Physical and Information Security Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Physical and Information Security flashcards as text
In payments security, what is 'data masking' PRIMARILY used for?
Answer: Replacing sensitive data with realistic but fictitious values in non-production environments
Data masking substitutes real cardholder data with realistic dummy values so developers and testers can work without exposing live account numbers.
Which type of social engineering attack targets specific high-value individuals within a payments organization, such as the CFO or CTO?
Answer: Spear phishing (whaling)
Whaling is a targeted spear phishing attack aimed at senior executives to authorize fraudulent payments or disclose credentials.
A rogue employee copies cardholder data to a personal thumb drive before leaving the company. Which control would BEST have prevented this?
Answer: Data Loss Prevention (DLP) tools with USB port blocking
DLP with USB port control prevents unauthorized copying of sensitive data to removable media.
PCI DSS requires that all default passwords on payment system components be changed. Why is this critical?
Answer: Default passwords are publicly known and easily exploited by attackers
Default credentials are documented in vendor manuals and widely known; leaving them unchanged is one of the most common and easily exploited vulnerabilities.
What is the primary security benefit of using point-to-point encryption (P2PE) in a card-present payment environment?
Answer: It encrypts cardholder data immediately at the point of interaction, preventing merchant systems from ever seeing plaintext card data
P2PE encrypts card data at the terminal before it reaches merchant systems, greatly reducing the risk of cardholder data theft and PCI DSS scope.
Which framework specifically governs information security risk management for payment card industry participants?
Answer: PCI DSS (Payment Card Industry Data Security Standard)
PCI DSS is the primary standard governing security requirements for entities that store, process, or transmit payment card data.
What is 'shoulder surfing' in a payments security context?
Answer: Visually observing someone entering a PIN or password without their knowledge
Shoulder surfing involves looking over someone's shoulder to capture PINs, passwords, or other sensitive data being entered.