Physical and Information Security Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Physical and Information Security flashcards as text
An organization discovers that a former employee's badge still grants access to the payments server room one month after termination. Which process failed?
Answer: Access revocation as part of the offboarding process
Timely revocation of physical and logical access during employee offboarding is a fundamental control to prevent unauthorized access by former staff.
Which concept requires that no single individual can complete a sensitive payment transaction or system change without involvement from at least one other person?
Answer: Separation of duties
Separation of duties splits critical tasks between two or more individuals to prevent fraud and errors by any single person.
A payment company's intrusion detection system (IDS) generates hundreds of alerts daily, but staff rarely investigate them. This BEST illustrates which risk?
Answer: Alert fatigue leading to missed real security events
Alert fatigue occurs when too many low-priority alerts cause analysts to overlook or ignore genuinely critical security events.
Which of the following BEST describes the purpose of a penetration test in a payments security program?
Answer: To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do
Penetration testing proactively identifies and validates security weaknesses by mimicking the tactics of actual attackers.
Under PCI DSS, what is the requirement for protecting cryptographic keys used to encrypt cardholder data?
Answer: Keys must be stored securely and access restricted to the fewest custodians necessary, with key-management procedures documented
PCI DSS Requirement 3 mandates strict key management including secure storage, limited access, and documented procedures for the full key lifecycle.
What is the MOST significant physical security risk associated with deploying unattended ATMs in low-traffic locations?
Answer: Increased vulnerability to skimmer installation and card trapping with less chance of detection
Low foot traffic reduces the chance that skimmer installations or card trapping devices will be noticed and reported promptly.
Which standard provides a framework for information security management systems (ISMS) that payment organizations may adopt alongside PCI DSS?
Answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard for establishing, implementing, and maintaining an ISMS and complements PCI DSS requirements.