APRP Fraud Prevention & Detection 3 — Questions and Answers
Question 1: What is the primary purpose of a fraud score generated by an authorization decisioning system?
- To calculate interchange fees for each transaction
- To rank the likelihood that a transaction is fraudulent so a decision can be made (Correct answer)
- To determine the correct routing path for a payment
- To assign a credit limit adjustment to the cardholder
Correct answer: To rank the likelihood that a transaction is fraudulent so a decision can be made
Fraud scores quantify risk at the moment of authorization, enabling issuers or acquirers to approve, decline, or step up authentication based on risk level.
Question 2: Which fraud type involves a cardholder intentionally disputing a legitimate transaction to obtain a refund while keeping the goods or services?
- First-party fraud / friendly fraud (Correct answer)
- Card-present counterfeit fraud
- Account takeover fraud
- Phishing-enabled fraud
Correct answer: First-party fraud / friendly fraud
Friendly fraud (first-party fraud) occurs when a legitimate cardholder falsely claims a transaction was unauthorized to receive a chargeback.
Question 3: Which authentication method provides the strongest protection against card-not-present fraud by requiring possession of the cardholder's mobile device?
- Static password
- Knowledge-based authentication (KBA)
- Out-of-band one-time passcode (OTP) (Correct answer)
- Address Verification Service (AVS)
Correct answer: Out-of-band one-time passcode (OTP)
An out-of-band OTP sent to the registered mobile device confirms physical possession, making it far harder for fraudsters who only have card credentials.
Question 4: In the context of APRP, 'bust-out fraud' typically involves:
- Hacking into a payment processor's database
- Building credit history and then maxing out credit lines with no intent to repay (Correct answer)
- Using a skimmer device at an ATM to clone cards
- Filing false insurance claims after a payment dispute
Correct answer: Building credit history and then maxing out credit lines with no intent to repay
Bust-out fraud is a credit fraud scheme where a fraudster gradually builds a good credit profile before suddenly maxing out all available credit and disappearing.
Question 5: Which data element is most useful for detecting 'card-present' counterfeit fraud at the point of sale?
- Billing ZIP code match
- CVV2 verification result
- EMV cryptogram validation (Correct answer)
- Spending category (MCC) analysis
Correct answer: EMV cryptogram validation
EMV chip cryptograms are unique per transaction and cannot be replicated from skimmed magnetic stripe data, making them the key defense against counterfeit card fraud.
Question 6: A risk professional identifies a network of seemingly unrelated accounts all funding the same recipient. This is an example of:
- Mule network detection (Correct answer)
- Chargeback arbitration
- Negative file screening
- Proxy piercing
Correct answer: Mule network detection
Mule networks use multiple accounts (often unwitting individuals) to funnel fraudulent funds, and link analysis revealing the common recipient exposes the scheme.
Question 7: What is the role of a 'negative file' or 'deny list' in fraud prevention?
- It stores approved merchant categories for automated clearing
- It contains identifiers associated with past fraud that trigger declines or alerts (Correct answer)
- It lists accounts exempt from velocity checks due to VIP status
- It records failed authentication attempts for regulatory reporting
Correct answer: It contains identifiers associated with past fraud that trigger declines or alerts
A negative file is a database of known fraudulent identifiers (cards, accounts, devices, IPs) used to automatically block or flag matching future transactions.
What is the primary purpose of a fraud score generated by an authorization decisioning system?