検証済みのCPSA_P_New試験問題集PDF [2024年最新] 成功の秘訣はここにある [Q11-Q27]

Share

検証済みのCPSA_P_New試験問題集PDF [2024年最新] 成功の秘訣はここにある

ベストを体験せよ!CPSA_P_New試験問題トレーニングを提供していますJPNTest

質問 # 11
A CPSA Company has submitted multiple reports that are incomplete and do not contain the information described in the reporting instructions. Which of the following are possible outcomes?

  • A. They may be fined by the applicable payment brands
  • B. They may be put into remediation or revoked by the applicable payment brands
  • C. They may be fined by PCI SSC
  • D. They may be put into remediation or revoked by PCI SSC

正解:D

解説:
Explanation
The PCI SSC has a quality assurance (QA) program that monitors the performance and compliance of CPSA Companies and CPSA Employees. The QA program is based on eight guiding principles that the assessor community must adhere to, one of which is to maintain consistent assessor procedures and reporting. The PCI SSC reviews the reports submitted by the CPSA Companies and provides feedback on the quality and completeness of the reports. If a CPSA Company submits multiple reports that are incomplete and do not contain the information described in the reporting instructions, they may be violating the QA program and the CPSA Qualification Requirements. The PCI SSC may take corrective actions against the CPSA Company, such as issuing a warning, requiring additional training, imposing remediation, or revoking the CPSA Company status. Remediation is a process that requires the CPSA Company to improve in one or more areas of their operations and demonstrate compliance with the PCI SSC requirements. Revocation is a process that terminates the CPSA Company status and removes the CPSA Company from the list of qualified assessors on the PCI SSC website. The PCI SSC has the sole authority and discretion to determine the appropriate corrective actions for any non-compliance issues by the CPSA Companies or CPSA Employees. The payment brands do not have the power to put the CPSA Companies into remediation or revoke their status, nor do they have the power to fine them. The payment brands may, however, impose their own sanctions or penalties on the card production entities that are assessed by the CPSA Companies, based on their own contractual agreements and compliance programs. References:
Card Production Security Assessor (CPSA) Program Guide, Section 3 and 5.1 Card Production Security Assessor (CPSA) Qualification Requirements, Section 3.1 and 3.2 CPSA Remediation Statement


質問 # 12
A vendor puts cardholder information into a chip by sliding a payment card through a machine that programs it and verifies the data. The chip can make contactless transactions. Which of the following best describes the vendor's activity?

  • A. Card personalization
  • B. Fulfillment
  • C. Host Card Emulation (HCE) provisioning
  • D. Secure Element (SE) provisioning

正解:A

解説:
Explanation
Card personalization is the process of transferring cardholder information, such as account number, name, expiration date, and other data, to a payment card. This can be done by various methods, such as magnetic stripe encoding, embossing, laser engraving, or chip programming. Chip programming is the method of personalizing a card that has an embedded microchip that can store and process data. Chip cards can support contact or contactless transactions, depending on the chip type and the terminal capabilities. Contact transactions require the card to be inserted into a reader, while contactless transactions use radio frequency (RF) communication between the card and the reader. The vendor in the question is performing card personalization by programming the chip and verifying the data on the card. References:
Payment Card Industry (PCI) Card Production and Provisioning - Logical Security Requirements, Section 1.1.1 Payment Card Industry (PCI) Card Production and Provisioning - Physical Security Requirements, Section 1.1.1 Payment Card Industry (PCI) Card Production and Provisioning - Glossary of Terms, Abbreviations, and Acronyms, Definitions of Card Personalization, Chip Card, Contact Card, and Contactless Card


質問 # 13
A vendor discovers that a recent shipment of cards is missing a set. Which of the following responses would you expect in a compliant organization?

