โ† All APRP Flashcard Decks

Data Security & Privacy Flashcards

6 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Data Security & Privacy flashcards as text
  1. A payment processor discovers that a developer included live PANs in application log files. What is the most critical immediate action?

    Answer: Purge the log files containing live PANs and remediate the logging code to prevent recurrence

    Log files containing live PANs must be immediately purged and the application code fixed to prevent future logging of sensitive data, as this violates PCI DSS Requirement 3.

  2. What distinguishes data masking from data encryption in a payment environment?

    Answer: Masking replaces data with non-sensitive characters for display, while encryption scrambles data in a reversible way using a key

    Data masking replaces portions of sensitive data (e.g., showing only last four digits of a PAN) for display purposes, while encryption transforms the full data into ciphertext that can be reversed with the proper key.

  3. Under the California Consumer Privacy Act (CCPA), what right do California consumers have regarding their personal data collected by businesses?

    Answer: The right to know what personal information is collected, to delete it, and to opt out of its sale

    The CCPA grants California consumers the right to know what personal information is collected and used, the right to request deletion, and the right to opt out of the sale of their personal information.

  4. Which of the following is the best example of a detective control for data security in a payment environment?

    Answer: Implementing file integrity monitoring to alert on unauthorized changes to cardholder data systems

    File integrity monitoring detects unauthorized changes after they occur, making it a detective control that triggers alerts when cardholder data system files are modified.

  5. What is 'data minimization' as it applies to payment privacy risk management?

    Answer: Collecting and retaining only the personal and payment data that is strictly necessary for the intended business purpose

    Data minimization is the privacy principle of collecting, using, and retaining only the minimum personal and payment data necessary for a specific, lawful purpose.

  6. A payment organization receives a subpoena for cardholder transaction records. Which principle should guide how much data is produced in response?

    Answer: Produce only the data specifically requested and legally required, consistent with data minimization and privacy obligations

    Organizations should produce only what is specifically requested and legally required, balancing legal obligations with privacy duties and data minimization principles.