person is not required to approve visitor entry to the HSA or cloud-based provisioning environment, unless they are also designated as the Security Manager by the vendor. References:
Payment Card Industry (PCI) Card Production and Provisioning - Physical Security Requirements, Section 3.1.1 and 3.1.2 Payment Card Industry (PCI) Card Production and Provisioning - Glossary of Terms, Abbreviations, and Acronyms, Definitions of Security Manager, High Security Area, Cloud-Based Provisioning Environment, OTA Provisioning, and HCE Provisioning
質問 # 29
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?
- A. PCI SSC
- B. Assessor
- C. Payment brands
- D. Issuing banks
正解:C
解説:
Explanation
The PCI SSC does not enforce compliance, nor does it mandate penalties for non-compliance. Compliance with the PCI Card Production Standards is enforced by the payment brands. The payment brands may have their own compliance programs and may apply penalties or fines to entities that are not compliant or suffer a breach. Therefore, a vendor who wants to know if they will be penalized if their vault is not compliant should ask the payment brands that they work with or are contracted by. References:
Payment Card Industry (PCI) Card Production Security Assessors Program Guide, Version 1.0, April
2019, page 51
PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 62
質問 # 30
A vendor is unsure which forms are needed to complete an assessment. Who should they ask?
- A. PCI SSC
- B. Issuing banks
- C. Assessor
- D. Payment brands
正解:C
解説:
Explanation
The assessor is the person who conducts the PCI Card Production Security Assessment and prepares the Card Production Report on Compliance (ROC) and the Card Production Attestation of Compliance (AOC). The assessor should be familiar with the forms that are needed to complete an assessment and provide guidance to the vendor on how to fill them out. The assessor should also ensure that the forms are consistent with the PCI Card Production Standards and the PCI CPSA Qualification Requirements. The other options are not the best sources of information for the vendor, as they may not be directly involved in the assessment process or have the expertise to advise on the forms. References:
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 81 PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 10 PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 3 PCI Card Production and Provisioning Attestation of Compliance, Version 1.0, April 2019, page 22
質問 # 31
Which of the following principles must be enforce by the HSA Access Control system?
- A. Dual control and dual presence
- B. Dual guard entry when required
- C. Dual presence
- D. Dual control
正解:A
解説:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the HSA Access Control system must enforce both dual control and dual presence principles. Dual control means that at least two authorized individuals must act together to perform a critical function or access a sensitive area. Dual presence means that at least two authorized individuals must be physically present in the same area at all times. These principles are intended to prevent unauthorized or fraudulent activities by requiring mutual supervision and accountability. Therefore, the HSA Access Control system must ensure that no single individual can enter, exit, or operate within the HSA without the cooperation and the presence of another authorized individual. References:
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
121
PCI Card Production and Provisioning Physical Security Requirements, Version 1.0, April 2019, page
131
質問 # 32
Which of the following must be used by the vendor to protect doors that provide access to buildings containing air conditioning equipment?
- A. Electrical contacts that log each open and close event to a secure system memory
- B. Magnetic contacts that are permanently alarmed and that are connected to the security control-room panels
- C. Security tape that will leave an observable trace each time a door is opened
- D. Physical locks with a limited set of keys under constant supervision by a guard in the security control-room
正解:B
解説:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must use magnetic contacts that are permanently alarmed and that are connected to the security control-room panels to protect doors that provide access to buildings containing air conditioning equipment. The vendor must also ensure that the air conditioning equipment is located in a secure area that is not accessible to unauthorized personnel, and that the air conditioning system is monitored and maintained to prevent unauthorized access or tampering. The vendor must also have procedures to respond to any alarms or incidents related to the air conditioning system, and to report them to the relevant parties. The vendor must not use security tape, electrical contacts, or physical locks alone, as these may not provide adequate protection or detection of unauthorized access or tampering. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 21-221
質問 # 33
A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder's mobile device. Which of the following best describes the vendor's activities?