  • A. A report is requested by the issuer, the vendor sends it to them, and the issuer handles the incident with the local police
  • B. An immediate call is made to the issuer and the VPA who, between them, contact law enforcement and put together a joint statement
  • C. After an incident review, the VPA, issuer and law enforcement are all notified within 24 hours
  • D. The head of security initiates a meeting, and once the VPA approves the messaging, law enforcement is notified in two days

正解:C

解説:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for card shipment is to ensure that the vendor has an incident response plan in place to handle any card shipment incidents, such as loss, theft, or tampering. The incident response plan should include the following steps1:
The vendor should conduct an incident review to determine the cause and scope of the incident, and document the findings and actions taken.
The vendor should notify the VPA, the issuer, and law enforcement of the incident within 24 hours of discovery, or as soon as possible.
The vendor should cooperate with the VPA, the issuer, and law enforcement in the investigation and resolution of the incident, and provide any evidence or information requested.
The vendor should implement corrective actions to prevent the recurrence of the incident, and report the results to the VPA and the issuer. Therefore, the response that best reflects a compliant organization is option D, which follows the steps of the incident response plan as required by the PCI Card Production Physical Security Requirements. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 6, Requirement 6.2, Page 131


質問 # 14
When must HSA motion detectors generate an alarm event?

  • A. Each time movement is detected and the access-control system indicates the room is occupied
  • B. Each time movement is detected and the access-control system indicates the room is not occupied
  • C. Each time movement is detected outside of regular business hours
  • D. Each time movement is detected

正解:B

解説:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for high-security areas (HSAs) is to have motion detectors that generate an alarm event when movement is detected and the access-control system indicates the room is not occupied. This is to prevent unauthorized access or intrusion to the HSAs, where sensitive card production and provisioning activities take place. The motion detectors should be configured to cover all areas within the HSA and should be tested periodically to ensure proper functionality. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 2, Requirement 2.1.1, Page 61


質問 # 15
A cardholder wants to make purchases using their phone, so they have their cardholder information programmed into their SIM card using their mobile phone provider. Which of the following best describes this system?

  • A. Secure Element (SE) provisioning
  • B. Host Card Emulation (HCE) provisioning
  • C. Card personalization
  • D. Over-the-air (OTA) provisioning

正解:A

解説:
Explanation
According to the PCI Card Production and Provisioning Logical Security Requirements, Secure Element (SE) provisioning is the process of adding cardholder account information to a secure element on a mobile device via an over-the-air or over-the-internet communication channel. A secure element is a tamper-resistant platform that can securely host applications and their confidential and cryptographic data. A SIM card is an example of a secure element that can be used for mobile payments. SE provisioning is different from Host Card Emulation (HCE) provisioning, which is the process of adding cardholder account information to a cloud-based server that emulates a secure element on a mobile device. SE provisioning is also different from card personalization, which is the process of adding cardholder account information to a physical card.
Over-the-air (OTA) provisioning is a generic term that can refer to either SE or HCE provisioning, depending on the type of mobile payment system used. References: PCI Card Production and Provisioning Logical Security Requirements and Test Procedures v3.0, January 2022, pages 6-71


質問 # 16
Which of the following personnel changes must result in the vendor notifying the Vendor Program Administration (VPA)?

  • A. Any change to a role that directly affects the security of card products and related components
  • B. Adding additional rights to someone's role to give them access to the mam production vault
  • C. Hiring someone that will directly interact with the card issuers
  • D. Promoting someone to senior management level

正解:A

解説:
Explanation
According to the PCI CPSA Qualification Requirements, one of the administrative requirements for CPSA Companies is to notify the VPA of any changes to the roles of CPSA Employees or other personnel that directly affect the security of card products and related components. This is to ensure that the CPSA Company maintains the quality and integrity of the CPSA Program and the PCI Card Production Security Standards. The VPA should be notified within 10 business days of the change, and the CPSA Company should provide evidence of the qualifications and training of theaffected personnel. References: PCI CPSA Qualification Requirements, Version 1.1, April 2020, Section 6.1.3, Page 121


質問 # 17
After reviewing their completed ROC and AOC, which state that they are compliant, the vendor wishes to be listed on PCI SSC's list of Compliant Card Vendors. How should you assist them with the listing process?

