PCIP STUDY
QUESTIONS FROM
PCI TRAINING
MANUAL
How is skimming used to target PCI data? - Answers-Copying payment card numbers
by tampering with POS devices, ATMs, Kiosks or copying the magnetic stripe using
handheld skimmers.
How is phishing used to target PCI data? - Answers-By doing reconnaissance work
through social engineering and or breaking in using software vulnerabilities or e-mails.
How can Payment Data be Monetized? - Answers-By skimming the card to get the full
track of data, and then making another like card. Using the card information in a "Card-
not-present transactions such as e-commerce or mail order, Telephone order. Card data
is also sold in bulk to other criminals who perform their own fraud using the stolen data.
Who all are targeted ? - Answers-Retail, Food and Beaverage, Hospitality, Financial
Services, non-profit. EVERYONE!
What is the PCI SSC ? - Answers-Payment Card Industry Security Service Counsel is
an independent industry standards body providing oversight of the development and
management of Payment Card Industry Data Security Standards on a global basis.
What are some of the PCI SSC founding payment brands. - Answers-American
Express, Discover Financial, JCB International, Master Card, Visa inc.
What are the Resources provided by the PCI SSC? - Answers-PCI DSS, PA-DSS,
P2PE, PTS (POI, HSM and PIN) Card Production, and supporting documents.
Roster of QSAs, PA-QSAs, PCIPs, ASVs, validated payment applications, PTS Devices,
and P2PE solutions
, PCI Security Standards Counsil FAQs
Education and Outreach programs
Participating Organization Membership, Community Meetings, feedback.
What is the overview of PCI DSS? - Answers-Covers security of the environments that
store, process or transmit account data.
Environments receive account data from payment applications and other sources (e.g..,
acquirers).
what is the overview of PCI PA-DSS - Answers-Covers secure payment applications to
support PCI DSS compliance
Payment application recieves account data from PIN-entry devices (PEDs) or other
devices and begins payment transaction.
What is the overview of PCI P2PE - Answers-Covers encryption, decryption, and Key
management requirements for point to point encryption solutions.
What is the overview of PCI PTS-POI? - Answers-Covers the protection of sensitive
data at the point of interaction devices and their secure components, including
cardholder PINs and account data, and the cryptographic keys used in connection with
the protection of that cardholder data.
What is the overview of PCI PTS-PIN Security? - Answers-Covers secure management,
processing and transmission of personal identification number (PIN) data during online
and offline payment card transaction processing.
What is the overview of PCI PTS-HSM - Answers-Covers physical, logical and device
security requirements for securing hardware security modules.
What is the overview of PCI Card Production - Answers-Covers physical and logical
security requirements for systems and business processes.
What PCI DSS compliance program does American Express develop and maintain? -
Answers-Data Security Operating Policy (DSOP)
What PCI DSS compliance program does Discover develop and maintain? - Answers-
Discover Information Security Compliance (DISC)
What PCI does DSS compliance program does JCB develop and maintain? - Answers-
Data Security Program
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Greaterheights. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $10.99. You're not tied to anything after your purchase.