Authentication & Access Controls in Payments Flashcards
6 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Authentication & Access Controls in Payments flashcards as text
In payments risk management, 'corporate account takeover' (CATO) is BEST described as:
Answer: Criminals stealing business online banking credentials to initiate unauthorized ACH debits or wire transfers
CATO refers to cybercriminals compromising a business's online banking login credentials — often through malware or phishing — and then using those credentials to initiate unauthorized payments such as ACH batch files or wire transfers. It is a major fraud vector specifically targeting commercial payment accounts.
Multi-factor authentication (MFA) in payment systems requires users to present credentials from:
Answer: Two or more independent factors drawn from different categories: something you know, something you have, and/or something you are
True MFA requires factors from at least two distinct categories: knowledge (password/PIN), possession (hardware token, mobile device), or inherence (biometrics). Using two passwords is not MFA — both belong to the same category. The independence of the factors is what makes MFA effective.
The principle of 'least privilege' applied to payment system access controls means users should be granted:
Answer: Access rights limited to only what is necessary to perform their specific job duties
Least privilege is a foundational access control principle that limits each user's system permissions to exactly what their role requires — no more. This minimizes the damage that can result from compromised credentials, insider threat, or accidental misuse.
Which control BEST prevents a single employee from both initiating a payment AND approving that same payment for processing?
Answer: Segregation of duties between payment initiation and payment approval roles
Segregation of duties (SoD) assigns the initiation and authorization steps of a payment workflow to different individuals, ensuring no single employee can complete a fraudulent transaction without a second party's involvement. MFA and password controls address authentication, not authorization workflow separation.
'Out-of-band' authentication for high-value payment transactions refers to verifying the transaction through:
Answer: A separate communication channel from the one used to initiate or request the payment
Out-of-band authentication uses a different channel — such as a phone call or SMS to a registered number — to confirm a transaction that was initiated via online banking or another channel. This defeats man-in-the-browser attacks because the attacker controlling the primary channel cannot intercept the secondary channel.
Which review process should be performed on a REGULAR, recurring basis to ensure that terminated employees and role-changed staff cannot access payment systems?
Answer: User access recertification (periodic review of access rights)
User access recertification (also called access rights review or attestation) is a periodic process in which managers certify that each employee's system access remains appropriate for their current role. This catches orphaned accounts, over-permissioned users, and access rights retained after role changes or termination.