  • A. Submit only the AOC to PCI SSC
  • B. Inform the vendor that PCI SSC does not list compliant vendors
  • C. Inform the vendor that they must request a listing via the payment brand(s) that received their ROC
  • D. Submit the full ROC to PCI SSC

正解:C

解説:
Explanation
According to the CPSA Program Guide1, PCI SSC does not list compliant card vendors on its website. The PCI SSC only lists the qualified CPSA Companies and CPSA Employees who are authorized to perform PCI Card Production Security Assessments. The PCI SSC also does not receive or review the full ROCs or AOCs from the card vendors or the CPSA Companies. The ROCs and AOCs are submitted by the CPSA Companies to the applicable payment brands that have contracted with the card vendors for card production and provisioning services. The payment brands are responsible for verifying the compliance status of the card vendors and determining whether to list them on their own websites or databases. Therefore, the CPSA Company should inform the vendor that they must request a listing via the payment brand(s) that received their ROC, and that the listing process may vary depending on the payment brand's policies and procedures.
The CPSA Company should also advise the vendor to maintain their compliance with the PCI Card Production Standards and to undergo annual assessments by a qualified CPSA Company.


質問 # 18
An assessor is unsure if log review and interview is sufficient testing for a requirement. Who can best answer this question?

  • A. PCI SSC
  • B. Payment brands
  • C. Issuing banks
  • D. Vendor

正解:A

解説:
Explanation
The PCI SSC (Payment Card Industry Security Standards Council) is the organization that develops and maintains the PCI Card Production Standards and related validation requirements, programs, and supporting documentation. The PCI SSC also provides training and qualification for CPSA Companies and CPSA Employees to perform PCI Card Production Assessments. The PCI SSC is the best source of guidance and clarification for any questions or issues related to the assessment process, testing methods, reporting requirements, and interpretation of the standards. The assessor can contact the PCI SSC by email, phone, or online form, as specified in the CPSA Program Guide1. The payment brands, issuing banks, and vendors are not responsible for defining or explaining the assessment requirements or testing methods, and may not have the same level of expertise or authority as the PCI SSC. References:
Card Production Security Assessor (CPSA) Program Guide, Section 2.1 and 5.1 Card Production Security Assessor (CPSA) Qualification Requirements, Section 1.1 and 2.1


質問 # 19
Where can misprinted, partially finished cards be shredded?

  • A. Either in the HSA destruction room or a loading bay that meets all requirements of a destruction room
  • B. Either in the HSA printing room or destruction room
  • C. Only in the HSA destruction room
  • D. In any HSA room approved by the security manager

正解:C

解説:
Explanation
According to the PCI Card Production Physical Security Requirements, one of the security controls for card destruction is to ensure that misprinted, partially finished, or rejected cards are shredded only in the HSA destruction room. This is to prevent unauthorized access, theft, or misuse of the cards, which may contain sensitive data or features. The HSA destruction room should have adequate security measures, such as locks, alarms, cameras, etc., to protect the cards until they are shredded. The shredding process should render the cards unusable and unrecognizable, and the shredded material should be disposed of securely. References: PCI Card Production Physical Security Requirements, Version 1.0, April 2019, Section 1.1, Objective 5, Requirement 5.1.1, Page 111


質問 # 20
During an assessment you do a walk-through of bringing card products into the HSA using the goods-tools trap. You act as production staff, using an empty cardboard box as the card products. During the process, the guard escorts you, along with the box, into the pre-press room. What is your conclusion?

  • A. Compliant, because the guard escorted you
  • B. Not compliant, because an inventory of the card product did not take place prior to entry
  • C. Not compliant, because the guard escorted you
  • D. Compliant, because the guard ensured that the card product remained under dual control

正解:C

解説:
Explanation
According to the PCI Card Production Physical Security Requirements, the goods-tools trap is a secure area that separates the HSA from the outside world, and is used to control the entry and exit of card products, tools, and other materials. The goods-tools trap must have two doors that are interlocked, meaning that only one door can be opened at a time. The goods-tools trap must also have a CCTV camera and an alarm system. The process of bringing card products into the HSA using the goods-tools trap must follow these steps1:
The card products must be delivered to the goods-tools trap by authorized personnel, who must present their identification to the guard and sign a delivery note.
The guard must verify the identification of the personnel and the quantity and quality of the card products, and record the details in a log.
The guard must then escort the personnel to the first door of the goods-tools trap, and open it using a key or a card reader. The personnel must place the card products inside the goods-tools trap and exit the area. The guard must then lock the first door.
The guard must then notify the production staff inside the HSA that the card products are ready to be collected. The production staff must present their identification to the guard and sign a receipt note.
The guard must then escort the production staff to the second door of the goods-tools trap, and open it using a key or a card reader. The production staff must collect the card products from the goods-tools trap and enter the HSA. The guard must then lock the second door.
In this scenario, the guard escorted the production staff, along with the box, into the pre-press room. This is not compliant, because the guard is not authorized to enter the HSA, and the card products must remain under dual control at all times. The guard should have stayed outside the HSA and only opened the second door of the goods-tools trap for the production staff. This would ensure that the card products are securely transferred from the goods-tools trap to the HSA, and that the guard does not compromise the security of the HSA.
References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 15, requirement 2.1.1 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 16, requirement 2.1.2 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 17, requirement 2.1.3 PCI Card Production Physical Security Requirements, v2.0, April 2019, page 18, requirement 2.1.4


