APRP Payment Systems & Technology 2 — Questions and Answers
Question 1: Which tokenization standard is used to replace sensitive Primary Account Numbers (PANs) in digital wallet transactions?
- EMV 3DS
- Network Token (Correct answer)
- P2PE
- HSM wrapping
Correct answer: Network Token
Network tokens replace the PAN with a surrogate value specific to a device or merchant, reducing exposure of the real card number.
Question 2: In the ACH network, what is the maximum dollar threshold that distinguishes a Same-Day ACH entry from a standard ACH entry?
- $25,000
- $100,000
- $1,000,000 (Correct answer)
- $10,000,000
Correct answer: $1,000,000
As of March 2020, NACHA raised the Same-Day ACH per-transaction cap to $1,000,000.
Question 3: A merchant uses a hardware device that encrypts card data at the point of swipe before it reaches the POS software. This is best described as:
- Tokenization
- End-to-end encryption (E2EE)
- Point-to-point encryption (P2PE) (Correct answer)
- SSL/TLS encryption
Correct answer: Point-to-point encryption (P2PE)
P2PE encrypts cardholder data from the point of interaction (POI) device, preventing clear-text PAN exposure within the merchant environment.
Question 4: Which RTP (Real-Time Payments) network attribute makes fraud recovery fundamentally more difficult than traditional ACH?
- Higher per-transaction fees
- Mandatory two-factor authentication
- Immediate and irrevocable settlement (Correct answer)
- 24/7 processing windows
Correct answer: Immediate and irrevocable settlement
Because RTP funds are credited instantly and settlement is final, there is no recall window like ACH's two-day return period.
Question 5: Which ISO standard defines the message format most widely used in card payment authorization communications?
- ISO 20022
- ISO 8583 (Correct answer)
- ISO 27001
- ISO 9362
Correct answer: ISO 8583
ISO 8583 defines the data elements and message structure for financial transaction card-originated messages used in authorization, clearing, and settlement.
Question 6: What is the primary purpose of the Payment Card Industry Data Security Standard (PCI DSS) Requirement 9?
- Encrypt transmission of cardholder data
- Restrict physical access to cardholder data (Correct answer)
- Maintain a vulnerability management program
- Implement strong access control measures
Correct answer: Restrict physical access to cardholder data
PCI DSS Requirement 9 specifically addresses restricting physical access to cardholder data, including securing devices that capture payment card data.
Question 7: A contactless payment using a mobile phone leverages which technology to communicate with the POS terminal?
- Bluetooth Low Energy (BLE)
- Near Field Communication (NFC) (Correct answer)
- Wi-Fi Direct
- RFID UHF
Correct answer: Near Field Communication (NFC)
NFC operates at 13.56 MHz and requires the device to be within ~4 cm of the terminal, making it the standard for tap-to-pay mobile transactions.
Which tokenization standard is used to replace sensitive Primary Account Numbers (PANs) in digital wallet transactions?