APRP APRP Quality & Compliance 2 — Questions and Answers
Question 1: Under PCI DSS, what is the maximum period allowed between required internal vulnerability scans?
- 30 days
- 60 days
- 90 days (Correct answer)
- 180 days
Correct answer: 90 days
PCI DSS requires internal vulnerability scans to be performed at least quarterly (every 90 days).
Question 2: A merchant's chargeback rate exceeds the card network's threshold for two consecutive months. What program does this typically trigger?
- Merchant Data Breach Program
- Chargeback Monitoring Program (Correct answer)
- Fraud Reporting Initiative
- Compliance Validation Program
Correct answer: Chargeback Monitoring Program
Card networks place merchants whose chargeback rates exceed defined thresholds into a Chargeback Monitoring Program, which imposes fees and remediation requirements.
Question 3: Which BSA/AML control requires financial institutions to identify and verify the identity of beneficial owners of legal entity customers?
- Customer Identification Program (CIP)
- Suspicious Activity Reporting (SAR)
- Customer Due Diligence (CDD) Rule (Correct answer)
- Currency Transaction Reporting (CTR)
Correct answer: Customer Due Diligence (CDD) Rule
FinCEN's CDD Rule requires covered institutions to collect and verify beneficial ownership information for legal entity customers.
Question 4: A quality assurance review finds that a payments processor is approving transactions without verifying CVV2 for card-not-present purchases. Which compliance domain is most directly violated?
- PCI DSS Requirement 3 (Correct answer)
- PCI DSS Requirement 6
- PCI DSS Requirement 12
- PCI DSS Requirement 8
Correct answer: PCI DSS Requirement 3
PCI DSS Requirement 3 governs the protection of stored cardholder data, including restrictions on storing sensitive authentication data such as CVV2 after authorization.
Question 5: What does a 'Risk-Based Approach' to AML compliance mean in practice?
- Applying the same controls uniformly to all customers
- Allocating more compliance resources to higher-risk customers and transactions (Correct answer)
- Avoiding high-risk markets entirely
- Reporting all transactions above $5,000 regardless of risk indicators
Correct answer: Allocating more compliance resources to higher-risk customers and transactions
A risk-based approach concentrates AML resources and enhanced due diligence on customers and transactions assessed as higher risk.
Question 6: Which metric is the PRIMARY indicator used to measure the effectiveness of a fraud prevention program?
- Total number of transactions declined
- Fraud loss as a percentage of sales volume (Correct answer)
- Number of chargebacks filed per month
- Average transaction approval time
Correct answer: Fraud loss as a percentage of sales volume
Fraud loss as a percentage of sales volume (fraud rate) is the standard KPI for measuring fraud prevention effectiveness relative to business scale.
Question 7: An issuer notices a pattern where stolen card data is tested with small micro-transactions before large fraudulent purchases. What fraud tactic is this?
- Account takeover
- Card-not-present bust-out fraud
- Card testing (BIN attack) (Correct answer)
- Friendly fraud
Correct answer: Card testing (BIN attack)
Card testing, also known as a BIN attack, involves using small transactions to validate stolen card credentials before committing larger fraud.
Under PCI DSS, what is the maximum period allowed between required internal vulnerability scans?