← All APRP Flashcard Decks

Physical and Information Security Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Physical and Information Security flashcards as text
  1. A payments organization uses multi-factor authentication (MFA). Which combination correctly represents three different authentication factors?

    Answer: Smart card, fingerprint, and one-time passcode

    Smart card (something you have), fingerprint (something you are), and OTP (something you have/know) span three distinct factor categories.

  2. Which attack exploits physical proximity to skim contactless payment card data without the cardholder's knowledge?

    Answer: RFID/NFC eavesdropping

    RFID/NFC eavesdropping captures contactless card data from a short distance using a covert reader.

  3. What is the purpose of a Hardware Security Module (HSM) in a payment processing environment?

    Answer: To securely generate, store, and manage cryptographic keys

    An HSM is a tamper-resistant physical device that manages cryptographic keys and performs encryption operations securely.

  4. Under PCI DSS, which media type requires secure destruction when no longer needed to protect cardholder data?

    Answer: All physical and electronic media containing cardholder data

    PCI DSS Requirement 9 requires secure destruction of all media types — paper, electronic, optical — that contain cardholder data.

  5. An employee working from home accesses the corporate payment platform. Which control is MOST important to mandate?

    Answer: VPN with MFA connecting to the corporate network

    A VPN with MFA ensures encrypted, authenticated access to payment systems from remote locations.

  6. Which physical security control is specifically designed to detect and alert on unauthorized removal of payment terminals from their installed locations?

    Answer: Anti-tampering tilt and motion sensors on terminals

    Tilt and motion sensors trigger alerts when terminals are moved or manipulated, helping detect skimmer installations.

  7. What is the MAIN risk of printing cardholder data (such as PANs) on receipts or reports in a payments environment?

    Answer: Printed data can be stolen, lost, or improperly disposed of, exposing sensitive account information

    Printed cardholder data creates physical copies that can be accessed by unauthorized individuals if not properly secured and destroyed.