Certified Payment Industry Security Implementer - Developer Exam Prep
Free practice questions

Free CPISI-D Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The CPISI-D exam has 50 questions and runs 1 hours.

These 10 free CPISI-D questions are organized by exam domain, so you can see how each part of the Certified Payment Industry Security Implementer - Developer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Background of Payment Industry

Question 1

A customer cancels an order in a conventional two-message card-payment flow. The issuer has approved an authorization and placed a hold, but the merchant has not captured the transaction. The processor supports releasing an uncaptured authorization. To cancel without first completing the purchase, the merchant should:

Show answer & explanation

Correct answer: C - Send an authorization reversal to release the existing hold.

Domain 2: Security By Design

Question 2

A portal permits users to retrieve only their own merchant's invoices. In an authorized test, Lina changes the invoice ID and retrieves a different merchant's invoice using her valid session. The handler checks that the ID is an integer and passes it as a bound SQL parameter. The missing server-side check is:

Show answer & explanation

Correct answer: A - Whether Lina is entitled to access that particular invoice.

Question 3

Every encryption worker in a payment service uses the same AES-GCM key. Each worker maintains its own persistent nonce counter, and a newly added worker starts at zero. All authentication tags verify during testing. Before scaling out, what must the architect change?

Show answer & explanation

Correct answer: A - Allocate nonoverlapping, restart-safe nonce ranges across all workers using that key.

Domain 3: PA-DSS and S3 Standards

Question 4

A software vendor presents a historical PA-DSS listing during procurement. The buyer instead wants assurance that security requirements, code review, vulnerability intake, and authenticated patch distribution are sustained across the vendor's product portfolio. Which PCI assessment addresses this request?

Show answer & explanation

Correct answer: D - PCI Secure Software Lifecycle assessment of the vendor's development practices.

Domain 4: Payment Card Industry Security Standards

Question 5

An online merchant proposes a fraud-investigation journal containing encrypted card verification codes (CVVs) and transaction identifiers, but no primary account numbers. Authorization completes immediately; capture occurs the following day. Under PCI DSS v4.0.1, which retention decision is acceptable?

Show answer & explanation

Correct answer: D - Make the CVV unrecoverable when authorization completes; use transaction identifiers for subsequent investigation.

Question 6

A checkout page loads a third-party script directly into shoppers' browsers. The merchant's tamper detector compares only files stored on its own web servers; it reports no changes. PCI DSS v4.0.1 Requirement 11.6.1 applies to this page. What additional view is essential to detect changes outside the origin server's files?

Show answer & explanation

Correct answer: C - Security-impacting HTTP headers and payment-page script content as received by the shopper's browser.

Domain 5: OWASP Web and Mobile Security

Question 7

A merchant portal authenticates users with a cookie marked Secure, HttpOnly, and SameSite=None. While an operator is signed in, an unrelated website submits a form that changes the operator's payout destination. The browser attaches the cookie. No attacker code runs within the merchant's origin, and the portal checks neither an anti-CSRF token nor the request origin. Which diagnosis fits these findings?

Show answer & explanation

Correct answer: C - Cross-site request forgery: the browser supplies credentials for an attacker-induced state-changing request.

Domain 6: Common Coding Vulnerabilities

Question 8

A payment provider retries a success webhook after the merchant's acknowledgment times out. Both deliveries have the same event ID and valid signatures, but different workers credit the customer's stored balance twice. The provider permits duplicate and out-of-order delivery. Which implementation prevents a second credit without discarding legitimate payment events?

Show answer & explanation

Correct answer: B - Enforce event-ID uniqueness and post the balance credit atomically in the same database transaction.

Question 9

A report endpoint uses this pseudocode. The database driver genuinely binds the second argument as data: execute("SELECT created_at, amount FROM payments WHERE merchant_id = ? ORDER BY " + request.sort, [session.merchant_id]) The client should be able to select only date or amount ordering. What should replace the direct concatenation of request.sort?

Show answer & explanation

Correct answer: B - Map the two permitted choices to fixed server-owned column names, rejecting every other supplied value.

Domain 7: Threat Modelling

Question 10

Triage lists two vulnerabilities with CVSS v4.0 Base scores of 8.2. One is reachable from the internet and exposes payment encryption keys. The other affects a disabled parser, with no identified execution path in the deployed service. What do the equal scores establish?

Show answer & explanation

Correct answer: A - Both have High technical severity; exposure and business impact can justify different remediation priorities.

That's 10 of 1,030

The full bank has 1,020 more CPISI-D questions with explanations.

Continue in the free practice test →

View plans