← All APRP Flashcard Decks

Mixed Deck — All APRP Topics Flashcards

100 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All APRP Topics flashcards as text
  1. Which review process should be performed on a REGULAR, recurring basis to ensure that terminated employees and role-changed staff cannot access payment systems?

    Answer: User access recertification (periodic review of access rights)

    User access recertification (also called access rights review or attestation) is a periodic process in which managers certify that each employee's system access remains appropriate for their current role. This catches orphaned accounts, over-permissioned users, and access rights retained after role changes or termination.

  2. What is the purpose of a fraud investigation?

    Answer: To determine whether a suspected fraudulent transaction is confirmed fraud, gather evidence, and prevent future occurrences

    Fraud investigations verify whether fraud occurred, identify perpetrators, document evidence for potential prosecution, recover losses where possible, and identify system improvements to prevent recurrence.

  3. In the context of APRP, 'bust-out fraud' typically involves:

    Answer: Building credit history and then maxing out credit lines with no intent to repay

    Bust-out fraud is a credit fraud scheme where a fraudster gradually builds a good credit profile before suddenly maxing out all available credit and disappearing.

  4. Which trend in the payments industry creates the greatest new career opportunity for APRP-credentialed professionals?

    Answer: Growth of real-time payments networks increasing demand for risk specialists

    The rapid expansion of real-time payment networks like RTP and FedNow creates significant demand for professionals who can manage the associated fraud and risk challenges.

  5. Which metric BEST measures the financial impact of chargebacks on a merchant relative to their overall sales volume?

    Answer: Chargeback-to-transaction ratio

    The chargeback-to-transaction ratio (total chargebacks divided by total transactions) is the primary metric card networks use to monitor merchant chargeback performance.

  6. Which framework specifically governs information security risk management for payment card industry participants?

    Answer: PCI DSS (Payment Card Industry Data Security Standard)

    PCI DSS is the primary standard governing security requirements for entities that store, process, or transmit payment card data.

  7. What is the role of a 'negative file' or 'deny list' in fraud prevention?

    Answer: It contains identifiers associated with past fraud that trigger declines or alerts

    A negative file is a database of known fraudulent identifiers (cards, accounts, devices, IPs) used to automatically block or flag matching future transactions.

  8. What is the role of a 'payment facilitator' (PayFac) in the merchant acquiring ecosystem?

    Answer: It sponsors merchants under its own master merchant account, handling onboarding and settlement

    A PayFac aggregates sub-merchants under its master merchant account, enabling faster onboarding and taking on liability for those merchants.

  9. Under FinCEN's Customer Due Diligence (CDD) Rule, financial institutions are required to identify and verify the identity of beneficial owners who own what minimum percentage of a legal entity customer?

    Answer: 25%

    FinCEN's CDD Rule requires financial institutions to collect and verify the identity of any individual who owns 25% or more of an equity interest in a legal entity customer.

  10. What is the primary purpose of an acquirer's merchant underwriting process from a compliance standpoint?

    Answer: To assess and mitigate financial and fraud risk before onboarding a merchant

    Merchant underwriting evaluates a prospective merchant's financial stability, business type, and risk profile to prevent acquirers from bearing undue liability.

  11. A bank files a Suspicious Activity Report (SAR) on a customer. Under BSA regulations, what is the bank prohibited from doing?

    Answer: Disclosing to the customer that a SAR has been filed

    BSA regulations prohibit 'tipping off' — informing the subject of a SAR that one has been filed, to avoid alerting potential money launderers.

  12. Under the Durbin Amendment to the Dodd-Frank Act, interchange fee caps on debit card transactions apply to issuers with assets of at least:

    Answer: $10 billion

    The Durbin Amendment's interchange cap applies to debit card issuers with consolidated assets of $10 billion or more.

  13. Which card network rule requires acquirers to ensure that merchants do not surcharge debit card transactions while allowing surcharges on credit cards?

    Answer: No-Surcharge rule (Visa/MC settlement)

    The 2013 merchant settlement agreement allows credit card surcharging under specific conditions but prohibits applying those surcharges to debit card transactions.

  14. Under Mastercard's dispute resolution framework, what is the maximum number of days an issuer has to file a chargeback after the transaction processing date for most dispute categories?

    Answer: 120 days

    Mastercard generally allows issuers 120 days from the transaction processing date to file a chargeback for most dispute reason codes.

  15. Which of the following is a prohibited practice under APRP professional conduct standards?

    Answer: Misrepresenting one's APRP credential status to employers

    Misrepresenting credential status violates APRP professional conduct standards and can result in revocation of the designation.

  16. Under a risk-based AML program, what is the primary factor that determines the level of customer due diligence (CDD) applied to a new merchant?

    Answer: The overall risk profile of the merchant based on business type, geography, and expected transaction patterns

    Risk-based CDD calibrates the depth of due diligence to the customer's composite risk profile, applying enhanced measures where risk indicators are elevated.

  17. A payments organization uses multi-factor authentication (MFA). Which combination correctly represents three different authentication factors?

    Answer: Smart card, fingerprint, and one-time passcode

    Smart card (something you have), fingerprint (something you are), and OTP (something you have/know) span three distinct factor categories.

  18. Which professional organization is most directly associated with the APRP credential for payments risk professionals?

    Answer: NACHA

    NACHA (now Nacha) administers the APRP credential, which is specifically designed for payments risk professionals.

  19. Which of the following is a requirement under the USA PATRIOT Act for financial institutions?

    Answer: Implementing a Customer Identification Program (CIP).

    The USA PATRIOT Act, enacted to combat terrorism financing and money laundering, mandates that financial institutions implement a Customer Identification Program (CIP). This program requires institutions to verify the identity of individuals and entities opening accounts. The CIP helps prevent terrorists and criminals from using the financial system for illicit purposes by ensuring that institutions know who their customers are.

  20. An issuer wants to allow cardholders to freeze and unfreeze their cards instantly. Which security principle does this feature PRIMARILY support?

    Answer: Dynamic authorization control

    Card freeze/unfreeze gives cardholders dynamic control over transaction authorization, enabling real-time restriction of card use without cancellation.