CPSA_P_New Card Production Security AssessorCPSA Physical NewExam Questions and Answers
Who is required to approve visitor entry to the HSA or cloud-based provisioning environment?
A vendor receives cardholder information and keys from a bank. The vendor then performs the following:
* Uses its HSM to create keys
* Creates cardholder information specific to each cardholder, including name and PAN
* Formats the data for the hardware that will put it on a card
* Writes it to an encrypted file
Which of the following best describes this process?
During an assessment you do a walk-through of bringing card products into the HSA using the goods-tools trap. You act as production staff, using an empty cardboard box as the card products. During the process, the guard escorts you, along with the box, into the pre-press room. What is your conclusion?
Which document describes the results of an assessment, and is signed by both the assessor and the vendor executive officer?
Before you go on-site, the vendor’s primary contact communicates a legitimate reason for delaying the assessment for several months. Who can approve the change in the report delivery schedule?
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?
A vendor uses codes from a chip manufacturer to ‘unlock’ chips and prepare them for use by adding applications and keys. Which of the following best describes this process?
How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?
To liberate a person detected inside of the inner shipping delivery room and stop the alarm, the software monitoring the access-control system must only allow the opening of which door?
