← All CFA Flashcard Decks

Digital Fraud & Account Takeover Flashcards

7 cards from real CFA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Digital Fraud & Account Takeover flashcards as text
  1. A fraudster purchases stolen credentials from the dark web and uses them to log into customer accounts. This technique is known as:

    Answer: Credential stuffing

    Credential stuffing involves using lists of previously breached username/password pairs to gain unauthorized access to accounts at other services.

  2. During an account takeover investigation, an analyst discovers the fraudster changed the victim's email and phone before making transactions. This tactic is called:

    Answer: Contact point hijacking

    Contact point hijacking involves replacing legitimate contact details to intercept security alerts and lock out the true owner.

  3. Which metric best measures an organization's exposure to automated bot-driven account takeover attacks?

    Answer: Failed login rate per IP range

    An unusually high failed login rate concentrated across certain IP ranges is a primary signal of automated credential stuffing or brute-force attacks.

  4. A bank notices logins from a known good device but at an unusual hour and location. Which fraud detection approach flags this anomaly?

    Answer: User and Entity Behavior Analytics (UEBA)

    UEBA establishes a behavioral baseline per user and flags deviations in time, location, or activity pattern as potential compromises.

  5. SIM swapping is a form of account takeover because it allows fraudsters to:

    Answer: Intercept one-time passwords sent via SMS

    By porting the victim's phone number to a fraudster-controlled SIM, all SMS-based OTPs are redirected, defeating SMS multi-factor authentication.

  6. Which type of malware is specifically designed to intercept online banking sessions and modify transaction details in real time?

    Answer: Man-in-the-Browser (MitB)

    Man-in-the-Browser malware injects code into the browser to manipulate web transactions without the user's knowledge, even when SSL is in use.

  7. An e-commerce site detects multiple new accounts created from the same device fingerprint within minutes. This is most indicative of:

    Answer: Account farming for future abuse

    Mass account creation from a single device is a hallmark of account farming, where fraudsters stockpile accounts for later fraudulent use.