APRP Physical and Information Security 5 — Questions and Answers
Question 1: An organization discovers that a former employee's badge still grants access to the payments server room one month after termination. Which process failed?
- Background check procedures
- Access revocation as part of the offboarding process (Correct answer)
- Security awareness training
- Physical intrusion detection monitoring
Correct answer: Access revocation as part of the offboarding process
Timely revocation of physical and logical access during employee offboarding is a fundamental control to prevent unauthorized access by former staff.
Question 2: Which concept requires that no single individual can complete a sensitive payment transaction or system change without involvement from at least one other person?
- Least privilege
- Separation of duties (Correct answer)
- Need to know
- Defense in depth
Correct answer: Separation of duties
Separation of duties splits critical tasks between two or more individuals to prevent fraud and errors by any single person.
Question 3: A payment company's intrusion detection system (IDS) generates hundreds of alerts daily, but staff rarely investigate them. This BEST illustrates which risk?
- Insufficient firewall rules
- Alert fatigue leading to missed real security events (Correct answer)
- Lack of encryption on the IDS feed
- Inadequate physical access controls
Correct answer: Alert fatigue leading to missed real security events
Alert fatigue occurs when too many low-priority alerts cause analysts to overlook or ignore genuinely critical security events.
Question 4: Which of the following BEST describes the purpose of a penetration test in a payments security program?
- To measure employee satisfaction with security policies
- To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do (Correct answer)
- To verify that antivirus definitions are up to date
- To audit financial transaction accuracy
Correct answer: To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do
Penetration testing proactively identifies and validates security weaknesses by mimicking the tactics of actual attackers.
Question 5: Under PCI DSS, what is the requirement for protecting cryptographic keys used to encrypt cardholder data?
- Keys may be stored in plaintext if the server is physically secured
- Keys must be stored securely and access restricted to the fewest custodians necessary, with key-management procedures documented (Correct answer)
- Keys should be changed only when a breach occurs
- Keys can be shared across all system administrators for operational efficiency
Correct answer: Keys must be stored securely and access restricted to the fewest custodians necessary, with key-management procedures documented
PCI DSS Requirement 3 mandates strict key management including secure storage, limited access, and documented procedures for the full key lifecycle.
Question 6: What is the MOST significant physical security risk associated with deploying unattended ATMs in low-traffic locations?
- Higher electricity consumption
- Increased vulnerability to skimmer installation and card trapping with less chance of detection (Correct answer)
- Greater wear on mechanical components
- Reduced cash replenishment frequency
Correct answer: Increased vulnerability to skimmer installation and card trapping with less chance of detection
Low foot traffic reduces the chance that skimmer installations or card trapping devices will be noticed and reported promptly.
Question 7: Which standard provides a framework for information security management systems (ISMS) that payment organizations may adopt alongside PCI DSS?
- ISO 9001
- ISO/IEC 27001 (Correct answer)
- ISO 14001
- IEEE 802.11
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard for establishing, implementing, and maintaining an ISMS and complements PCI DSS requirements.
An organization discovers that a former employee's badge still grants access to the payments server room one month after termination.
Which process failed?