Data Security & Privacy Flashcards
6 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Data Security & Privacy flashcards as text
A payment organization suffers a data breach exposing cardholder data. Which entity must be notified immediately under card network rules?
Answer: The acquiring bank and card networks (e.g., Visa, Mastercard)
Card network rules require immediate notification of the acquiring bank and the relevant card networks when a breach involving cardholder data is discovered.
What is the role of a Qualified Security Assessor (QSA) in the PCI DSS compliance process?
Answer: To independently assess and validate an organization's compliance with PCI DSS requirements
A QSA is a company certified by the PCI SSC to independently assess an organization's PCI DSS compliance and validate its Report on Compliance (ROC).
Which of the following describes a 'skimming' attack in the context of payment data security?
Answer: The theft of card data by attaching a covert device to a payment terminal or ATM
Skimming involves attaching a covert device to a payment terminal or ATM to capture magnetic stripe data from cards as they are swiped.
Under the GLBA Safeguards Rule, what must a financial institution's information security program include?
Answer: A designated information security officer and a risk-based written information security program
The GLBA Safeguards Rule requires financial institutions to designate a qualified individual to oversee an information security program and implement safeguards based on a risk assessment.
What is 'point-to-point encryption' (P2PE) in payment security?
Answer: Encryption of cardholder data from the point of interaction to a secure decryption environment, preventing interception
P2PE encrypts cardholder data immediately at the point of capture and keeps it encrypted until it reaches a secure decryption environment, preventing data from being usable if intercepted.
Which PCI DSS requirement specifically addresses the need to regularly test security systems and processes?
Answer: Requirement 11: Test security of systems and networks regularly
PCI DSS Requirement 11 requires organizations to regularly test security systems and processes through activities like vulnerability scans and penetration testing.