Data Security & Privacy Flashcards
6 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Data Security & Privacy flashcards as text
What is the primary objective of the Payment Card Industry Data Security Standard (PCI DSS)?
Answer: To protect cardholder data and reduce payment card fraud
PCI DSS was established to protect cardholder data environments and reduce payment card fraud by setting security requirements for all entities that store, process, or transmit cardholder data.
Under PCI DSS, which data element is NEVER permitted to be stored after transaction authorization?
Answer: Full magnetic stripe data (track data)
Full magnetic stripe data (track data) is classified as sensitive authentication data and must never be stored after authorization under any circumstances under PCI DSS.
A merchant stores customer PANs in a database. Under PCI DSS, which method is acceptable for protecting stored PANs?
Answer: Encrypting PANs using strong cryptography with proper key management
PCI DSS requires that stored PANs be protected using strong cryptography with associated key management procedures.
What does 'tokenization' accomplish in a payment security context?
Answer: It replaces sensitive cardholder data with a non-sensitive surrogate value (token)
Tokenization replaces sensitive cardholder data such as the PAN with a unique token that has no exploitable value outside the specific system that issued it.
Which US federal law primarily governs the privacy of nonpublic personal financial information held by financial institutions, including payment service providers?
Answer: Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices and protect customers' nonpublic personal financial information.
What is the purpose of network segmentation in a payment card data environment?
Answer: To isolate the cardholder data environment from untrusted networks and reduce PCI DSS scope
Network segmentation isolates the cardholder data environment (CDE) from other networks, reducing the scope of PCI DSS compliance and limiting the exposure of sensitive data.