質問 # 21
For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?

  • A. 1 year
  • B. As long as the entity under assessment is a client of the CPSA Company
  • C. Until each applicable payment brand has accepted (and signed off) the ROC and AOC
  • D. 3 years

正解:D

解説:
Explanation
According to the PCI CPSA Program Guide, a CPSA Company must maintain workpapers and technical information obtained during an assessment for a minimum of three years from the date of the assessment. The workpapers and technical information must be stored securely and made available to PCI SSC upon request.
The workpapers and technical information must include, but are not limited to, the following:
The Card Production Report on Compliance (ROC) and the Card Production Attestation of Compliance (AOC) The Card Production Entity's policies and procedures The Card Production Entity's network diagrams and data flow diagrams The results of any testing performed by the CPSA Company or the Card Production Entity The evidence of any remediation actions taken by the Card Production Entity The correspondence between the CPSA Company and the Card Production Entity The correspondence between the CPSA Company and the payment brands The feedback form completed by the Card Production Entity References:
PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 111


質問 # 22
A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder's mobile device. Which of the following best describes the vendor's activities?

  • A. Host Card Emulation (HCE) provisioning
  • B. Card personalization
  • C. Secure Element (SE) provisioning
  • D. Over-the-air (OTA) provisioning

正解:A

解説:
Explanation
Host Card Emulation (HCE) provisioning is the process of creating and storing cardholder data in a virtual secure element hosted in a remote server, and generating a payment token that can be used by a mobile device to perform a contactless transaction. HCE provisioning is one of the methods of cloud-based provisioning, which does not require the use of a physical secure element on the mobile device. HCE provisioning is different from Secure Element (SE) provisioning, which involves loading cardholder data into a physical secure element embedded or attached to the mobile device. HCE provisioning is also different from Over-the-air (OTA) provisioning, which involves transmitting cardholder data from a remote server to a physical secure element on the mobiledevice using a wireless communication channel. In this scenario, the vendor hosts virtual secure elements holding cardholder information in their data center, and creates a payment token that is sent to the cardholder's mobile device. This best describes the vendor's activities as HCE provisioning. References:
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 8, section
1.3
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 9, section
1.4
PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 10, section 1.5 PCI Card Production and Provisioning Logical Security Requirements, v2.0, April 2019, page 43, Appendix A: Applicability of Requirements


質問 # 23
If you have a query about a missing field in the card production reporting template, which organization is best-placed to answer it?

  • A. PCI SSC
  • B. The payment brands
  • C. The vendor
  • D. The issuer

正解:A

解説:
Explanation
The PCI SSC is the best-placed organization to answer a query about a missing field in the card production reporting template, as they are the ones who develop and maintain the template and the standards. The card production reporting template is the mandatory template for use in completing a Card Production Report on Compliance (ROC), which provides detail on how to document the findings of a PCI Card Production Assessment. The template is based on the PCI Card Production and Provisioning LogicalSecurity Requirements and the PCI Card Production and Provisioning Physical Security Requirements, which are also developed and maintained by the PCI SSC. Therefore, the PCI SSC has the authority and the expertise to clarify any issues or questions regarding the template and the standards. The other options are not the best sources of information for the query, as they may not have the same level of knowledge or involvement in the template and the standards. References:
PCI Card Production and Provisioning Template for Report on Compliance, Version 1.0, April 2019, page 31 PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 52 PCI Card Production Security Assessor (CPSA) Program Guide, Version 1.0, April 2019, page 82


質問 # 24
A vendor's HSA access is enforced by a security turnstile they have a logical access-control system that ensures anti pass-back. The device is functioning correctly. When must the status of the access change?

