Digital Fraud & Account Takeover Flashcards
7 cards from real CFA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Digital Fraud & Account Takeover flashcards as text
During a phishing simulation, employees who clicked the link were redirected to a fake login page that captured real credentials. This infrastructure is called a:
Answer: Adversary-in-the-Middle (AiTM) proxy
AiTM phishing proxies sit between the victim and the legitimate site, capturing credentials and session cookies in real time.
Which digital fraud indicator is most associated with new-account fraud (NAF) rather than account takeover (ATO)?
Answer: Synthetic or mismatched identity data at registration
New-account fraud typically involves fabricated or synthetic identity data submitted during account opening, unlike ATO which targets existing legitimate accounts.
A fraud analyst reviewing logs sees thousands of login attempts using valid usernames but randomized passwords. This is best characterized as:
Answer: Brute force attack
Brute force attacks systematically try many passwords against one or more accounts, whereas credential stuffing uses known username-password pairs.
What is the primary purpose of device fingerprinting in digital fraud prevention?
Answer: Identifying and tracking devices across sessions without cookies
Device fingerprinting collects browser and hardware attributes to create a unique identifier that persists even when cookies are cleared.
A fraudster gains access to an account by answering knowledge-based authentication (KBA) questions using information scraped from social media. This illustrates a weakness of:
Answer: Static KBA
Static KBA relies on answers to questions whose answers are often publicly available or easily researched, making it a weak authentication factor.
Which regulatory framework requires financial institutions to implement a layered security approach specifically to combat online account fraud?
Answer: FFIEC Authentication Guidance
The FFIEC Authentication Guidance mandates that financial institutions use layered security controls to mitigate risks from online banking account fraud.
An analyst notices that after an ATO event, the fraudster waited 30 days before transacting. What fraud strategy does this reflect?
Answer: Account aging
Account aging involves waiting after takeover to allow the account's fraud score to normalize before committing the actual fraud.