APRP Physical and Information Security 2 — Questions and Answers
Question 1: Which control is MOST effective at preventing tailgating (piggybacking) into a secure payments data center?
- Security awareness training
- Mantrap/airlock entry vestibule (Correct answer)
- CCTV surveillance cameras
- Badge access logs review
Correct answer: Mantrap/airlock entry vestibule
A mantrap forces one person at a time to badge through two doors, physically preventing tailgating.
Question 2: Under PCI DSS, how long must video surveillance footage from cardholder data environment entry points be retained?
- 30 days
- 60 days
- 90 days (Correct answer)
- 180 days
Correct answer: 90 days
PCI DSS Requirement 9 mandates that physical security camera footage be retained for at least 90 days.
Question 3: A payments processor discovers an unknown USB device plugged into a point-of-sale terminal. What is the FIRST action to take?
- Plug it into an isolated PC to inspect contents
- Remove the device and preserve it as evidence (Correct answer)
- Format and reuse the device
- Ignore it if transactions are processing normally
Correct answer: Remove the device and preserve it as evidence
Removing and preserving the device maintains the chain of custody for forensic investigation without introducing further risk.
Question 4: Which encryption standard is required by PCI DSS for protecting stored cardholder data at rest?
- DES with 56-bit keys
- RC4 stream cipher
- AES-256 or equivalent strong cryptography (Correct answer)
- MD5 hashing
Correct answer: AES-256 or equivalent strong cryptography
PCI DSS requires strong cryptography such as AES-256 for protecting stored cardholder data.
Question 5: What does the principle of 'clean desk policy' PRIMARILY address in a payments security context?
- Physical ergonomics for employees
- Preventing unauthorized access to sensitive documents and media left unattended (Correct answer)
- Reducing clutter for productivity
- Ensuring proper disposal of obsolete equipment
Correct answer: Preventing unauthorized access to sensitive documents and media left unattended
A clean desk policy reduces the risk of sensitive cardholder data or credentials being seen or taken by unauthorized individuals.
Question 6: In a payments environment, what is the primary purpose of network segmentation?
- To increase internet bandwidth
- To isolate the cardholder data environment and reduce the scope of PCI DSS compliance (Correct answer)
- To simplify network management
- To improve application performance
Correct answer: To isolate the cardholder data environment and reduce the scope of PCI DSS compliance
Network segmentation limits the cardholder data environment to a defined zone, shrinking the PCI DSS audit scope and attack surface.
Question 7: Which of the following BEST describes a 'defense in depth' strategy for a payment processing facility?
- Deploying a single highly sophisticated firewall
- Using multiple overlapping layers of physical and logical security controls (Correct answer)
- Relying solely on encryption for data protection
- Implementing one strong authentication method
Correct answer: Using multiple overlapping layers of physical and logical security controls
Defense in depth uses layered controls so that if one fails, additional safeguards continue to protect the environment.
Which control is MOST effective at preventing tailgating (piggybacking) into a secure payments data center?