APRP APRP Quality & Compliance 5 — Questions and Answers
Question 1: What is the key difference between 'first-party fraud' and 'third-party fraud' in payments?
- First-party fraud involves stolen card data; third-party fraud involves identity theft
- First-party fraud is committed by the account holder themselves; third-party fraud is committed by an external criminal (Correct answer)
- First-party fraud occurs at the point of sale; third-party fraud occurs online
- First-party fraud is covered by Regulation E; third-party fraud is not
Correct answer: First-party fraud is committed by the account holder themselves; third-party fraud is committed by an external criminal
First-party fraud is perpetrated by the legitimate account holder (e.g., bust-out, friendly fraud), while third-party fraud involves an external actor using stolen credentials.
Question 2: Under NACHA Operating Rules, an Originating Depository Financial Institution (ODFI) that originates ACH entries bears primary responsibility for:
- Setting return reason codes for failed entries
- Ensuring originators comply with NACHA rules and warranting the entries (Correct answer)
- Approving settlement windows for each transaction
- Determining whether a Receiving Depository Financial Institution will accept the entry
Correct answer: Ensuring originators comply with NACHA rules and warranting the entries
ODFIs warrant each ACH entry they originate and are responsible for ensuring that originators comply with NACHA Operating Rules.
Question 3: A payments firm's governance committee receives a risk report showing that inherent risk is high but residual risk is low. What does this indicate?
- The firm is exposed to significant losses with no mitigating controls in place
- Effective controls are successfully reducing the impact of a high-risk environment (Correct answer)
- The firm has understated its risk exposure in the report
- Risk appetite exceeds the firm's actual risk capacity
Correct answer: Effective controls are successfully reducing the impact of a high-risk environment
Residual risk equals inherent risk minus the effect of controls; a low residual risk despite high inherent risk indicates that controls are working effectively.
Question 4: Which card network rule requires acquirers to ensure that merchants do not surcharge debit card transactions while allowing surcharges on credit cards?
- Interchange reimbursement fee rule
- Honor All Cards rule
- No-Surcharge rule (Visa/MC settlement) (Correct answer)
- Least-Cost Routing mandate
Correct answer: No-Surcharge rule (Visa/MC settlement)
The 2013 merchant settlement agreement allows credit card surcharging under specific conditions but prohibits applying those surcharges to debit card transactions.
Question 5: An APRP exam scenario presents a processor that stores full PANs in application logs 'for debugging purposes.' Which PCI DSS requirement is most directly violated?
- Requirement 1 — Install and maintain network security controls
- Requirement 3 — Protect stored account data (Correct answer)
- Requirement 7 — Restrict access to cardholder data by business need to know
- Requirement 10 — Log and monitor all access to network resources and cardholder data
Correct answer: Requirement 3 — Protect stored account data
PCI DSS Requirement 3 prohibits storing sensitive cardholder data (including full PANs without proper masking or encryption) beyond what is necessary, regardless of the stated purpose.
Question 6: A compliance team conducts a 'gap analysis' before a PCI DSS assessment. What is the PRIMARY goal of this activity?
- To calculate the cost of compliance certification
- To identify controls that are missing or inadequate relative to PCI DSS requirements (Correct answer)
- To train employees on data security policies
- To negotiate the scope of the assessment with the QSA
Correct answer: To identify controls that are missing or inadequate relative to PCI DSS requirements
A gap analysis compares the current state of controls against PCI DSS requirements to identify deficiencies that must be remediated before the formal assessment.
Question 7: What is the purpose of the 'return rate' monitoring requirement under NACHA rules for ACH originators?
- To measure how quickly payment processors settle funds
- To identify originators with unusually high rates of unauthorized or incorrect ACH entries (Correct answer)
- To track ACH volume growth across payment types
- To ensure same-day ACH entries are returned within the correct window
Correct answer: To identify originators with unusually high rates of unauthorized or incorrect ACH entries
NACHA monitors return rates to detect originators whose high rates of returned entries may signal poor data quality, unauthorized debits, or fraud.
What is the key difference between 'first-party fraud' and 'third-party fraud' in payments?