APRP APRP Industry Standards 3 — Questions and Answers
Question 1: Which industry standard governs the end-to-end encryption of payment card data from the point of interaction to the acquirer?
- PCI P2PE (Correct answer)
- PCI PA-DSS
- PCI PTS
- PCI DSS
Correct answer: PCI P2PE
PCI Point-to-Point Encryption (P2PE) standard defines requirements for encrypting cardholder data from the point of interaction through decryption at a secure point, reducing PCI DSS scope for merchants.
Question 2: NACHA's WEB Debit Account Validation Rule requires originators to validate consumer accounts using which method before the first transaction?
- Verbal confirmation from the consumer
- A prenote or commercially reasonable external validation method (Correct answer)
- A signed paper authorization
- A real-time credit check
Correct answer: A prenote or commercially reasonable external validation method
NACHA's WEB debit rule requires originators to use a prenote or a commercially reasonable fraud detection method to validate accounts before initiating the first debit.
Question 3: Under Mastercard's dispute resolution framework (MCDR), what replaced the traditional chargeback and arbitration process?
- Collaboration and pre-arbitration only
- A fully automated AI-driven settlement
- The Dispute Resolution Management (DRM) system (Correct answer)
- A mandatory third-party mediation service
Correct answer: The Dispute Resolution Management (DRM) system
Mastercard's Dispute Resolution Management (DRM) system streamlined the process by consolidating dispute stages and automating routing decisions.
Question 4: Which regulatory framework requires US banks to file a Suspicious Activity Report (SAR) within 30 days of detecting a suspicious transaction?
- Regulation E
- Bank Secrecy Act (BSA) (Correct answer)
- Dodd-Frank Act
- Electronic Fund Transfer Act (EFTA)
Correct answer: Bank Secrecy Act (BSA)
The Bank Secrecy Act (BSA) and its implementing regulations require financial institutions to file SARs within 30 calendar days of initial detection of suspicious activity.
Question 5: In the context of ACH risk management, what is an 'unauthorized debit' under NACHA rules?
- A debit that exceeds the account balance
- A debit initiated without a valid authorization from the account holder (Correct answer)
- A debit returned due to insufficient funds
- A debit processed after the account was closed
Correct answer: A debit initiated without a valid authorization from the account holder
An unauthorized debit under NACHA rules is one where the Originator did not obtain proper authorization from the Receiver before initiating the ACH entry.
Question 6: The CFPB's Prepaid Account Rule (Regulation E) extended protections to prepaid cards, requiring issuers to provide which document before account opening?
- A full cardholder agreement
- A short-form and long-form fee disclosure (Correct answer)
- A credit score disclosure
- A fraud liability waiver
Correct answer: A short-form and long-form fee disclosure
The CFPB Prepaid Rule requires issuers to provide a short-form fee disclosure pre-purchase and a long-form disclosure with all fees and terms.
Question 7: Under PCI DSS, what is the minimum frequency for running internal vulnerability scans on systems in the cardholder data environment?
- Annually
- Semi-annually
- Quarterly (Correct answer)
- Monthly
Correct answer: Quarterly
PCI DSS Requirement 11 mandates that internal vulnerability scans be performed at least quarterly and after any significant changes to the network.
Which industry standard governs the end-to-end encryption of payment card data from the point of interaction to the acquirer?