APRP Payment Systems & Technology 3 — Questions and Answers
Question 1: In a card transaction, which entity is responsible for performing fraud scoring and making the authorization decision on behalf of the card issuer?
- Merchant acquirer
- Payment processor / issuer authorization system (Correct answer)
- Card network (Visa/Mastercard)
- Payment gateway
Correct answer: Payment processor / issuer authorization system
The issuer or its processor runs real-time fraud models and decides to approve, decline, or refer each authorization request.
Question 2: What does the term 'interchange' refer to in card payment economics?
- The fee a gateway charges a merchant for routing transactions
- The fee the acquirer pays to the issuer for each card transaction (Correct answer)
- The settlement amount transferred between issuing and acquiring banks
- The markup added by a card network above processing costs
Correct answer: The fee the acquirer pays to the issuer for each card transaction
Interchange is the fee the merchant's acquiring bank pays to the cardholder's issuing bank, representing the largest component of card acceptance cost.
Question 3: Which clearing file format is used by the Federal Reserve's FedACH service to exchange batch payment instructions between financial institutions?
- SWIFT MT103
- NACHA CCD/PPD flat file (Correct answer)
- ISO 20022 pacs.008
- X12 835 EDI
Correct answer: NACHA CCD/PPD flat file
FedACH uses the NACHA-defined fixed-length flat file format, where CCD (corporate credit/debit) and PPD (prearranged payment/deposit) are common SEC codes.
Question 4: A fraudster calls a bank pretending to be a customer and convinces the agent to change the account's registered phone number. This attack best exemplifies:
- SIM swapping
- Vishing with social engineering (Correct answer)
- Account takeover via credential stuffing
- Man-in-the-middle attack
Correct answer: Vishing with social engineering
Vishing (voice phishing) combined with social engineering manipulates human agents to make unauthorized account changes without technical compromise.
Question 5: Under Regulation E, a consumer must report an unauthorized EFT within how many business days to limit liability to $50?
- 2 business days (Correct answer)
- 10 business days
- 30 business days
- 60 business days
Correct answer: 2 business days
Regulation E limits consumer liability to $50 if the unauthorized transfer is reported within 2 business days of learning of the loss or theft.
Question 6: What is the primary function of a payment gateway in an e-commerce transaction?
- Settle funds between issuing and acquiring banks
- Securely transmit transaction data between the merchant and the payment processor (Correct answer)
- Perform chargeback dispute resolution
- Assign interchange category codes to transactions
Correct answer: Securely transmit transaction data between the merchant and the payment processor
A payment gateway encrypts and routes the authorization request from the merchant's website to the acquiring bank's payment processor.
Question 7: Which fraud type involves a legitimate business processing fraudulent transactions on behalf of unknown third-party fraudsters?
- Bust-out fraud
- Factoring (merchant laundering) (Correct answer)
- Triangulation fraud
- Refund abuse
Correct answer: Factoring (merchant laundering)
Factoring occurs when a merchant runs transactions for another party through its own merchant account, violating card network rules and enabling fraud or money laundering.
In a card transaction, which entity is responsible for performing fraud scoring and making the authorization decision on behalf of the card issuer?