APRP Fraud Prevention & Detection 5 — Questions and Answers
Question 1: Which regulatory requirement obligates US financial institutions to file a Suspicious Activity Report (SAR) when fraud is suspected above a certain threshold?
- PCI DSS v4.0
- Bank Secrecy Act (BSA) (Correct answer)
- Regulation E
- Gramm-Leach-Bliley Act (GLBA)
Correct answer: Bank Secrecy Act (BSA)
The Bank Secrecy Act and its implementing regulations require financial institutions to file SARs when transactions suggest criminal activity, including fraud, above reporting thresholds.
Question 2: A fraud analyst notices that disputed transactions share the same IP geolocation — a country the cardholder has never visited. This is an example of using which fraud signal?
- Chargeback reason code analysis
- Geolocation anomaly detection (Correct answer)
- Velocity threshold breach
- Negative file match
Correct answer: Geolocation anomaly detection
Geolocation anomaly detection compares the transaction origin's IP location against cardholder behavioral history to flag geographically implausible activity.
Question 3: What distinguishes 'first-party misuse' from 'third-party fraud' in consumer payments?
- First-party misuse involves external attackers; third-party fraud involves insiders
- First-party misuse is committed by the account holder; third-party fraud is committed by someone other than the account holder (Correct answer)
- First-party misuse only applies to credit products; third-party fraud applies to debit
- First-party misuse requires a data breach; third-party fraud does not
Correct answer: First-party misuse is committed by the account holder; third-party fraud is committed by someone other than the account holder
First-party misuse means the legitimate account owner abuses the account (e.g., friendly fraud), whereas third-party fraud involves an outside party acting without the account holder's knowledge.
Question 4: Which data sharing practice helps issuers detect account takeover by alerting them when a cardholder's personal information appears in a known data breach?
- Tokenization
- Dark web monitoring and breach intelligence feeds (Correct answer)
- PCI DSS Level 1 certification
- Real-time gross settlement (RTGS)
Correct answer: Dark web monitoring and breach intelligence feeds
Dark web monitoring services scan criminal marketplaces and breach databases to alert issuers when customer credentials or card data appear, enabling proactive account protection.
Question 5: A payment risk professional recommends step-up authentication only for transactions above a defined risk threshold. This approach is an example of:
- Zero-trust security architecture
- Risk-based authentication (Correct answer)
- Static rule enforcement
- Multifactor enrollment
Correct answer: Risk-based authentication
Risk-based authentication applies additional verification only when a transaction's risk score exceeds a threshold, balancing security and customer friction.
Question 6: In chargeback management, which reason code category is most directly associated with card-not-present fraud on Visa's dispute framework?
- Consumer disputes (Category 12)
- Fraud (Category 10) (Correct answer)
- Processing errors (Category 13)
- Authorization (Category 11)
Correct answer: Fraud (Category 10)
Visa's Category 10 covers fraud disputes, including 10.4 (card-absent environment), which is the primary CNP fraud chargeback reason code.
Question 7: Which emerging fraud vector exploits the speed of instant payment rails (e.g., RTP, FedNow) to make fund recovery nearly impossible?
- Card skimming at ATM networks
- Real-time payment fraud through social engineering (Correct answer)
- Counterfeit check kiting schemes
- Point-of-sale terminal tampering
Correct answer: Real-time payment fraud through social engineering
Real-time payment rails settle funds in seconds, and fraudsters exploit this speed through APP scams and account takeover to move money before detection or freezing is possible.
Which regulatory requirement obligates US financial institutions to file a Suspicious Activity Report (SAR) when fraud is suspected above a certain threshold?