APRP Emerging Payment Risks 3 β Questions and Answers
Question 1: Which type of attack specifically targets the enrollment phase of biometric authentication in mobile payment apps?
- Presentation attack using a spoofed fingerprint or face mask (Correct answer)
- Replay attack using captured biometric templates
- Man-in-the-middle attack on the biometric comparison server
- Brute force attack on the biometric PIN fallback
Correct answer: Presentation attack using a spoofed fingerprint or face mask
Presentation attacks at enrollment inject fake biometric samples (spoofed fingerprints, 3D-printed faces) to register an attacker's biometric as the legitimate user's credential.
Question 2: What distinguishes a 'push payment fraud' from traditional card fraud in terms of recovery options?
- Push payments have no chargeback mechanism, making recovery largely dependent on voluntary bank cooperation (Correct answer)
- Push payments are covered by Reg Z's billing error resolution procedures
- Card network zero-liability policies apply equally to push payments
- Push payments are insured by FDIC up to $250,000 per transaction
Correct answer: Push payments have no chargeback mechanism, making recovery largely dependent on voluntary bank cooperation
Push payments (like Zelle or wire transfers) are authorized by the consumer, so no card network chargeback right exists; recovery depends on receiving bank cooperation or litigation.
Question 3: In the context of tokenization for digital wallets, what risk does 'token requestor compromise' represent?
- An attacker intercepts and replays network tokens during transaction authorization
- A compromised token requestor can request and stockpile tokens tied to real PANs for later fraud (Correct answer)
- Token expiration causes declined transactions during peak payment periods
- NFC token collision between multiple cards in the same wallet
Correct answer: A compromised token requestor can request and stockpile tokens tied to real PANs for later fraud
If a token requestor (e.g., a digital wallet provider) is compromised, attackers can generate large numbers of payment tokens linked to real account numbers and use them for fraudulent transactions.
Question 4: A BNPL provider offers instant credit without a hard credit check. Which risk does this practice most directly increase for the payment ecosystem?
- Systemic counterparty credit risk when BNPL providers extend beyond their capital base (Correct answer)
- PCI DSS scope expansion for all merchants accepting BNPL
- Reg Z disclosure violations for open-end credit products
- ACH nacha rule violations for recurring debit authorizations
Correct answer: Systemic counterparty credit risk when BNPL providers extend beyond their capital base
BNPL providers extending credit without robust credit checks build portfolios of potentially high-risk borrowers, and if losses exceed capital, their inability to honor merchant settlements creates systemic risk.
Question 5: Which characteristic of real-time payment systems (e.g., RTP, FedNow) makes fraud prevention fundamentally harder than in batch ACH processing?
- Real-time payments use stronger encryption that delays fraud detection algorithms
- The irrevocability and speed leave no window for pre-settlement fraud intervention (Correct answer)
- Real-time systems lack Nacha's Operating Rules framework for dispute resolution
- Authentication standards are lower for real-time rail participants
Correct answer: The irrevocability and speed leave no window for pre-settlement fraud intervention
Real-time payments settle in seconds and are typically irrevocable, eliminating the hours-long batch window where traditional fraud controls could flag and recall suspicious ACH transactions.
Question 6: An e-money institution offers a multi-currency digital wallet. Which operational risk is most amplified by real-time FX conversion features?
- Basis risk from mismatched FX hedge durations during high-volatility periods (Correct answer)
- PCI DSS Level 1 compliance requirements for cross-border card storage
- Nacha ACH origination limits exceeding daily transaction caps
- OFAC sanctions screening delays on domestic USD transactions
Correct answer: Basis risk from mismatched FX hedge durations during high-volatility periods
Real-time FX conversion exposes the institution to basis risk when hedges are executed at different times or tenors than the underlying customer transactions during volatile market conditions.
Question 7: What is 'credential stuffing' and why is it particularly dangerous in the context of stored payment credentials?
- Injecting malicious data into payment card magnetic stripes to clone cards at POS
- Using breached username/password pairs to take over accounts containing stored payment methods (Correct answer)
- Overloading payment gateways with fraudulent authorization requests to cause downtime
- Embedding malware in payment terminal firmware to capture card data
Correct answer: Using breached username/password pairs to take over accounts containing stored payment methods
Credential stuffing automates login attempts using username/password pairs from prior breaches, and success gives attackers access to stored payment methods for immediate fraudulent use.
Which type of attack specifically targets the enrollment phase of biometric authentication in mobile payment apps?