  • A. Upon initial presentation of an authorised badge, prior to completion of the access cycle
  • B. Only when an unauthorised badge is presented
  • C. Upon initial entry of the person into the device, prior to completion of the access cycle
  • D. Only when the person has successfully completed the access cycle

正解:A

解説:
Explanation
According to the PCI Card Production Logical Security Requirements, a vendor's HSA access must be enforced by a security turnstile that has a logical access-control system that ensures anti pass-back. This means that the system must prevent a person from using the same badge to enter or exit the HSA more than once without completing the access cycle. The access cycle is the process of entering or exiting the HSA through the turnstile, which may involve biometric verification, PIN entry, or other authentication methods. The status of the access must change upon initial presentation of an authorised badge, prior to completion of the access cycle, to prevent another person from using the same badge to enter or exit the HSA. For example, if a person presents an authorised badge to enter the HSA, the system must register that the badge is inside the HSA and deny access to anyone else who tries to use the same badge until the person exits the HSA with the same badge. References: PCI Card Production Logical Security Requirements, v2.0, April 2019, page 12


質問 # 25
Who is required to approve visitor entry to the HSA or cloud-based provisioning environment?

  • A. The head of the vendor facility
  • B. The Security Manager, Production Manager, and the head of the vendor facility
  • C. Both the Security Manager and the Production Manager
  • D. The Security Manager

正解:D

解説:
Explanation
According to the PCI Card Production and Provisioning - Physical Security Requirements, the Security Manager is the person who is responsible for approving visitor entry to the High Security Area (HSA) or cloud-based provisioning environment. The HSA is the area where card production and provisioning activities take place, such as card manufacturing, personalization, PIN generation and printing, and fulfillment. The cloud-based provisioning environment is the logical equivalent of the HSA for entities that provide over-the-air (OTA) provisioning or host card emulation (HCE) provisioning services. The Security Manager must ensure that visitors have a legitimate business need toenter the HSA or cloud-based provisioning environment, and must authorize their access in advance. The Security Manager must also maintain a visitor log that records the visitor's name, company, date, time, and purpose of visit, as well as the escort's name and signature. The Security Manager must also ensure that visitors are escorted by authorized personnel at all times, and that they wear a distinctive visitor badge. The head of the vendor facility, the Production Manager, or any other person is not required to approve visitor entry to the HSA or cloud-based provisioning environment, unless they are also designated as the Security Manager by the vendor. References:
Payment Card Industry (PCI) Card Production and Provisioning - Physical Security Requirements, Section 3.1.1 and 3.1.2 Payment Card Industry (PCI) Card Production and Provisioning - Glossary of Terms, Abbreviations, and Acronyms, Definitions of Security Manager, High Security Area, Cloud-Based Provisioning Environment, OTA Provisioning, and HCE Provisioning


質問 # 26
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?

  • A. Issuing banks
  • B. Payment brands
  • C. Assessor
  • D. PCI SSC

正解:B

解説:
Explanation
The PCI SSC does not enforce compliance, nor does it mandate penalties for non-compliance. Compliance with the PCI Card Production Standards is enforced by the payment brands. The payment brands may have their own compliance programs and may apply penalties or fines to entities that are not compliant or suffer a breach. Therefore, a vendor who wants to know if they will be penalized if their vault is not compliant should ask the payment brands that they work with or are contracted by. References:
Payment Card Industry (PCI) Card Production Security Assessors Program Guide, Version 1.0, April
2019, page 51
PCI Card Production Security Assessor (CPSA) Qualification Requirements, Version 1.0, April 2019, page 62


質問 # 27
......

最新の100%合格保証付きの素晴らしいCPSA_P_New試験問題PDF:https://www.jpntest.com/shiken/CPSA_P_New-mondaishu

練習サンプルと問題集と秘訣には2024年最新のCPSA_P_New有効なテスト問題集:https://drive.google.com/open?id=1yfwbGFyCWxNvr1BZdVfVBoEqyJmJojmf

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