โ† All APRP Flashcard Decks

Data Security & Privacy Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Data Security & Privacy flashcards as text
  1. A payments company discovers that a rogue employee has been exfiltrating cardholder data for six months. Which FIRST step best aligns with PCI DSS incident response requirements?

    Answer: Contain the breach and preserve forensic evidence

    PCI DSS Requirement 12.10 mandates that the first incident response priority is containment and evidence preservation to limit damage and support forensic analysis.

  2. What is the primary security advantage of using point-to-point encryption (P2PE) in a retail payment environment?

    Answer: It reduces the scope of PCI DSS compliance by removing clear-text card data from merchant systems

    P2PE encrypts card data at the point of interaction and keeps it encrypted until it reaches the secure decryption environment, removing the merchant's systems from PCI DSS scope.

  3. Under HIPAA's intersection with payment data, which scenario would require BOTH PCI DSS and HIPAA compliance?

    Answer: A healthcare provider accepting credit card payments for patient services

    A healthcare provider that accepts credit card payments handles both cardholder data (PCI DSS) and protected health information (HIPAA), requiring compliance with both frameworks.

  4. An issuer wants to allow cardholders to freeze and unfreeze their cards instantly. Which security principle does this feature PRIMARILY support?

    Answer: Dynamic authorization control

    Card freeze/unfreeze gives cardholders dynamic control over transaction authorization, enabling real-time restriction of card use without cancellation.

  5. A payment fintech transfers European customer payment data to a US-based cloud provider. Under GDPR, which mechanism MOST commonly legitimizes this cross-border data transfer?

    Answer: Standard Contractual Clauses (SCCs)

    Standard Contractual Clauses (SCCs) are the most widely used GDPR-approved mechanism for transferring personal data from the EU to third countries lacking an adequacy decision.

  6. During a PCI DSS audit, an assessor finds that an e-commerce merchant logs full PANs in application error logs. What is the MOST appropriate remediation?

    Answer: Modify the application to mask or truncate PANs in all log outputs

    PCI DSS Requirement 3.3 prohibits storing sensitive authentication data and requires that PANs be masked when displayed; modifying the application to prevent logging full PANs is the correct fix.

  7. Which of the following BEST characterizes the difference between pseudonymization and anonymization in the context of payment data privacy?

    Answer: Anonymization is irreversible; pseudonymized data can be re-identified with additional information

    Anonymization permanently removes the ability to re-identify individuals, while pseudonymization replaces identifiers with a pseudonym that can be reversed using a separate key or mapping.