Physical and Information Security Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Physical and Information Security flashcards as text
Which control is MOST effective at preventing tailgating (piggybacking) into a secure payments data center?
Answer: Mantrap/airlock entry vestibule
A mantrap forces one person at a time to badge through two doors, physically preventing tailgating.
Under PCI DSS, how long must video surveillance footage from cardholder data environment entry points be retained?
Answer: 90 days
PCI DSS Requirement 9 mandates that physical security camera footage be retained for at least 90 days.
A payments processor discovers an unknown USB device plugged into a point-of-sale terminal. What is the FIRST action to take?
Answer: Remove the device and preserve it as evidence
Removing and preserving the device maintains the chain of custody for forensic investigation without introducing further risk.
Which encryption standard is required by PCI DSS for protecting stored cardholder data at rest?
Answer: AES-256 or equivalent strong cryptography
PCI DSS requires strong cryptography such as AES-256 for protecting stored cardholder data.
What does the principle of 'clean desk policy' PRIMARILY address in a payments security context?
Answer: Preventing unauthorized access to sensitive documents and media left unattended
A clean desk policy reduces the risk of sensitive cardholder data or credentials being seen or taken by unauthorized individuals.
In a payments environment, what is the primary purpose of network segmentation?
Answer: To isolate the cardholder data environment and reduce the scope of PCI DSS compliance
Network segmentation limits the cardholder data environment to a defined zone, shrinking the PCI DSS audit scope and attack surface.
Which of the following BEST describes a 'defense in depth' strategy for a payment processing facility?
Answer: Using multiple overlapping layers of physical and logical security controls
Defense in depth uses layered controls so that if one fails, additional safeguards continue to protect the environment.