APRP APRP Industry Standards 2 — Questions and Answers
Question 1: Which PCI DSS requirement specifically mandates that cardholder data must not be stored after authorization?
- Requirement 3 (Correct answer)
- Requirement 6
- Requirement 8
- Requirement 10
Correct answer: Requirement 3
PCI DSS Requirement 3 governs the protection of stored cardholder data, including prohibitions on storing sensitive authentication data after authorization.
Question 2: Under NACHA Operating Rules, what is the maximum dollar threshold per transaction for Same Day ACH entries?
- $25,000
- $100,000 (Correct answer)
- $1,000,000
- $10,000
Correct answer: $100,000
NACHA set the Same Day ACH per-transaction cap at $100,000, effective March 2020, to support higher-value business payments.
Question 3: The ISO 20022 messaging standard is primarily designed to improve which aspect of payments?
- Cardholder authentication
- Rich data and interoperability across payment systems (Correct answer)
- Fraud detection algorithms
- ATM network routing
Correct answer: Rich data and interoperability across payment systems
ISO 20022 provides a universal financial messaging standard enabling richer data and greater interoperability across domestic and international payment systems.
Question 4: Which Regulation E provision requires financial institutions to investigate disputes and provisionally credit consumer accounts within a specific timeframe?
- 10 business days (Correct answer)
- 45 calendar days
- 60 calendar days
- 5 business days
Correct answer: 10 business days
Regulation E requires financial institutions to complete error resolution investigations within 10 business days, or provisionally credit the account while extending the investigation.
Question 5: What does the FFIEC define as a key element of layered security for online banking?
- Single-factor authentication only
- Complex passwords with 90-day rotation
- Anomaly detection and out-of-band transaction verification (Correct answer)
- Static IP address whitelisting
Correct answer: Anomaly detection and out-of-band transaction verification
FFIEC guidance identifies anomaly detection coupled with out-of-band verification for high-risk transactions as critical components of effective layered security.
Question 6: Under the Card Brand Rules, what is the standard chargeback representment window for Visa disputes?
- 30 days
- 45 days (Correct answer)
- 60 days
- 90 days
Correct answer: 45 days
Visa's dispute rules generally allow merchants 45 days to respond to a chargeback with representment documentation.
Question 7: The EMVCo 3-D Secure (3DS2) protocol introduces which key capability over the original 3DS1?
- Chip-and-PIN at POS terminals
- Risk-based authentication using rich data from the merchant (Correct answer)
- Tokenization of PANs for card-not-present transactions
- Contactless NFC payment support
Correct answer: Risk-based authentication using rich data from the merchant
3DS2 enables risk-based authentication by passing rich transaction and device data from the merchant to the issuer, allowing frictionless flows for low-risk transactions.
Which PCI DSS requirement specifically mandates that cardholder data must not be stored after authorization?