- A. Over-the-air (OTA) provisioning
- B. Host Card Emulation (HCE) provisioning
- C. Card personalization
- D. Secure Element (SE) provisioning
正解:B
解説:
Explanation
Host Card Emulation (HCE) provisioning is the process of creating and storing cardholder data in a virtual secure element hosted in a remote server, and generating a payment token that can be used by a mobile device to perform a contactless transaction. HCE provisioning is one of the methods of cloud-based provisioning, which does not require the use of a physical secure element on the mobile device. HCE provisioning is different from Secure Element (SE) provisioning, which involves loading cardholder data into a physical secure element embedded or attached to the mobile device. HCE provisioning is also different from Over-the-air (OTA) provisioning, which involves transmitting cardholder data from a remote server to a physical secure element on the mobiledevice using a wireless communication channel. In this scenario, the vendor hosts virtual secure elements holding cardholder information in their data center, and creates a payment token that is sent to the cardholder's mobile device. This best describes the vendor's activities as HCE provisioning. References:
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 8, section
1.3
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 9, section
1.4
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 10, section 1.5 PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 43, Appendix A: Applicability of Requirements
質問 # 34
During an assessment you ask to see employee records for employees with access to the HSA. The records include information about the screening process, including background information from the employee application process. The oldest background Information that is available is for an employee that left the vendor (terminated their contract) one year previously. You note this as non-compliant, why?
- A. The vendor must only retain background information for all current employees, not for those that have been terminated
- B. The vendor must retain the background information for at least 18 months after termination of contract
- C. Employee information must be securely destroyed (e.g. securely wiped) within 2 years (after termination of contract)
- D. Employee information, including background checks, must be stored for at least seven years
正解:C
解説:
Explanation
According to the PCI Card Production Logical Security Requirements, the vendor must securely destroy all employee information, including background checks, within two years of the employee's termination of contract. This is to prevent unauthorized access to sensitive employee data and to comply with the PCI DSS requirement 3.1, which states that cardholder data must not be stored longer than necessary. The vendor must also have a documented policy and procedure for the secure destruction of employee information, and must maintain a log of all destruction activities. References:
PCI Card Production Logical Security Requirements, v2.0, April 2019, page 19, requirement 6.1.1 PCI DSS, v3.2.1, May 2018, page 25, requirement 3.1
質問 # 35
Which of the following statements is true in relation to visitor access badges?
- A. Unissued visitor access badges must be securely stored
- B. Each visitor entering the facility must be issued and must visibly wear a disposable ID badge that identifies them as a non-employee
- C. Each visitor entering the facility must wear their issued access badge above waist height
- D. Badges with access-controls must not be issued to visitors
正解:B
質問 # 36
For how long must a vendor retain all applicant and employee background information on file?
- A. It is not a requirement to store this information beyond termination of the contract
- B. For at least 12 months after termination of the contract of employment
- C. For at least 24 months after termination of the contract of employment
- D. For at least 18 months after termination of the contract of employment
正解:B
解説:
Explanation
According to the PCI CPSA Qualification Requirements, one of the administrative requirements for CPSA Companies is to retain all applicant and employee background information on file for at least 12 months after termination of the contract of employment. This is to ensure that the CPSA Company can provide evidence of the background checks performed on the CPSA Employees or other personnel involved in card production and provisioning activities. The background checks should include criminal history, employment history, education verification, and reference checks, and should be conducted at least every two years or upon rehire. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 6.1.2, Page 111
質問 # 37
Which of the following statements is true about the facility's non-emergency exits?
