APRP APRP Quality & Compliance 4 — Questions and Answers
Question 1: Which data element, if compromised, allows fraudsters to clone a physical payment card?
- Primary Account Number (PAN) alone
- Track 1 or Track 2 magnetic stripe data (Correct answer)
- Card Verification Value 2 (CVV2)
- Cardholder billing address
Correct answer: Track 1 or Track 2 magnetic stripe data
Track 1 and Track 2 magnetic stripe data contain all information needed to encode a counterfeit card, making their protection critical under PCI DSS.
Question 2: An APRP candidate reviews a processor's audit findings and sees 'scope creep' flagged as a deficiency. What does this mean in a PCI DSS context?
- The audit exceeded its budgeted timeline
- Systems that touch cardholder data were added without updating the cardholder data environment boundary (Correct answer)
- Too many employees have access to payment terminals
- The processor expanded to new geographic markets without approval
Correct answer: Systems that touch cardholder data were added without updating the cardholder data environment boundary
PCI DSS scope creep occurs when new systems enter the cardholder data environment without proper documentation and security controls being applied to them.
Question 3: What is 'network tokenization' and how does it improve payment security?
- Replacing the card network's routing infrastructure with blockchain
- Substituting a PAN with a token issued by the card network, valid only for a specific merchant or device (Correct answer)
- Encrypting transaction data at the point-of-sale terminal
- Assigning unique identifiers to merchant accounts for fraud tracking
Correct answer: Substituting a PAN with a token issued by the card network, valid only for a specific merchant or device
Network tokenization replaces sensitive PANs with network-issued tokens scoped to a specific merchant or device, limiting the value of intercepted payment credentials.
Question 4: A bank files a Suspicious Activity Report (SAR) on a customer. Under BSA regulations, what is the bank prohibited from doing?
- Closing the customer's account
- Disclosing to the customer that a SAR has been filed (Correct answer)
- Continuing to monitor the account
- Reporting the activity to internal compliance staff
Correct answer: Disclosing to the customer that a SAR has been filed
BSA regulations prohibit 'tipping off' — informing the subject of a SAR that one has been filed, to avoid alerting potential money launderers.
Question 5: In the context of payments compliance, what does 'regulatory capital' refer to for an acquiring bank?
- Funds held in escrow for disputed transactions
- Capital reserves that regulators require banks to hold against risk-weighted assets (Correct answer)
- The fee income generated from card processing activity
- Collateral posted by merchants to cover chargeback exposure
Correct answer: Capital reserves that regulators require banks to hold against risk-weighted assets
Regulatory capital refers to the minimum capital buffers mandated by bank regulators (such as under Basel III) to absorb losses from risk-weighted exposures.
Question 6: Which of the following is an example of a 'preventive' control in a payments fraud management program?
- Reviewing declined transaction logs to identify false positives
- Real-time velocity checking that blocks transactions exceeding defined thresholds (Correct answer)
- Filing chargebacks on unauthorized transactions after the fact
- Generating monthly fraud loss reports for management
Correct answer: Real-time velocity checking that blocks transactions exceeding defined thresholds
Real-time velocity checking prevents fraudulent transactions from completing, making it a preventive control that acts before the harm occurs.
Question 7: A payments risk professional is asked to evaluate a new fintech partner's compliance posture. Which document would BEST demonstrate the partner's security controls to a third party?
- A signed non-disclosure agreement
- A SOC 2 Type II audit report (Correct answer)
- The partner's internal policy manual
- A letter of attestation from the CEO
Correct answer: A SOC 2 Type II audit report
A SOC 2 Type II report provides independent third-party validation that a service organization's controls are designed effectively and operated consistently over a period of time.
Which data element, if compromised, allows fraudsters to clone a physical payment card?