PCIP STUDY QUESTIONS AND ANSWERS
FROM THE PCI TRAINING MANUAL
How does skimming target PCI data? - ANSWER Payment card numbers can
be copied via interfering with POS terminals, ATMs, and kiosks, or by copying
the magnetic stripe with handheld skimmers.
How is phishing used to obtain PCI data? - ANSWER By conducting
reconnaissance work through social engineering and/or breaking in via software
vulnerabilities or e-mails.
How Can Payment Data Be Monetized? - ANSWER By skimming the card to
obtain a complete record of data, and then creating another similar card. Using
card information in "Card-not-present transactions such as e-commerce or mail
order, telephone order." Card data is also sold in bulk to other criminals, who
then use the stolen information to commit fraud.
Who are the targets? - ANSWER: Retail, Food and Beverage, Hospitality,
Financial Services, Nonprofit. EVERYONE!
What is the PCI SSC? - ANSWER Payment Card Industry Security Service
Counsel is an independent industry standards group that oversees the
development and management of Payment Card Industry Data Security
Standards around the world.
What are some of the PCI SSC's founding payment brands? - ANSWER
American Express, Discover Financial, JCB International, MasterCard, Visa
Inc.
What resources are supplied by the PCI SSC? - ANSWER: PCI DSS, PA-DSS,
P2PE, PTS (POI, HSM, and PIN) Card Production and accompanying papers.
A list of QSAs, PA-QSAs, PCIPs, ASVs, certified payment applications, PTS
devices, and P2PE solutions
, PCI Security Standards Council FAQs:
Education and outreach programs.
Participating Organization Membership, Community Meetings, and Feedback.
What is the overview of the PCI DSS? - ANSWER Covers the security of
environments where account data is stored, processed, or sent.
Environments accept account data from payment applications and other sources
(e.g., acquirers).
What is the overview of PCI PA-DSS? ANSWER: It covers secure payment
applications that support PCI DSS compliance.
Payment application receives account information from PIN-entry devices
(PEDs) or other devices and initiates a payment transaction.
What is the overview of PCI P2PE? - Answer Addresses the encryption,
decryption, and key management requirements for point-to-point encryption
solutions.
What is the overview of the PCI PTS-POI. - ANSWER Covers the protection
of sensitive data at the point of interaction devices and their secure components,
such as cardholder PINs and account data, as well as the cryptographic keys
used to safeguard that cardholder data.
What is the general overview of PCI PTS-PIN Security? - ANSWER Covers
the safe management, processing, and transmission of personal identification
number (PIN) data during both online and offline payment card transactions.
What is the overview of PCI PTS-HSM? - Answer Covers the physical, logical,
and device security requirements for protecting hardware security modules.
What is the overview of PCI Card Production? It addresses the physical and
logical security needs for systems and business processes.
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller luzlinkuz. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $11.89. You're not tied to anything after your purchase.