PCI Card Production Security AssessorCPSA Physical NewExam Sample Questions:
1. During an assessment you ask to see employee records for employees with access to the HSA. The records include information about the screening process, including background information from the employee application process. The oldest background Information that is available is for an employee that left the vendor (terminated their contract) one year previously. You note this as non-compliant, why?
A) Employee information must be securely destroyed (e.g. securely wiped) within 2 years (after termination of contract)
B) The vendor must only retain background information for all current employees, not for those that have been terminated
C) Employee information, including background checks, must be stored for at least seven years
D) The vendor must retain the background information for at least 18 months after termination of contract
2. For how long must a vendor retain all applicant and employee background information on file?
A) It is not a requirement to store this information beyond termination of the contract
B) For at least 18 months after termination of the contract of employment
C) For at least 12 months after termination of the contract of employment
D) For at least 24 months after termination of the contract of employment
3. A vendor has a list of pre-approved third parties which may be granted access to the facility. Under what circumstances can other third-parties be granted access?
A) None, only people on the pre-approved list may enter
B) When they are approved by the physical security manager or senior management
C) When the third party s liability insurance covers the risk
D) When no card production activities are taking place
4. In relation to guards, which of the following must the vendor ensure?
A) A clear segregation of duties is maintained between guard and reception related job functions
B) A clear segregation of duties is maintained between production staff and guards
C) There is always at least one guard in the HSA and one guard in the security control room at all times
D) There is always at least one guard on-site, including outside of working hours, to monitor security systems and premises
5. Which of the following must every assessor do to maintain their CPSA certification?
A) Earn an additional professional certification from List A or B of the Qualification Requirements (QRs)
B) Earn and document at least 20 hours of Continuing Professional Education (CPE) over 3 years
C) Submit evidence of internal training in a relevant area (as per the QRs)
D) Complete annual requalification training or complete 3 assessments for different facilities each year
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: C | Question # 3 Answer: B | Question # 4 Answer: A | Question # 5 Answer: D |

We're so confident of our products that we provide no hassle product exchange.


By Rex


