IS3445 CHAP 10 MAINTAINING PCI DSS COMPLIANCE FOR E-COMMERCE WEB SITES Flashcards
___ is a processing strategy in which transactions are not handled immediately; rather, receipts are collected and processed as a batch.
Batch processing
___ is a protocol within the TCP/IP protocol suite designed to synchronize clocks of computer systems over packet-switched networks.
(NTP) Network Time Protocol
___ occurs when companies send their information to third party service providers for storage, processing or transmission.
Outsourcing
___ is a set of standards designed to help organizations that process credit card payments prevent fraud by having increased control over data and its exposure.
(PCI DSS) Payment Card Industry Data Security Standard
___ is a credit card transaction in which processing is immediate.
Real time processing
___ is a unique client identifier sent over a wireless network as a simple password that is used for authentication between a wireless client and and access point.
(SSID) Service set identifier
___ is a person trained to conduct PCI DSS Security Assessments.
(QSA) Qualified Security Assessor
___ is data encryption method used on 802.11 wireless LANs.
(WPA)Wi-Fi Protected Access
- Because it is a perimeter defense strategy, a firewall is not a critical element of cardholder data security.
TRUE OR FALSE
FALSE
- You are tasked with designing a security policy for cardholder data. Which of the following are recommended security strategies for cardholder data? (Select three)
- Verify that data is retained for a limited period of time.
- Verify that user groups are used to access sensitive data areas
- Verify that data is disposed of properly.
- Verify that passwords are encrypted during transmission.
Verify that data is retained for a limited period of time.
Verify that data is disposed of properly.
Verify that passwords are encrypted during transmission.
- Use WEP to secure communications sent over a wired network.
TRUE OR FALSE
FALSE
- Which of the following elements are typically examined during a PCI DSS Security Assessment? (Select two)
- Firewalls
- Network hardware
- Employee background
- Cached files
Firewalls
Network hardware
- When credit card transactions are handled in ___, receipts are often collected over a day or week and then sent in as multiple sets of information.
Batch processing
- PSS DSS is a set of standards designed to help organizations that process credit card payments prevent fraud by having increased control over data and its exposure.
TRUE OR FALSE
TRUE
- When credit card transactions are handled in ___, a consumer’s credit card is debited immediately to complete a purchase.
Real-time processing