- A. They must be configured to prevent staff tailgating
- B. They must be fitted with biometric access-control devices
- C. They may be left unlocked when a guard is present
- D. They must be contact-alarm monitored only when card production activities are taking place
正解:A
解説:
Explanation
According to the PCI Card Production and Provisioning Physical Security Requirements, the vendor must ensure that all non-emergency exits are configured to prevent staff tailgating. Tailgating is the act of following someone closely through a door or other entry point without proper authorization. The vendor must use access-control devices, such as turnstiles, mantraps, or biometric readers, to prevent tailgating and unauthorized access or exit. The vendor must also monitor and alarm all non-emergency exits 24/7, and have procedures to respond to any alarms or incidents. The vendor must not leave any non-emergency exits unlocked, even when a guard is present, as this may compromise the security of the facility and the card production andprovisioning materials. References: PCI Card Production and Provisioning Physical Security Requirements and Test Procedures v3.0, January 2022, pages 8-91
質問 # 38
A CPSA Company has submitted multiple reports that are incomplete and do not contain the information described in the reporting instructions. Which of the following are possible outcomes?
- A. They may be fined by PCI SSC
- B. They may be fined by the applicable payment brands
- C. They may be put into remediation or revoked by PCI SSC
- D. They may be put into remediation or revoked by the applicable payment brands
正解:C
解説:
Explanation
The PCI SSC has a quality assurance (QA) program that monitors the performance and compliance of CPSA Companies and CPSA Employees. The QA program is based on eight guiding principles that the assessor community must adhere to, one of which is to maintain consistent assessor procedures and reporting. The PCI SSC reviews the reports submitted by the CPSA Companies and provides feedback on the quality and completeness of the reports. If a CPSA Company submits multiple reports that are incomplete and do not contain the information described in the reporting instructions, they may be violating the QA program and the CPSA Qualification Requirements. The PCI SSC may take corrective actions against the CPSA Company, such as issuing a warning, requiring additional training, imposing remediation, or revoking the CPSA Company status. Remediation is a process that requires the CPSA Company to improve in one or more areas of their operations and demonstrate compliance with the PCI SSC requirements. Revocation is a process that terminates the CPSA Company status and removes the CPSA Company from the list of qualified assessors on the PCI SSC website. The PCI SSC has the sole authority and discretion to determine the appropriate corrective actions for any non-compliance issues by the CPSA Companies or CPSA Employees. The payment brands do not have the power to put the CPSA Companies into remediation or revoke their status, nor do they have the power to fine them. The payment brands may, however, impose their own sanctions or penalties on the card production entities that are assessed by the CPSA Companies, based on their own contractual agreements and compliance programs. References:
Card Production Security Assessor (CPSA) Program Guide, Section 3 and 5.1 Card Production Security Assessor (CPSA) Qualification Requirements, Section 3.1 and 3.2 CPSA Remediation Statement
質問 # 39
Which document describes the results of an assessment, and is signed by both the assessor and the vendor executive officer?
- A. Security Assessment Questionnaire (SAQ)
- B. Report on Compliance (ROC)
- C. Attestation of Compliance (AOC)
- D. Letter of Approval (LOA)
正解:C
解説:
Explanation
The Attestation of Compliance (AOC) is the document that describes the results of a PCI Card Production Assessment, and is signed by both the CPSA and the vendor executive officer. The AOC is a summary of the findings and conclusions of the assessment, and indicates whether the vendor meets the PCI Card Production Logical Security Requirements and/or the PCI Card Production Physical Security Requirements. The AOC must be completed using the template provided by PCI SSC, and must be submitted to PCI SSC along with the Report on Compliance (ROC) and other supporting documents. The AOC must also be provided to the vendor's clients upon request. References:
PCI Card Production Security Assessor (CPSA) Qualification Requirements, v1.0, April 2019, page 11, requirement 7.1.1 PCI Card Production and Provisioning Attestation of Compliance, v2.0, April 2019, page 1, section 1
質問 # 40
......
有効なCPSA_P_Newテスト解答とPCI CPSA_P_New試験PDF:https://www.jpntest.com/shiken/CPSA_P_New-mondaishu
PCI CPSA_P_New認定リアル2024年最新の模擬試験:https://drive.google.com/open?id=1ueQi8hyWAOcDs8TwW3PGgs_75TdRMqca