APRP Data Security & Privacy 2 — Questions and Answers
Question 1: A payment organization suffers a data breach exposing cardholder data. Which entity must be notified immediately under card network rules?
- Only the affected cardholders directly
- The acquiring bank and card networks (e.g., Visa, Mastercard) (Correct answer)
- The Federal Reserve Board exclusively
- The organization's external auditors
Correct answer: The acquiring bank and card networks (e.g., Visa, Mastercard)
Card network rules require immediate notification of the acquiring bank and the relevant card networks when a breach involving cardholder data is discovered.
Question 2: What is the role of a Qualified Security Assessor (QSA) in the PCI DSS compliance process?
- To approve new payment card designs for card networks
- To independently assess and validate an organization's compliance with PCI DSS requirements (Correct answer)
- To process chargebacks on behalf of issuing banks
- To set PCI DSS standards on behalf of the PCI Security Standards Council
Correct answer: To independently assess and validate an organization's compliance with PCI DSS requirements
A QSA is a company certified by the PCI SSC to independently assess an organization's PCI DSS compliance and validate its Report on Compliance (ROC).
Question 3: Which of the following describes a 'skimming' attack in the context of payment data security?
- A phishing email campaign targeting payment card customers
- The theft of card data by attaching a covert device to a payment terminal or ATM (Correct answer)
- A man-in-the-middle attack intercepting online payment transactions
- Social engineering of call center agents to obtain cardholder details
Correct answer: The theft of card data by attaching a covert device to a payment terminal or ATM
Skimming involves attaching a covert device to a payment terminal or ATM to capture magnetic stripe data from cards as they are swiped.
Question 4: Under the GLBA Safeguards Rule, what must a financial institution's information security program include?
- A written policy prohibiting all third-party data sharing
- A designated information security officer and a risk-based written information security program (Correct answer)
- Annual PCI DSS certification by a Qualified Security Assessor
- Real-time monitoring of all customer transactions for fraud
Correct answer: A designated information security officer and a risk-based written information security program
The GLBA Safeguards Rule requires financial institutions to designate a qualified individual to oversee an information security program and implement safeguards based on a risk assessment.
Question 5: What is 'point-to-point encryption' (P2PE) in payment security?
- Encryption of data at rest within the issuer's core banking system
- Encryption of cardholder data from the point of interaction to a secure decryption environment, preventing interception (Correct answer)
- Two-way authentication between a cardholder and their issuing bank
- A VPN tunnel between a merchant's POS system and the acquirer
Correct answer: Encryption of cardholder data from the point of interaction to a secure decryption environment, preventing interception
P2PE encrypts cardholder data immediately at the point of capture and keeps it encrypted until it reaches a secure decryption environment, preventing data from being usable if intercepted.
Question 6: Which PCI DSS requirement specifically addresses the need to regularly test security systems and processes?
- Requirement 3: Protect stored account data
- Requirement 6: Develop and maintain secure systems and software
- Requirement 11: Test security of systems and networks regularly (Correct answer)
- Requirement 12: Support information security with organizational policies and programs
Correct answer: Requirement 11: Test security of systems and networks regularly
PCI DSS Requirement 11 requires organizations to regularly test security systems and processes through activities like vulnerability scans and penetration testing.
A payment organization suffers a data breach exposing cardholder data.
Which entity must be notified immediately under card network rules?